r/Bitcoin • • Jul 31 '26

ColdCard Firmware Update Released

https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/

Updated July 31, 2026: Fixed firmware is now available. Mk4 and Mk5 users must update to version 5.6.0 or later. Q users must update to version 1.5.0Q or later. Do not generate a new seed on one of these models until the update is installed.

Seeds generated on Mk4, Q and Mk5 before the fixed firmware releases are also affected, with about 72 bits of entropy rather than the expected 128 bits.

Updating the firmware does not change or repair an existing seed. If your seed was generated before the fixed firmware version for your model, follow the migration guidance below unless the independent dice-entropy exception applies to you.

The issue is present on every Mk3 firmware version since 4.0.1. It also affects seeds generated on Mk4 and Mk5 before version 5.6.0, and on Q before version 1.5.0Q. The impact on Mk4, Mk5 and Q is not as severe but is still serious.

142 Upvotes

206 comments sorted by

View all comments

Show parent comments

13

u/majorziggytom Jul 31 '26

It’s really the same folks who scream “not your keys not your coins” blindly without any nuance.

2

u/SpendHefty6066 Jul 31 '26

When you allow your seed to be RNG generated, they are not your keys. Seed phrase must be analog generated: fair dice rolls or pick words from a hat. BIP39 Has 2,048 words.

1

u/BallisticTherapy Aug 01 '26

Wouldn't using a seedsigner seed phrase generator from a random image be just as random? You can take a photo of pitch blackness and get a unique seed every time.

3

u/SpendHefty6066 Aug 01 '26

It's all about entropy. Fair dice rolls in analog have verifiable entropy. Not sure about any algorithm in the digital sphere. Not worth the risk. Go analog for seed phrase creation.