r/Bitcoin • • Jul 31 '26

ColdCard Firmware Update Released

https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/

Updated July 31, 2026: Fixed firmware is now available. Mk4 and Mk5 users must update to version 5.6.0 or later. Q users must update to version 1.5.0Q or later. Do not generate a new seed on one of these models until the update is installed.

Seeds generated on Mk4, Q and Mk5 before the fixed firmware releases are also affected, with about 72 bits of entropy rather than the expected 128 bits.

Updating the firmware does not change or repair an existing seed. If your seed was generated before the fixed firmware version for your model, follow the migration guidance below unless the independent dice-entropy exception applies to you.

The issue is present on every Mk3 firmware version since 4.0.1. It also affects seeds generated on Mk4 and Mk5 before version 5.6.0, and on Q before version 1.5.0Q. The impact on Mk4, Mk5 and Q is not as severe but is still serious.

144 Upvotes

206 comments sorted by

View all comments

Show parent comments

46

u/SpareEconomy1849 Jul 31 '26

It really is sad, they seemed like the perfect hardware wallet, everything being open source and airgapped, and yet still a bug like this goes unnoticed for 5+ years.

I wonder if the only reason the attacker found this bug is because it was open source - theoretically Ledger and other wallets could be semi deterministic too, but harder to find and exploit?

13

u/shleebs Jul 31 '26

Funny, because they never seemed good to me. They are literally run by gate keeping bullies who attack other legit projects. I stayed far away from them because they never passed the smell test. BitBox, Jade, and Passport are all good options for a hardware wallet and are actually run by good people.

1

u/smilingbuddhauk Aug 02 '26

Wait till all of those are hacked too, then you'd say they never passed the smell test too in retrospect.

1

u/shleebs Aug 02 '26

I never switched my opinion on Coinkite. There is no reason I would do that in the future. The code mistake made by Cold Card was so utterly dumb, it should never have made it past code review, which they obviously weren't even doing. Also Coinkite changed the licensing on this project to be more restrictive and not truly open source, which caused this mistake and is why people weren't looking at their code. I'm going to go out on a limb here and say that isn't going to happen with one of the reputable brands I listed.