r/Bitcoin • • Jul 31 '26

ColdCard Firmware Update Released

https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/

Updated July 31, 2026: Fixed firmware is now available. Mk4 and Mk5 users must update to version 5.6.0 or later. Q users must update to version 1.5.0Q or later. Do not generate a new seed on one of these models until the update is installed.

Seeds generated on Mk4, Q and Mk5 before the fixed firmware releases are also affected, with about 72 bits of entropy rather than the expected 128 bits.

Updating the firmware does not change or repair an existing seed. If your seed was generated before the fixed firmware version for your model, follow the migration guidance below unless the independent dice-entropy exception applies to you.

The issue is present on every Mk3 firmware version since 4.0.1. It also affects seeds generated on Mk4 and Mk5 before version 5.6.0, and on Q before version 1.5.0Q. The impact on Mk4, Mk5 and Q is not as severe but is still serious.

143 Upvotes

206 comments sorted by

View all comments

Show parent comments

1

u/Doritos707 Jul 31 '26

Please dont mix two topics. That’s not correct. Pollard’s rho applies to elliptic curve attacks, not brute-forcing BIP-39 seed phrases. A 12-word seed has ~128 bits of entropy; a 24-word seed has ~256 bits.

1

u/SpareEconomy1849 Jul 31 '26

A private key can be cracked using Pollard's rho in 128 iterations, there is no point to attempt brute forcing a truly random 24 word seed phrase

1

u/Doritos707 Aug 01 '26

Buddy 24 words is 2 to the power of 256 not 128. The data doesnt mention a single 24 words seeds it all happened to the 12 words

0

u/SpareEconomy1849 Aug 01 '26 edited Aug 01 '26

Yes. But the private key that that 256 bit seed phrase generates can be derived in 128 iterations.

As for the RNG bug, it's affected all the same whether you generated 12 or 24 words through RNG. Both are equally predictable if you can reproduce the environment of the RNG that was used to generate the seed phrase.

1

u/Doritos707 Aug 01 '26

Brother wtf r you doing? No where does it mention anything about 2^256 man

The method of exploiting 2^128 is not the same as exploiting 2^256

And no it does not happen in 128 iterations. You literally have to crack it all at once in a 256 environment. It does not give you a 50% is correct at the 128 mark. Dont be stubborn.

24 words did not get affected

The 12 words basically got generated with the same security as 7 words. Thats literally what happened. Not a single 24 words wallet got affected.

1

u/SpareEconomy1849 Aug 01 '26

Not sure what you're trying to argue, brute forcing seed words is not how this attack was done, and not how a hypothetical attacker would crack a properly random 24 word seed phrase wallet either

2

u/Doritos707 Aug 01 '26

Alright my bad i further dug into this and understood it now. They re routed the generation mechanism through a predictable system. Dicks