(Headline blog post below) Basically, if you created a seed with Coldcard hardware wallets from 2021 to present, you need to update the firmware and generate a new seed like now. They incorrectly programmed the firmware to use a code library for random number generation verses the built in hardware which is superior. If you used a passphrase as an extra seed word, it’s not as bad, but you should still generate a new seed phrase. Or if hardcore, buy the dice kit and use that in addition. And I included the technical deep dive article below the advisory. And supposedly as reported by Bitcoin Mechanic, people have lost their funds. I have a Coldcard Q that had a few hundred dollars worth of Bitcoin, but I didn’t suffer a loss before getting the funds off and generating a new seed. Consequently, I like the hardware wallets and features, but I’m not sure they’re up to the security task of coding firmware for people with really large holdings, and they changed their opensource licensing prohibiting commercial reuse which really limits people examining the code and finding bugs like this. And the CEO is a bit of a douche here lately, so it will be interesting to see how they stand behind their product when people have lost money.
Looking at a Reddit post, the hacker was sending the compromised wallet coins to address bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r, and per my Block Explorer below it has 562 BTC worth over $36 million currently. People on X were talking about destroying their Coinkite hardware wallets, and you’d have to think the company might be done. Can they be sued into bankruptcy in Canada? And CEO @NVK has been a jerk to node runners of late in reference to BIP-110, which makes it all that much worse.

https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
- Published Jul 30, 2026

Updated July 31, 2026 at 9:33 a.m. EDT: Fixed firmware is now available. Mk4 and Mk5 users must update to version 5.6.0 or later. Q users must update to version 1.5.0Q or later. For Mk3, update to version 4.2.0 or later.
Do not generate a new seed on any of these models until the update is installed.
Coinkite is warning all users who generated a seed using a Mk3 on version 4.0.1 (March 2021) thru 4.1.9 (inclusive) that their funds may be at risk.
Seeds generated on Mk4, Q and Mk5 before the fixed firmware releases are also affected, with about 72 bits of entropy rather than the expected 128 bits.
Updating the firmware does not change or repair an existing seed. If your seed was generated before the fixed firmware version for your model, follow the migration guidance below unless the independent dice-entropy exception applies to you.
TAPSIGNER, OPENDIME and SATSCARD are not affected by this bug as they are different codebases
The issue is present on Mk3 firmware versions 4.0.1 through 4.1.9 inclusive. It also affects seeds generated on Mk4 and Mk5 before version 5.6.0, and on Q before version 1.5.0Q. The impact on Mk4, Mk5 and Q is not as severe but is still serious.
If You Added Dice When Creating the Seed
This issue affects the device-generated entropy. It does not remove independent entropy that you supplied with dice.
On affected firmware, COLDCARD hashed the device-generated seed together with every dice roll entered through Add Dice Rolls:
- 50 to 98 independent, private rolls: the dice input alone contributed at least 128 bits of entropy.
- 99 or more independent, private rolls: the dice input contributed approximately 256 bits of entropy.
- Fewer than 50 rolls, or you do not remember: follow the migration guidance in this advisory.
If you entered at least 50 fair and independent rolls, and the rolls were not recorded or exposed, we do not consider the resulting seed at risk from this RNG issue alone.
This applies to the final seed words shown after the dice were added. If you are uncertain which words you used, how many rolls you entered, or whether the rolls were private, migrate to a new seed.
Investigation and Firmware Status
Fixed Mk3 firmware version 4.2.0 has been released. Install it from the official Mk3 download page before generating a replacement seed.
Version 4.2.0 corrects new seed generation. It cannot repair a seed that was already generated by affected firmware.
This advisory reflects our early analysis. Our investigation is ongoing, and a formal technical review will be released as soon as possible.
If You Used a Passphrase
If the affected Mk3 seed was used with a strong, unique BIP-39 passphrase, that passphrase adds an independent barrier. The risk depends on the strength of the passphrase: a short, common, patterned, quoted, or reused passphrase may be guessable and should not be assumed to provide minimal risk.
This means a BIP-39 passphrase, not the COLDCARD PIN. Even with a strong passphrase, migrate to a newly generated seed as soon as practical. Continue to protect the passphrase and do not enter it into a website or an untrusted device.
If the Mk3 Is Your Only Device
Firmware 4.2.0 allows the Mk3 to generate a replacement seed correctly. You do not need a newer COLDCARD to complete the migration. Updating does not repair the affected seed already stored on the device.
Using one Mk3 for both wallets requires carefully switching between the old and new seeds. If a second device with fixed firmware is available, use it instead. If the Mk3 is your only device:
- Verify the written backup and wallet fingerprint of the affected seed.
- Install firmware 4.2.0 or later and confirm the version on the Mk3.
- On an empty Mk3, generate a new seed. Record and verify its backup, wallet fingerprint, and a receive address.
- Restore the affected seed and send a small test transaction to the verified address.
- Restore the new seed and confirm that its fingerprint matches and the test funds arrived.
- Restore the affected seed and move the remaining funds.
- Restore the new seed and confirm the migration. Keep the old backup until the complete balance has arrived and is confirmed.
The fixed firmware’s device-generated seed is sufficient. Dice rolls are optional and are not required to address this issue. A BIP-39 passphrase is a separate wallet-security choice; if used, back it up exactly and separately from the seed words.
Optional Dice-Only Seed on Mk3
After updating to version 4.2.0, users who are confident in their ability to perform and verify a dice-only migration can create a replacement seed without using the device’s random-number generator. This is optional; the normal New Wallet flow is corrected in version 4.2.0.
On an empty Mk3 running 4.2.0, select Import Existing > Dice Rolls and enter at least 99 independent rolls of a fair six-sided die. This dedicated dice-only path hashes the roll sequence directly; it does not use the device’s generator.
This is an advanced procedure. A one-device migration requires safely alternating between the old and new seeds. Before erasing either seed from the Mk3, verify its written backup and XFP. Verify a receive address for the dice-generated wallet, restore and verify the original wallet, and send a small test transaction before moving the remainder. Keep the original backup until the entire migration is confirmed.
The dice-roll sequence is secret key material. Never photograph it, save it digitally, or enter it into a networked computer. Read the COLDCARD dice-roll method before attempting this option.
Migrate Carefully
When migrating to a new key, calm and care should be applied. Rushing a wallet migration can create a more immediate risk than the issue you are trying to address.
Seeds generated on Mk3 versions 4.0.1 through 4.1.9, Mk4 and Mk5 before version 5.6.0, or Q before version 1.5.0Q are affected unless the independent dice-entropy exception applies. Before generating a replacement seed, update Mk3 to version 4.2.0 or later, Mk4 and Mk5 to version 5.6.0 or later, or Q to version 1.5.0Q or later:
- Confirm the fixed firmware version is installed.
- Generate a new seed on the updated COLDCARD.
- Record and verify its backup before depositing funds.
- Verify a new receive address on the COLDCARD screen.
- Send a small test transaction and confirm that the new wallet works.
- Only then move the remaining funds.
- Keep the old backup until the migration is complete and confirmed.
We are continuing to investigate. More details will follow.
Technical Deep Dive into the Entropy Issue
- Published Jul 30, 2026

Updated July 31, 2026 at 9:33 a.m. EDT: Fixed Mk3 firmware version 4.2.0 is now available.
What You Should Do
If your seed was generated on a Mk3 running firmware 4.0.1 through 4.1.9 without at least 50 independent, private dice rolls:
- Update the Mk3 to firmware version 4.2.0 or later before generating a replacement seed.
- Generate a completely new seed on the updated Mk3.
- Record and verify the new backup, wallet fingerprint, and a receive address.
- Send a small test transaction before moving the remaining funds.
- Keep the old backup until the migration is complete and confirmed.
Follow the dedicated Mk3 Security Advisory and migration instructions. Proceed calmly and verify every step.
If you added at least 50 fair, independent, private dice rolls when originally creating the seed, read the dice guidance in the advisory before migrating. We do not consider that seed at risk from this RNG issue alone.
If your seed was generated on affected Mk4, Mk5, or Q firmware without at least 50 independent, private dice rolls:
- Upgrade the firmware before generating any new seed: version 5.6.0 or later for Mk4 and Mk5, or version 1.5.0Q or later for Q and 4.2.0 for Mk3.
- Generate a completely new seed on the updated COLDCARD.
- The fixed firmware’s device-generated seed is sufficient. Dice rolls are optional and are not required to address this issue. A BIP-39 passphrase is a separate wallet-security choice.
- Back up the new seed and any passphrase carefully. Store the passphrase separately from the seed words.
- Power-cycle the COLDCARD and verify the wallet fingerprint and a receive address.
- Send a small test transaction before moving the remaining funds.
Updating the firmware does not repair a seed that was generated by affected firmware. A new seed must be generated and the funds migrated to the new wallet.
A passphrase creates a different wallet. Every passphrase—including one containing a typo—produces a valid wallet, so verify the wallet fingerprint before depositing funds. Losing the passphrase means losing access to that wallet.
Read the COLDCARD passphrase instructions and dice-roll instructions before using either option.
TAPSIGNER, OPENDIME, and SATSCARD are not affected because they use different codebases.
Summary
A complex and subtle series of bugs prevented the hardware RNG from contributing randomness in certain versions of the firmware. We were unaware of the bug until today. Changes introduced for Mk4 added entropy from SE1 and SE2, which partially reduced the impact on later models but did not restore the intended 128-bit security target.
The COLDCARD source code has always been open and publicly available, so we have to assume that someone used AI to review previous versions of our firmware and stumbled upon this issue. A few weeks ago, we used one of the best available AI models to review our code for security issues, and it did not find this bug or anything serious.
Both attackers and defenders have the same AI tools, but today it did not help us, and only helped the bad guys.
Technical Background
In 2021, we moved COLDCARD’s elliptic-curve operations to Bitcoin Core’s libsecp256k1, using the same implementation trusted by Bitcoin Core instead of maintaining a separate EC stack. That required adding libNgU, an embedded MicroPython library that exposes libsecp256k1 and other Bitcoin primitives.
The cryptographic choice was sound. The integration was not. During that migration, wallet seed generation moved from ckcc.rng_bytes() to ngu.random.bytes(). That path resolved rng_get() to MicroPython’s software fallback instead of COLDCARD’s hardware RNG implementation.
The bulk of randomness on the COLDCARD was coming from a PRNG that I didn’t know was actually in the source code base (it is from a submodule, Micropython). At the same time the carefully crafted TRNG code I wrote was being used, but just by chance, and only for less important things.
On Mk3, the active PRNG was seeded primarily from device and timing state. Under our current attack assumptions, we estimate the effective search space at about 40 bits. This is a preliminary estimate and may change as analysis continues.
During Mk4 development, we also mixed values from the TRNGs in SE1 and SE2 into the PRNG state as a backup to a backup. This additional entropy materially improves the situation for Mk4, Q and Mk5. Under the same current assumptions, we estimate the effective search space at about 72 bits.
Although Mk4, Q and Mk5 had additional secure-element entropy mixed into the PRNG state, they continued to draw most subsequent random values from the same MicroPython PRNG:
That file either builds PRNG code, or uses the STM32 hardware TRNG. Looking quickly at it, you’d think we got the TRNG version of get_rng() but in fact, I explicitly set MICROPY_HW_ENABLE_RNG to zero, thinking we didn’t need either version, but that’s not what it does. Because that code provided a PRNG with the same function signature as the desired code, the build completed without identifying the wrong implementation.
The MicroPython fallback was introduced upstream in May 2018. It did not enter COLDCARD wallet seed generation until the libNgU migration in March 2021. The affected Mk3 firmware range is 4.0.1 through 4.1.9. Version 4.2.0 corrects new seed generation. The eight-year figure therefore describes the age of the upstream fallback code, not the duration of affected COLDCARD seed generation.
Existing review confirmed that the intended TRNG implementation was present in the firmware binary, but did not verify which rng_get() implementation the wallet seed-generation path actually reached across the two submodules. No changes are needed in the COLDCARD firmware itself, just which code comes along for the ride.
Why Existing Review Did Not Catch It
Both RNG implementations had the same function signature, and the intended board-specific TRNG code was present in the binary. Existing review verified that code but did not verify end-to-end symbol resolution and call reachability from wallet seed generation.
The relevant preprocessor guard is visible in this section of code:
The guard used #ifndef, which tests whether MICROPY_HW_ENABLE_RNG is defined, rather than whether its value is nonzero. We defined that macro as zero, so the #error did not stop the build.
The hotfix now explicitly excludes MicroPython’s fallback PRNG object and adds a build-time RNG symbol check. The build fails unless the board-specific object defines the global rng_get() symbol and the upstream fallback object defines no symbols.
Next Steps
We have released emergency hotfixes for every affected model:
These hotfixes correct entropy generation. Updating does not repair seeds that were generated by earlier affected firmware; those seeds must still be replaced unless the independent dice-entropy exception applies.
At this point, many researchers and competitors have studied this bug and published their own analysis: