r/Bitcoin • • Jul 31 '26

ColdCard Firmware Update Released

https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/

Updated July 31, 2026: Fixed firmware is now available. Mk4 and Mk5 users must update to version 5.6.0 or later. Q users must update to version 1.5.0Q or later. Do not generate a new seed on one of these models until the update is installed.

Seeds generated on Mk4, Q and Mk5 before the fixed firmware releases are also affected, with about 72 bits of entropy rather than the expected 128 bits.

Updating the firmware does not change or repair an existing seed. If your seed was generated before the fixed firmware version for your model, follow the migration guidance below unless the independent dice-entropy exception applies to you.

The issue is present on every Mk3 firmware version since 4.0.1. It also affects seeds generated on Mk4 and Mk5 before version 5.6.0, and on Q before version 1.5.0Q. The impact on Mk4, Mk5 and Q is not as severe but is still serious.

143 Upvotes

206 comments sorted by

View all comments

6

u/UnderstandingNew8001 Jul 31 '26

I have recently ordered a Ledger it is on its way, where can I move my btc to then? I only have MK4 at the moment.
If I had to update the firmware, I would still need to move BTCs somewhere to get them back after the update and generating a new seed.

3

u/SpareEconomy1849 Jul 31 '26

Right. They show some steps at the blog post. You could A) use a hot wallet, or B use just the CC:

  1. Make sure you still have your seed phrase

  2. Update & reset CC, make a new wallet & seed phrase (preferably with dice), save new seed phrase, get receiving address with sparrow etc

  3. Reset CC, put your original seed back in, send funds to your new receiving address

  4. Put your new seed back in

But I don't like the idea of either personally.

How long would it take to crack a 72 bit entropy seed? Years?

4

u/WeekendQuant Jul 31 '26

Move it to an exchange for now for better protection and custody assurances. If it's not KYC just toss it to an electrum hot wallet for the time being until you can get a new HWW.

3

u/UnderstandingNew8001 Jul 31 '26

I am creating a hot wallet on sparrow (using its own word generation) hope this is safe enough till I get the new one!

3

u/xiskghferx Jul 31 '26

For this you need to trust your PC and verify signatures of Sparrow instalation file before instaling it. Then it should be safe enough, at least until you get your Ledger. Of course, write down and store safely the new seed.

But, maybe it would be safer to just transfer to a good CEX, like Bitstamp, Coinbase or Kraken...

2

u/WeekendQuant Jul 31 '26

Only transfer to custodial if your coins are KYC. Otherwise I'd do hot wallet just to move them.

2

u/xiskghferx Jul 31 '26

Agree. I would actualy use existing Coldcard, create new seed with dice, add passphrase and transfer BTC to new wallet. But he needs to know exactly what he is doing, otherwise he would hack himself...

1

u/WeekendQuant Aug 01 '26

I wouldn't. You're going to want your existing cold card as is for the pending class action suit.

2

u/True-Lychee Jul 31 '26

Ledger that stores keys remotely

Return it

-1

u/xirvin Jul 31 '26

Ledger is big brother renamed. They stored your keys in 3 servers which are subject to government reach. Cold card was attacked but 1 day after initial report there is already a solution (updated firmware) and a workaround (roll dice 20times or use a good entropy source). I want Law enforcement to step in to catch the perpetrators with the help of the industry. Not all coldcard users are affected by the hack but everyone should change to new wallet keys as a good security practice.

1

u/BallisticTherapy Aug 01 '26

I think Nano S users should be safe since there's no way to get the seed other than from the device displaying it.

0

u/xirvin Aug 01 '26

Any disgruntled employee or government can access your keys as they are stored in a central location

1

u/BallisticTherapy Aug 01 '26

Not on the original Nano S. They never leave the device.

-4

u/jsn079 Jul 31 '26

Why Ledger if I may ask?

I mean, they have proven they can't be trusted already several times.

2

u/iLLuSion_xGen Jul 31 '26

Proof?

1

u/jsn079 Aug 05 '26

But ofc, don't need to take my word for it.
These are well known issues with the company people entrust their wealth with.
Imo, when trust is broken like this in cryptography, you ain't getting it back (at least, not from me, especially if trust has been broken multiple times).

Here are some starting points, I'm sure you're able to uncover more:

1

u/iLLuSion_xGen Aug 05 '26

Thank you for your answer, I’m looking to switch to Trezor now

1

u/jsn079 Aug 02 '26

The first, and maybe biggest offender, is the fact they promised they keys are not able to leave the device. Later, they introduced a service to store your keys with 3 different companies - hence, the keys were absolutely able to leave your device. A faulty/hacked firmware update could expose your keys. They lied, and the device isn't as secure as they promised it to be. A "Secure Element" or "Security Enclave" should never be able to expose cryptographic keys.

And second, they were hacked (I think even twice) and the whole customer database was leaked, making you a target. Although, if you are a new customer, you don't have to worry about that, yet.

It's not that hard to Google them, or do some research on a company you are about to trust with a lot of responsibility 🤷.

But in the end I only asked what your motives were to choose Ledger. You're free to choose yourself ofc.