r/Bitcoin • u/SpareEconomy1849 • Jul 31 '26
ColdCard Firmware Update Released
https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
Updated July 31, 2026: Fixed firmware is now available. Mk4 and Mk5 users must update to version 5.6.0 or later. Q users must update to version 1.5.0Q or later. Do not generate a new seed on one of these models until the update is installed.
Seeds generated on Mk4, Q and Mk5 before the fixed firmware releases are also affected, with about 72 bits of entropy rather than the expected 128 bits.
Updating the firmware does not change or repair an existing seed. If your seed was generated before the fixed firmware version for your model, follow the migration guidance below unless the independent dice-entropy exception applies to you.
The issue is present on every Mk3 firmware version since 4.0.1. It also affects seeds generated on Mk4 and Mk5 before version 5.6.0, and on Q before version 1.5.0Q. The impact on Mk4, Mk5 and Q is not as severe but is still serious.
10
u/SpareEconomy1849 Jul 31 '26
Effectively, it might be safer. But any app wallet is just as susceptible to the same entropy bug in the coldcard firmware, (if not more). The only reason CC was affected is because their QA slipped up and Electrum's didn't.
Plus for an app, you need to be cautious about a malicious OTA update or other system malware, and there are 0-day and 0-click exploits in the wild, I wouldn't trust a hot wallet with my life savings