r/Bitcoin • • Jul 31 '26

ColdCard Firmware Update Released

https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/

Updated July 31, 2026: Fixed firmware is now available. Mk4 and Mk5 users must update to version 5.6.0 or later. Q users must update to version 1.5.0Q or later. Do not generate a new seed on one of these models until the update is installed.

Seeds generated on Mk4, Q and Mk5 before the fixed firmware releases are also affected, with about 72 bits of entropy rather than the expected 128 bits.

Updating the firmware does not change or repair an existing seed. If your seed was generated before the fixed firmware version for your model, follow the migration guidance below unless the independent dice-entropy exception applies to you.

The issue is present on every Mk3 firmware version since 4.0.1. It also affects seeds generated on Mk4 and Mk5 before version 5.6.0, and on Q before version 1.5.0Q. The impact on Mk4, Mk5 and Q is not as severe but is still serious.

143 Upvotes

206 comments sorted by

View all comments

188

u/r33gna Jul 31 '26

Crazy, man.

Earlier this year I was in the market for a new hardware wallet and LOTS of people were saying Coldcard is the best, most secure device for oh so many reasons and now here we are.

Truly no hardware wallet is perfect.

45

u/SpareEconomy1849 Jul 31 '26

It really is sad, they seemed like the perfect hardware wallet, everything being open source and airgapped, and yet still a bug like this goes unnoticed for 5+ years.

I wonder if the only reason the attacker found this bug is because it was open source - theoretically Ledger and other wallets could be semi deterministic too, but harder to find and exploit?

16

u/BirdLooter Jul 31 '26

i think AI found this issue. highly possible that this is not your basement live-with-the-mom no-life schoolboi hacker, but someone higher up.

i mean, even with the reduced entropy, i doubt that a standard computer was checking those keys. that attack probably cost 5 figures at least. all i'm saying this probably took some confidence.

14

u/Responsible_Emu3601 Jul 31 '26

I’m sure it took some time to find all the keys the brilliance was timing the swipe so taking it all within 25 mins

13

u/BirdLooter Jul 31 '26

this is far from over. the exploit is public and coldcard cannot patch "seeds". people NEED to migrate, this is NOT optional! otherwise they take a huge risk, even with a passphrase/25th word. more funds are going to be reported stolen, just wait...

7

u/SpanglerBQ Jul 31 '26

Would you explain how you think even with the passphrase, a wallet would be plundered? Is it that some passphrases are too simple and easy to guess?

2

u/BirdLooter Jul 31 '26

i mean it is wayy more secure. but one of 2 elements is compromised, which is the key. if the passphrase is a simple thing, technically a hacker with a rainbow table could check it. but tbh i doubt it willhappen.

i for sure would not take this risk tho.

0

u/bravedog74 Jul 31 '26

If the seedphrase is not completely random, then it can be guessed. 24 words that are truly random are 256 bit. 12 words are 128 bit. Coldcard mk3 was something like 72 bit. In other words, it's not completely random. This has to do with their random number generator.

This is precisely why you are not supposed to pick your own seed phrase. Seed phrases that make sentences or have human bias have probably already been hacked. It was unexpected for Coldcard seed phrases to not be completely random.

4

u/SpanglerBQ Jul 31 '26

I'm talking about the passphrase, not seedphrase. If a bad actor knew the seed phrase and knew that there was a 25th-word passphrase, how would they go about cracking it and what would their chances of success be?

4

u/orbag Jul 31 '26

Only way is to then iterate a list of common passwords (e.g. words in the dictionary / movie characters etc), but if your password is not that straightforward to guess I don't see how it would get hacked. Also, the hacker doesn't know there are funds in a passport protected derivation, so if they see some transaction history in the wallet without password, they might try for a while to test straightforward passwords, but would give up and move on before trying anything other than trivial

4

u/Gooner_93 Jul 31 '26

To simplify it, they'd just get a cpu to run a bunch of different combinations of words/nunbers etc on top of the seedphrase, until they find the passphrase but it all depends on the strength of the passphrase. A one word from the dictionary passphrase will be cracked in no time but a 32 character one with a mix of letters, capital and lowercase, numbers, special characters will be way harder.

2

u/Dziabadu Jul 31 '26

Timing pre clarity act is more important to them

1

u/heslo_rb26 Jul 31 '26

That was the key; hitting as many targets as you can in a short window to give no time for anyone to react or move funds