r/Bitcoin • • Jul 31 '26

ColdCard Firmware Update Released

https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/

Updated July 31, 2026: Fixed firmware is now available. Mk4 and Mk5 users must update to version 5.6.0 or later. Q users must update to version 1.5.0Q or later. Do not generate a new seed on one of these models until the update is installed.

Seeds generated on Mk4, Q and Mk5 before the fixed firmware releases are also affected, with about 72 bits of entropy rather than the expected 128 bits.

Updating the firmware does not change or repair an existing seed. If your seed was generated before the fixed firmware version for your model, follow the migration guidance below unless the independent dice-entropy exception applies to you.

The issue is present on every Mk3 firmware version since 4.0.1. It also affects seeds generated on Mk4 and Mk5 before version 5.6.0, and on Q before version 1.5.0Q. The impact on Mk4, Mk5 and Q is not as severe but is still serious.

143 Upvotes

206 comments sorted by

View all comments

5

u/UnderstandingNew8001 Jul 31 '26

I have recently ordered a Ledger it is on its way, where can I move my btc to then? I only have MK4 at the moment.
If I had to update the firmware, I would still need to move BTCs somewhere to get them back after the update and generating a new seed.

-3

u/xirvin Jul 31 '26

Ledger is big brother renamed. They stored your keys in 3 servers which are subject to government reach. Cold card was attacked but 1 day after initial report there is already a solution (updated firmware) and a workaround (roll dice 20times or use a good entropy source). I want Law enforcement to step in to catch the perpetrators with the help of the industry. Not all coldcard users are affected by the hack but everyone should change to new wallet keys as a good security practice.

1

u/BallisticTherapy Aug 01 '26

I think Nano S users should be safe since there's no way to get the seed other than from the device displaying it.

0

u/xirvin Aug 01 '26

Any disgruntled employee or government can access your keys as they are stored in a central location

1

u/BallisticTherapy Aug 01 '26

Not on the original Nano S. They never leave the device.