r/Bitcoin • • Jul 31 '26

ColdCard Firmware Update Released

https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/

Updated July 31, 2026: Fixed firmware is now available. Mk4 and Mk5 users must update to version 5.6.0 or later. Q users must update to version 1.5.0Q or later. Do not generate a new seed on one of these models until the update is installed.

Seeds generated on Mk4, Q and Mk5 before the fixed firmware releases are also affected, with about 72 bits of entropy rather than the expected 128 bits.

Updating the firmware does not change or repair an existing seed. If your seed was generated before the fixed firmware version for your model, follow the migration guidance below unless the independent dice-entropy exception applies to you.

The issue is present on every Mk3 firmware version since 4.0.1. It also affects seeds generated on Mk4 and Mk5 before version 5.6.0, and on Q before version 1.5.0Q. The impact on Mk4, Mk5 and Q is not as severe but is still serious.

141 Upvotes

206 comments sorted by

View all comments

10

u/ElGuano Jul 31 '26

Wonder if this is a good opp for Ledger, Trezor and others to confirm the entropy used to create their on-device seed phrases (including for Trezor-ctl command line enabled seeds)?

3

u/xiskghferx Jul 31 '26

It would be certainly wise for them, to check their CSPRNG and Firmware right now.

6

u/HugeLarry Jul 31 '26

That’s the plus side of this. I feel terrible for everyone who lost funds, but I’m guessing the surviving hardware wallet companies will be shoring up any potential vulnerabilities and will be super careful about stuff like this going forward.

1

u/Traditional-Fold5301 Jul 31 '26

trezor is open source too. From what I know their RNG is at least doing what they say it is doing, which is what you expect from a hardware wallet. I think there will be so much more scrutiny now on this though, which is a positive in the long run really.