{"id":18224,"date":"2026-07-31T09:48:57","date_gmt":"2026-07-31T16:48:57","guid":{"rendered":"https:\/\/jasonsblog.ddns.net\/?p=18224"},"modified":"2026-07-31T09:48:57","modified_gmt":"2026-07-31T16:48:57","slug":"security-advisory-all-coldcard-hardware-wallets-update-firmware-generate-new-seed","status":"publish","type":"post","link":"https:\/\/jasonsblog.ddns.net\/index.php\/2026\/07\/31\/security-advisory-all-coldcard-hardware-wallets-update-firmware-generate-new-seed\/","title":{"rendered":"Security Advisory &#8211; All Coldcard Hardware Wallets &#8211; Update Firmware &#8211; Generate New Seed"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">(Headline blog post below) Basically, if you created a seed with Coldcard hardware wallets from 2021 to present, you need to update the firmware and generate a new seed like now. They incorrectly programmed the firmware to use a code library for random number generation verses the built in hardware which is superior. If you used a passphrase as an extra seed word, it&#8217;s not as bad, but you should still generate a new seed phrase. Or if hardcore, buy the dice kit and use that in addition. And I included the technical deep dive article below the advisory. And supposedly as reported by Bitcoin Mechanic, people have lost their funds. I have a Coldcard Q that had a few hundred dollars worth of Bitcoin, but I didn&#8217;t suffer a loss before getting the funds off and generating a new seed. Consequently, I like the hardware wallets and features, but I&#8217;m not sure they&#8217;re up to the security task of coding firmware for people with really large holdings, and they changed their opensource licensing prohibiting commercial reuse which really limits people examining the code and finding bugs like this. And the CEO is a bit of a douche here lately, so it will be interesting to see how they stand behind their product when people have lost money.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"Coldcard - Massive Breach, Funds Not Safe, Coinkite Downplaying it, TELL EVERYONE!\" width=\"1290\" height=\"726\" src=\"https:\/\/www.youtube.com\/embed\/HRxETD61K8E?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Looking at a Reddit <a href=\"https:\/\/redlib.catsarch.com\/r\/Bitcoin\/comments\/1vatgl4\/full_panic_one_of_my_wallets_was_drained\/\">post<\/a>, the hacker was sending the compromised wallet coins to address bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r, and per my Block Explorer below it has 562 BTC worth over $36 million currently. People on X were talking about destroying their Coinkite hardware wallets, and you&#8217;d have to think the company might be done. Can they be sued into bankruptcy in Canada? And CEO @NVK has been a jerk to node runners of late in reference to BIP-110, which makes it all that much worse.<\/p>\n\n\n\n<figure class=\"wp-block-image alignwide size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"678\" src=\"https:\/\/jasonsblog.ddns.net\/wp-content\/uploads\/2026\/07\/image-52-1024x678.png\" alt=\"\" class=\"wp-image-18230\" srcset=\"https:\/\/jasonsblog.ddns.net\/wp-content\/uploads\/2026\/07\/image-52-1024x678.png 1024w, https:\/\/jasonsblog.ddns.net\/wp-content\/uploads\/2026\/07\/image-52-300x199.png 300w, https:\/\/jasonsblog.ddns.net\/wp-content\/uploads\/2026\/07\/image-52-768x509.png 768w, https:\/\/jasonsblog.ddns.net\/wp-content\/uploads\/2026\/07\/image-52.png 1371w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/blog.coinkite.com\/coldcard-mk3-seed-generation-warning\/\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/blog.coinkite.com\/coldcard-mk3-seed-generation-warning\/<\/a><\/p>\n\n\n<div class=\"wp-block-ub-divider ub_divider ub-divider-orientation-horizontal\" id=\"ub_divider_fb2fd855-7d78-4b1c-803a-269abbf96849\"><div class=\"ub_divider_wrapper\" style=\"position: relative; margin-bottom: 2px; width: 100%; height: 2px; \" data-divider-alignment=\"center\"><div class=\"ub_divider_line\" style=\"border-top: 2px solid #ccc; margin-top: 2px; \"><\/div><\/div><\/div>\n\n\n<ul class=\"wp-block-list\">\n<li>Published Jul 30, 2026<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/blog.coinkite.com\/images\/posts-img\/security-advisory.png\" alt=\"Mk3 Security Advisory\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Updated July 31, 2026 at 9:33 a.m. EDT:<\/strong> Fixed firmware is now available. <strong>Mk4 and Mk5 users must update to <a href=\"https:\/\/coldcard.com\/downloads\/mk\">version 5.6.0 or later<\/a>. Q users must update to <a href=\"https:\/\/coldcard.com\/downloads\/q1\">version 1.5.0Q or later<\/a>. For Mk3, update to <a href=\"https:\/\/coldcard.com\/downloads\/mk3\">version 4.2.0 or later<\/a><\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Do not generate a new seed on any of these models until the update is installed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Coinkite is warning all users who generated a seed using a Mk3 on version 4.0.1 (March 2021) thru 4.1.9 (inclusive) that their funds may be at risk.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Seeds generated on Mk4, Q and Mk5 before the fixed firmware releases are also affected, with about 72 bits of entropy rather than the expected 128 bits.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Updating the firmware does not change or repair an existing seed. If your seed was generated before the fixed firmware version for your model, follow the migration guidance below unless the independent dice-entropy exception applies to you.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>TAPSIGNER, OPENDIME and SATSCARD are not affected by this bug as they are different codebases<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The issue is present on Mk3 firmware versions <a href=\"https:\/\/coldcard.com\/downloads\/mk3\">4.0.1 through 4.1.9 inclusive<\/a>. It also affects seeds generated on Mk4 and Mk5 before version 5.6.0, and on Q before version 1.5.0Q. The impact on Mk4, Mk5 and Q is not as severe but is still serious.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">If You Added Dice When Creating the Seed<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This issue affects the device-generated entropy. It does not remove independent entropy that you supplied with dice.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On affected firmware, COLDCARD <a href=\"https:\/\/github.com\/Coldcard\/firmware\/blob\/621e808712464688584fdffad9eba132cc7c27cd\/shared\/seed.py#L276-L332\">hashed the device-generated seed together with every dice roll<\/a> entered through <strong>Add Dice Rolls<\/strong>:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>50 to 98 independent, private rolls:<\/strong> the dice input alone contributed at least 128 bits of entropy.<\/li>\n\n\n\n<li><strong>99 or more independent, private rolls:<\/strong> the dice input contributed approximately 256 bits of entropy.<\/li>\n\n\n\n<li><strong>Fewer than 50 rolls, or you do not remember:<\/strong> follow the migration guidance in this advisory.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">If you entered at least 50 fair and independent rolls, and the rolls were not recorded or exposed, we do not consider the resulting seed at risk from this RNG issue alone.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This applies to the final seed words shown after the dice were added. If you are uncertain which words you used, how many rolls you entered, or whether the rolls were private, migrate to a new seed.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Investigation and Firmware Status<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Fixed Mk3 firmware version 4.2.0 has been released. Install it from the official Mk3 download page before generating a replacement seed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Version 4.2.0 corrects new seed generation. It cannot repair a seed that was already generated by affected firmware.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This advisory reflects our early analysis. Our investigation is ongoing, and a formal technical review will be released as soon as possible.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">If You Used a Passphrase<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If the affected Mk3 seed was used with a strong, unique BIP-39 passphrase, that passphrase adds an independent barrier. The risk depends on the strength of the passphrase: a short, common, patterned, quoted, or reused passphrase may be guessable and should not be assumed to provide minimal risk.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This means a BIP-39 passphrase, not the COLDCARD PIN. Even with a strong passphrase, migrate to a newly generated seed as soon as practical. Continue to protect the passphrase and do not enter it into a website or an untrusted device.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">If the Mk3 Is Your Only Device<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Firmware 4.2.0 allows the Mk3 to generate a replacement seed correctly. You do not need a newer COLDCARD to complete the migration. Updating does not repair the affected seed already stored on the device.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Using one Mk3 for both wallets requires carefully switching between the old and new seeds. If a second device with fixed firmware is available, use it instead. If the Mk3 is your only device:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Verify the written backup and wallet fingerprint of the affected seed.<\/li>\n\n\n\n<li><a href=\"https:\/\/coldcard.com\/downloads\/mk3\">Install firmware 4.2.0 or later<\/a> and confirm the version on the Mk3.<\/li>\n\n\n\n<li>On an empty Mk3, generate a new seed. Record and verify its backup, wallet fingerprint, and a receive address.<\/li>\n\n\n\n<li>Restore the affected seed and send a small test transaction to the verified address.<\/li>\n\n\n\n<li>Restore the new seed and confirm that its fingerprint matches and the test funds arrived.<\/li>\n\n\n\n<li>Restore the affected seed and move the remaining funds.<\/li>\n\n\n\n<li>Restore the new seed and confirm the migration. Keep the old backup until the complete balance has arrived and is confirmed.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">The fixed firmware\u2019s device-generated seed is sufficient. Dice rolls are optional and are not required to address this issue. A BIP-39 passphrase is a separate wallet-security choice; if used, back it up exactly and separately from the seed words.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Optional Dice-Only Seed on Mk3<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">After updating to version 4.2.0, users who are confident in their ability to perform and verify a dice-only migration can create a replacement seed without using the device\u2019s random-number generator. This is optional; the normal <code>New Wallet<\/code> flow is corrected in version 4.2.0.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On an empty Mk3 running 4.2.0, select <code>Import Existing &gt; Dice Rolls<\/code> and enter at least 99 independent rolls of a fair six-sided die. This dedicated dice-only path hashes the roll sequence directly; it does not use the device\u2019s generator.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is an advanced procedure. A one-device migration requires safely alternating between the old and new seeds. Before erasing either seed from the Mk3, verify its written backup and XFP. Verify a receive address for the dice-generated wallet, restore and verify the original wallet, and send a small test transaction before moving the remainder. Keep the original backup until the entire migration is confirmed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The dice-roll sequence is secret key material. Never photograph it, save it digitally, or enter it into a networked computer. Read the <a href=\"https:\/\/coldcard.com\/docs\/verifying-dice-roll-math\/\">COLDCARD dice-roll method<\/a> before attempting this option.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Migrate Carefully<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">When migrating to a new key, calm and care should be applied. Rushing a wallet migration can create a more immediate risk than the issue you are trying to address.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Seeds generated on Mk3 versions 4.0.1 through 4.1.9, Mk4 and Mk5 before version 5.6.0, or Q before version 1.5.0Q are affected unless the independent dice-entropy exception applies. Before generating a replacement seed, update Mk3 to version 4.2.0 or later, Mk4 and Mk5 to version 5.6.0 or later, or Q to version 1.5.0Q or later:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Confirm the fixed firmware version is installed.<\/li>\n\n\n\n<li>Generate a new seed on the updated COLDCARD.<\/li>\n\n\n\n<li>Record and verify its backup before depositing funds.<\/li>\n\n\n\n<li>Verify a new receive address on the COLDCARD screen.<\/li>\n\n\n\n<li>Send a small test transaction and confirm that the new wallet works.<\/li>\n\n\n\n<li>Only then move the remaining funds.<\/li>\n\n\n\n<li>Keep the old backup until the migration is complete and confirmed.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">We are continuing to investigate. More details will follow.<\/p>\n\n\n<div class=\"wp-block-ub-divider ub_divider ub-divider-orientation-horizontal\" id=\"ub_divider_a88b8983-96ec-47cc-a452-967ade281472\"><div class=\"ub_divider_wrapper\" style=\"position: relative; margin-bottom: 2px; width: 100%; height: 2px; \" data-divider-alignment=\"center\"><div class=\"ub_divider_line\" style=\"border-top: 2px solid #ccc; margin-top: 2px; \"><\/div><\/div><\/div>\n\n\n<h1 class=\"wp-block-heading\">Technical Deep Dive into the Entropy Issue<\/h1>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Published Jul 30, 2026<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/blog.coinkite.com\/images\/posts-img\/security-advisory-details.png\" alt=\"Technical Deep Dive into the Entropy Issue\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Updated July 31, 2026 at 9:33 a.m. EDT:<\/strong> Fixed Mk3 firmware version 4.2.0 is now available.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What You Should Do<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>If your seed was generated on a Mk3 running firmware 4.0.1 through 4.1.9 without at least 50 independent, private dice rolls:<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Update the Mk3 to <a href=\"https:\/\/coldcard.com\/downloads\/mk3\">firmware version <strong>4.2.0 or later<\/strong><\/a> before generating a replacement seed.<\/li>\n\n\n\n<li>Generate a completely new seed on the updated Mk3.<\/li>\n\n\n\n<li>Record and verify the new backup, wallet fingerprint, and a receive address.<\/li>\n\n\n\n<li>Send a small test transaction before moving the remaining funds.<\/li>\n\n\n\n<li>Keep the old backup until the migration is complete and confirmed.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Follow the dedicated <a href=\"https:\/\/blog.coinkite.com\/coldcard-mk3-seed-generation-warning\/\">Mk3 Security Advisory and migration instructions<\/a>. Proceed calmly and verify every step.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you added at least 50 fair, independent, private dice rolls when originally creating the seed, read the dice guidance in the advisory before migrating. We do not consider that seed at risk from this RNG issue alone.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>If your seed was generated on affected Mk4, Mk5, or Q firmware without at least 50 independent, private dice rolls:<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><a href=\"https:\/\/coldcard.com\/docs\/upgrade\/\">Upgrade the firmware<\/a> before generating any new seed: version <strong>5.6.0 or later for Mk4 and Mk5<\/strong>, or version <strong>1.5.0Q or later for Q<\/strong> and <strong>4.2.0 for Mk3<\/strong>.<\/li>\n\n\n\n<li>Generate a completely new seed on the updated COLDCARD.<\/li>\n\n\n\n<li>The fixed firmware\u2019s device-generated seed is sufficient. Dice rolls are optional and are not required to address this issue. A BIP-39 passphrase is a separate wallet-security choice.<\/li>\n\n\n\n<li>Back up the new seed and any passphrase carefully. Store the passphrase separately from the seed words.<\/li>\n\n\n\n<li>Power-cycle the COLDCARD and verify the wallet fingerprint and a receive address.<\/li>\n\n\n\n<li>Send a small test transaction before moving the remaining funds.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Updating the firmware does <strong>not<\/strong> repair a seed that was generated by affected firmware. A new seed must be generated and the funds migrated to the new wallet.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A passphrase creates a different wallet. Every passphrase\u2014including one containing a typo\u2014produces a valid wallet, so verify the wallet fingerprint before depositing funds. Losing the passphrase means losing access to that wallet.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Read the <a href=\"https:\/\/coldcard.com\/docs\/passphrase\/\">COLDCARD passphrase instructions<\/a> and <a href=\"https:\/\/coldcard.com\/docs\/verifying-dice-roll-math\/\">dice-roll instructions<\/a> before using either option.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>TAPSIGNER, OPENDIME, and SATSCARD are not affected because they use different codebases.<\/strong><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Summary<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A complex and subtle series of bugs prevented the hardware RNG from contributing randomness in certain versions of the firmware. We were unaware of the bug until today. Changes introduced for Mk4 added entropy from SE1 and SE2, which partially reduced the impact on later models but did not restore the intended 128-bit security target.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The COLDCARD source code has always been open and publicly available, so we have to assume that someone used AI to review previous versions of our firmware and stumbled upon this issue. A few weeks ago, we used one of the best available AI models to review our code for security issues, and it did not find this bug or anything serious.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Both attackers and defenders have the same AI tools, but today it did not help us, and only helped the bad guys.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Technical Background<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In 2021, we moved COLDCARD\u2019s elliptic-curve operations to Bitcoin Core\u2019s <code>libsecp256k1<\/code>, using the same implementation trusted by Bitcoin Core instead of maintaining a separate EC stack. That required adding libNgU, an embedded MicroPython library that exposes <code>libsecp256k1<\/code> and other Bitcoin primitives.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The cryptographic choice was sound. The integration was not. During that migration, wallet seed generation moved from <code>ckcc.rng_bytes()<\/code> to <code>ngu.random.bytes()<\/code>. That path resolved <code>rng_get()<\/code> to MicroPython\u2019s software fallback instead of COLDCARD\u2019s hardware RNG implementation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The bulk of randomness on the COLDCARD was coming from a PRNG that I didn\u2019t know was actually in the source code base (it is from a submodule, Micropython). At the same time the carefully crafted TRNG code I wrote <strong>was being<\/strong> used, but just by chance, and only for less important things.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On Mk3, the active PRNG was seeded primarily from device and timing state. Under our current attack assumptions, we estimate the effective search space at about 40 bits. This is a preliminary estimate and may change as analysis continues.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">During Mk4 development, we also mixed values from the TRNGs in SE1 and SE2 into the PRNG state as a backup to a backup. This additional entropy materially improves the situation for Mk4, Q and Mk5. Under the same current assumptions, we estimate the effective search space at about 72 bits.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Although Mk4, Q and Mk5 had additional secure-element entropy mixed into the PRNG state, they continued to draw most subsequent random values from the same MicroPython PRNG:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/github.com\/micropython\/micropython\/blob\/master\/ports\/stm32\/rng.c#L36\">micropython\/ports\/stm32\/rng.c<\/a><\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">That file either builds PRNG code, or uses the STM32 hardware TRNG. Looking quickly at it, you\u2019d think we got the TRNG version of <code>get_rng()<\/code> but in fact, I explicitly set <code>MICROPY_HW_ENABLE_RNG<\/code> to zero, thinking we didn\u2019t need either version, but that\u2019s not what it does. Because that code provided a PRNG with the same function signature as the desired code, the build completed without identifying the wrong implementation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The MicroPython fallback was <a href=\"https:\/\/github.com\/micropython\/micropython\/commit\/f68e722005\">introduced upstream in May 2018<\/a>. It did not enter COLDCARD wallet seed generation until the <a href=\"https:\/\/github.com\/Coldcard\/firmware\/commit\/b18723dddb6d751c39978e4364b56b2414f68b47\">libNgU migration in March 2021<\/a>. The affected Mk3 firmware range is 4.0.1 through 4.1.9. Version 4.2.0 corrects new seed generation. The eight-year figure therefore describes the age of the upstream fallback code, not the duration of affected COLDCARD seed generation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Existing review confirmed that the intended TRNG implementation was present in the firmware binary, but did not verify which <code>rng_get()<\/code> implementation the wallet seed-generation path actually reached across the two submodules. No changes are needed in the COLDCARD firmware itself, just which code comes along for the ride.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Why Existing Review Did Not Catch It<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Both RNG implementations had the same function signature, and the intended board-specific TRNG code was present in the binary. Existing review verified that code but did not verify end-to-end symbol resolution and call reachability from wallet seed generation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The relevant preprocessor guard is visible in this section of code:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/github.com\/switck\/libngu\/blob\/cf1988aa54969a7d2dcef261ee664a41a7013262\/ngu\/random.c#L22-L31\">random.c:22-31<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The guard used <code>#ifndef<\/code>, which tests whether <code>MICROPY_HW_ENABLE_RNG<\/code> is defined, rather than whether its value is nonzero. We defined that macro as zero, so the <code>#error<\/code> did not stop the build.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The hotfix now explicitly excludes MicroPython\u2019s fallback PRNG object and adds a build-time RNG symbol check. The build fails unless the board-specific object defines the global <code>rng_get()<\/code> symbol and the upstream fallback object defines no symbols.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Next Steps<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">We have released emergency hotfixes for every affected model:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/coldcard.com\/downloads\/mk3\">Version 4.2.0 for Mk3<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/coldcard.com\/downloads\/mk\">Version 5.6.0 for Mk4 and Mk5<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/coldcard.com\/downloads\/q1\">Version 1.5.0Q for Q<\/a><\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">These hotfixes correct entropy generation. Updating does not repair seeds that were generated by earlier affected firmware; those seeds must still be replaced unless the independent dice-entropy exception applies.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At this point, many researchers and competitors have studied this bug and published their own analysis:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/x.com\/LLFOURN\/status\/2082990000896147942\">LLFOURN: Attack-cost model for affected COLDCARD generations<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/engineering.block.xyz\/blog\/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware\">Block: Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>(Headline blog post below) Basically, if you created a seed with Coldcard hardware wallets from 2021 to present, you need to update the firmware and generate a new seed like now. They incorrectly programmed the firmware to use a code library for random number generation verses the built in hardware which is superior. If you [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[],"class_list":["post-18224","post","type-post","status-publish","format-standard","hentry","category-tech"],"blocksy_meta":[],"featured_image_src":null,"author_info":{"display_name":"Jason","author_link":"https:\/\/jasonsblog.ddns.net\/index.php\/author\/jturning\/"},"_links":{"self":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/18224","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/comments?post=18224"}],"version-history":[{"count":6,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/18224\/revisions"}],"predecessor-version":[{"id":18237,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/18224\/revisions\/18237"}],"wp:attachment":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/media?parent=18224"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/categories?post=18224"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/tags?post=18224"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}