Secretus logo

COLDCARD RNG Vulnerability: Is Your Bitcoin at Risk?

·7 min read

Coinkite has disclosed a serious COLDCARD seed-generation vulnerability affecting Mk2, Mk3, Mk4, Mk5 and Q devices running specified firmware. The issue reduced the randomness available when some wallets generated their recovery seed. An attacker who can search the smaller space may be able to reconstruct a weak seed and spend the Bitcoin it controls without physically possessing the hardware wallet.

Calling this a “COLDCARD hack” is understandable, but incomplete. Coinkite's advisory does not describe attackers remotely breaking into every device. The core problem is cryptographic: some seeds created by affected firmware may be more predictable than users were promised. A hardware wallet cannot protect funds if the master secret it generated lacks enough entropy.

Which COLDCARD firmware is affected?

Coinkite's 30 July advisory, updated on 1 August 2026, identifies the following affected seed-generation ranges. The important question is the firmware that created the seed, not only the firmware currently displayed by the device.

  • Mk2 and Mk3: seeds generated by firmware 4.0.1 through 4.1.9 inclusive.
  • Mk4 and Mk5 standard: seeds generated before version 5.6.0.
  • COLDCARD Q standard: seeds generated before version 1.5.0Q.
  • Mk4 and Mk5 Edge: seeds generated before version 6.6.0X.
  • Q Edge: seeds generated before version 6.6.0QX.

TAPSIGNER, OPENDIME and SATSCARD are not affected because they use different codebases. Coinkite says seeds generated on Mk4, Mk5 and Q before the fixed releases had roughly 72 bits of entropy instead of the expected 128 bits. That is a meaningful security reduction, even though it is not the same as publishing the seed itself.

Updating firmware does not repair an old seed

This is the most important operational detail. Installing fixed firmware prevents the device from generating another affected seed, but it cannot add randomness to seed words that already exist. If an affected version created the wallet, the durable fix is to generate a new seed using corrected firmware and move the funds to addresses controlled by that new wallet.

The fixed minimum versions published by Coinkite are 4.2.0 for Mk2/Mk3, 5.6.0 for standard Mk4/Mk5, 1.5.0Q for standard Q, 6.6.0X for Mk4/Mk5 Edge and 6.6.0QX for Q Edge. Standard and Edge are separate release tracks: a numerically higher old Edge release is not automatically fixed.

Two protections may change the immediate risk

Independent dice entropy

The vulnerable code still mixed user-supplied dice input into the final seed. Coinkite says at least 50 fair, independent and private dice rolls contributed at least 128 bits of entropy. If you entered 50 or more rolls, never recorded or exposed them, and know the displayed final seed came after that process, the company does not consider the seed at risk from this RNG issue alone. If the number or privacy of the rolls is uncertain, treat the wallet as affected.

A strong, unique BIP-39 passphrase

A strong BIP-39 passphrase adds an independent secret that an attacker must also find. It can reduce immediate exposure, but it does not repair the weak seed. A short, common, patterned, quoted or reused passphrase may be guessable. The device PIN is not a BIP-39 passphrase and does not provide this protection against offline seed search.

How to migrate an affected COLDCARD wallet safely

  1. Do not expose the old seed. Never type seed words, passphrases or private keys into a website, support form or networked computer.
  2. Verify the official advisory. Navigate independently to Coinkite or COLDCARD; do not trust firmware or migration links from email, social media or direct messages.
  3. Confirm the correct release track. Install the fixed standard or Edge firmware for the exact model and verify the version on the device.
  4. Create a genuinely new seed. An old seed imported into updated firmware remains the same old seed. Record the replacement backup offline and verify it.
  5. Verify the destination on-device. Confirm the new wallet fingerprint and a receive address on the COLDCARD display.
  6. Send a small test transaction. Restore or reopen the new wallet and confirm the test before transferring the remaining balance.
  7. Move the full balance. Once verified, transfer all funds controlled by the affected seed, including passphrase wallets and accounts that may not appear in the default view.
  8. Keep the old backup temporarily. Retain it until every intended transaction is confirmed, then clearly mark it as retired so it is never reused.

Watch for scams exploiting the advisory

Urgent hardware-wallet news creates ideal conditions for phishing. A fake “seed checker” can steal funds more quickly than an attacker performing cryptographic search. Coinkite support does not need your seed words, passphrase, PIN or private key to identify an affected model or firmware version. No legitimate migration requires entering those secrets on a website.

Slow down, verify every address on the trusted display and avoid improvising with the only copy of a wallet. The vulnerability is real, but a rushed migration can introduce a more immediate failure: a phishing loss, an incomplete backup or a transfer to the wrong wallet.

The broader cryptographic lesson

Secure elements, air gaps and transaction verification protect different parts of a wallet. None can compensate for a weak root secret. Random-number generation must be treated as a critical dependency, tested across hardware and firmware releases and supported by a recovery plan that lets users rotate keys without exposing them.

Sources

Share a secret the safe way

Start a 14-day trial to send; recipients open one-time links without an account.

Try Secretus