UPDATE: 🚨 COLDCARD released a new firmware that now requires users to provide physical entropy, such as 50 dice rolls or 65 key presses, before any new seed is generated.
🚨 New COLDCARD firmware is available: 5.6.1 for Mk4/Mk5 and 1.5.1Q for Q.
This release follows three weeks of sustained review since our July 31 hotfix. We continue to acknowledge the customers who suffered severe financial losses from the seed-generation attack.
Every newly generated seed now requires one source of user entropy: at least 65 key presses with unpredictable timing, 50 physical dice rolls, or 128 physical coin flips. This input is combined with fresh entropy from the STM32 TRNG, SE1, and SE2.
The release also adds staged-PSBT verification immediately before signing, stronger USB and firmware-update boundaries, improved Delta Mode isolation, active-wallet backup fixes, stronger RNG initialization and fault checks, safer SIGHASH defaults, and many additional security and correctness improvements.
Important: Updating does not repair an existing seed generated on affected firmware. If the advisory applies to your seed, update your device, generate and verify a new seed, then move your funds.
We strongly recommend that all Mk4, Mk5, and Q users update and verify the signed firmware download.
Thank you to every researcher who reported issues, reproduced edge cases, reviewed fixes, and helped make this release stronger.
Show more
NEW: Coinkite issues a new Coldcard firmware update to fix seed phrase security.
Earlier vulnerable seeds remain unsafe and should be replaced.
UPDATE: 🚨 COLDCARD released a new firmware that now requires users to provide physical entropy, such as 50 dice rolls or 65 key presses, before any new seed is generated.
🚨 New COLDCARD firmware is available: 5.6.1 for Mk4/Mk5 and 1.5.1Q for Q.
This release follows three weeks of sustained review since our July 31 hotfix. We continue to acknowledge the customers who suffered severe financial losses from the seed-generation attack.
Every newly generated seed now requires one source of user entropy: at least 65 key presses with unpredictable timing, 50 physical dice rolls, or 128 physical coin flips. This input is combined with fresh entropy from the STM32 TRNG, SE1, and SE2.
The release also adds staged-PSBT verification immediately before signing, stronger USB and firmware-update boundaries, improved Delta Mode isolation, active-wallet backup fixes, stronger RNG initialization and fault checks, safer SIGHASH defaults, and many additional security and correctness improvements.
Important: Updating does not repair an existing seed generated on affected firmware. If the advisory applies to your seed, update your device, generate and verify a new seed, then move your funds.
We strongly recommend that all Mk4, Mk5, and Q users update and verify the signed firmware download.
Thank you to every researcher who reported issues, reproduced edge cases, reviewed fixes, and helped make this release stronger.
Show more
I think I'm finally at a point where I can put my finger a little more articulately on the gap that is left in the wake of the Coldcard incident, and it's honestly a lot more important and fundamental than I initially thought.
It's not just losing "airgaps" or a specific feature...it's literally losing a MASSIVE degree of freedom that just doesn't exist anywhere else really in the hardware offerings in this space (other than DIY projects, which to each though own, I am not interested in using).
Coldcard didn't require a specific app to sign transactions. It didn't require an app to generate keys. It didn't require an app to update your device firmware.
It wasn't just the airgap, and security arguments around that, it was the FREEDOM that came with that. _You did not depend on Coinkite in anyway to actually use your device after you bought it from them_.
Name me another device you can say that about. Show me one reputable hardware wallet that doesn't REQUIRE their app to generate keys, or update firmware, doesn't leak your xpub to their server during initial set up if your computer is online.
As someone who has only used Coldcard for close to a decade, the reality of how much vendor lock, and dependency on manufacturers software, and the inability to opt out of that or the information leaks it creates is finally sinking in.
It's disgusting. There are a lot of solid teams out there, solid hardware architectures, solid devices, but the totality of the entire user experience around all of them in one way or another leaves me feeling gross.
The idea of using any of them makes me feel like I am trapped, not fully in control of my own money. Just the thought feels constricting.
I don't know what to do about this, and I know for a lot of normie users these things won't matter, but they do to me. It's incredibly disappointing, and I don't know what to do about it.
Show more
Important: If you generated a seed on affected firmware and haven’t migrated, update your COLDCARD, create a new seed with our guidance, then move your funds to it.
Updating alone does not secure an affected seed.
Migration, dice and passphrase guidance:
Show more
Important: If you generated a seed on affected firmware and haven’t migrated, update your COLDCARD, create a new seed with our guidance, then move your funds to it.
Updating alone does not secure an affected seed.
Migration, dice and passphrase guidance:
Show more
New release: Electrum 4.8.1. Please upgrade, this release contains important security fixes. Release notes and binaries:
Because you have to do checksum generation anyway, there's no point in generating the binary bits that map to words. You might as well just enter the dice rolls.
Now, that doesn't preclude you from verifying all inputs across various devices and systems.
Use dummy data first
- Roll the dice (at least 150-200 rolls), record the outcome (1-6).
- sha256 hash the dice to create 256 bits of hex.
- Use the hex to create the seed words.
- Do this simultaneously across three or more devices.
- Verify that each device agrees with each stage in each other device.
- Once verified, throw away these keys.
- Repeat if you think they might change across iterations
You can now assert that all of the devices, as they are, produce the same deterministic and highly improbable output.
As such, you can be reasonably assured that when it comes time to actually generate a real seed, you have some trust that those seeds are going to be generated according to your expectations.
Show more
🚨 🚨 🚨 macOS users! Update your mac! Critical bug fixed.
After
@COLDCARDwallet firmawe bug, developers from red team, are working to find bugs in the code before everyone else!
Such a great initiative 👏 ✌️
#
bitcoin# #
redteam#
Imagine if the Coldcard bug was responsibility disclosed.
How would you tell everyone "move funds immediately" without triggering mass pandemonium?
If you would like us to apply our existing retention policies to your data, we will exempt them from this protocol. Please confirm that you do not want us to preserve your data by contacting support @ coinkite . com
Show more
Update on Customer Data Retention
We want to inform our customers of a change to our data-handling practices in connection with the security incident disclosed on July 30, 2026.
As many of you know, our standard practice has been to automatically blank customer records after 120 days, retaining only email addresses and country of residence. We have also offered customers the option to request accelerated blanking at any time after delivery.
Due to legal obligations arising from the security incident, including the preservation of records that may be relevant to ongoing and anticipated legal proceedings, we have temporarily suspended our automated data-blanking process. This means that customer records that would otherwise have been blanked under our standard schedule will be retained until further notice.
However, if you would like us to apply our existing retention policies to your data, we will exempt them from this protocol. Please confirm that you do not want us to preserve your data by contacting support
@coinkite.com.
We understand that this is a departure from our published practices and that our customers value the privacy protections we have committed to. We want to be transparent about why this change has been made. We are required by law to preserve records that may be relevant to legal proceedings. This obligation applies regardless of our internal data-retention policies and overrides our standard deletion schedule.
During this period, all retained customer data will be stored securely and access will be restricted to authorized personnel. Retained data will not be used for any purpose other than compliance with legal obligations. We will resume our standard data-blanking practices as soon as we are legally permitted to do so.
If you have questions about this change, please contact support
@coinkite.com.
for more information and updated always check out
Show more
It stayed hidden because reviews (human and AI) confirmed the hardware TRNG code existed in the binary but never traced the actual linker resolution of rng_get() from seed generation. Identical function signatures let the MicroPython Yasmarang path resolve silently with no build error. The guard only checked definition, not value. No end-to-end call-path tests or entropy-quality checks on generated seeds existed. Open-source eyes rarely audit full multi-submodule link behavior this deeply.
Show more
Extremely important correction.
@jackmallers there wasn’t a weak entropy fallback. I think it’s important to be precise about what actually happened.
The weak PRNG (Yasmarang) wasn’t Coinkite’s fallback—it was MicroPython’s built-in general-purpose RNG, introduced upstream in May 2018. It didn’t become part of Coldcard’s seed generation until the libNgU migration in March 2021.
Most language runtimes include a non-cryptographic RNG like this for general purposes such as shuffling, timing jitter, or other non-security-related randomness. By itself, that’s not unusual.
Coinkite’s design intent was actually the opposite of having a software fallback: seed generation was supposed to rely exclusively on the hardware TRNG and never use the software RNG. Setting MICROPY_HW_ENABLE_RNG=0 was intended to disable that software path.
The issue is that this setting didn’t have the intended effect, and the symbol instead resolved to the runtime’s default implementation. So what people are describing as a “fallback” wasn’t an intentional design decision or a shortcut in the seed-generation logic—it was inherited behavior from the underlying platform that became active because of a link-time error.
Show more
Jack explains the ColdCard hack in non-technical terms:
Update on Customer Data Retention
We want to inform our customers of a change to our data-handling practices in connection with the security incident disclosed on July 30, 2026.
As many of you know, our standard practice has been to automatically blank customer records after 120 days, retaining only email addresses and country of residence. We have also offered customers the option to request accelerated blanking at any time after delivery.
Due to legal obligations arising from the security incident, including the preservation of records that may be relevant to ongoing and anticipated legal proceedings, we have temporarily suspended our automated data-blanking process. This means that customer records that would otherwise have been blanked under our standard schedule will be retained until further notice.
However, if you would like us to apply our existing retention policies to your data, we will exempt them from this protocol. Please confirm that you do not want us to preserve your data by contacting support
@coinkite.com.
We understand that this is a departure from our published practices and that our customers value the privacy protections we have committed to. We want to be transparent about why this change has been made. We are required by law to preserve records that may be relevant to legal proceedings. This obligation applies regardless of our internal data-retention policies and overrides our standard deletion schedule.
During this period, all retained customer data will be stored securely and access will be restricted to authorized personnel. Retained data will not be used for any purpose other than compliance with legal obligations. We will resume our standard data-blanking practices as soon as we are legally permitted to do so.
If you have questions about this change, please contact support
@coinkite.com.
for more information and updated always check out
Show more
THE COLDCARD BUG ODELL MENTIONED ON RHR IN 2021 WAS NOT THE RNG BUG
Claims circulating that a 2021 Rabbit Hole Recap episode proves Coinkite knew about the RNG vulnerability for years are incorrect.
The bug
@ODELLXYZ referenced was an entirely different issue affecting unreleased firmware v4.0.0, not the entropy/RNG flaw behind the recent wallet-draining attacks.
The issue was a USB serial REPL vulnerability.
According to Coinkite’s historical security disclosures, v4.0.0 was built and tested internally but never released publicly. Public users received v4.0.1, which already contained the fix.
The attack also required a malicious USB connection to the device. Matt Odell’s setup guides from the time explicitly instructed users to power the Coldcard from a battery instead of a laptop, a practice that would have mitigated this attack vector.
The 2021 podcast was discussing a legitimate security bug, but it was not the RNG vulnerability that enabled the 2026 thefts.
Show more
Extremely important correction.
@jackmallers there wasn’t a weak entropy fallback. I think it’s important to be precise about what actually happened.
The weak PRNG (Yasmarang) wasn’t Coinkite’s fallback—it was MicroPython’s built-in general-purpose RNG, introduced upstream in May 2018. It didn’t become part of Coldcard’s seed generation until the libNgU migration in March 2021.
Most language runtimes include a non-cryptographic RNG like this for general purposes such as shuffling, timing jitter, or other non-security-related randomness. By itself, that’s not unusual.
Coinkite’s design intent was actually the opposite of having a software fallback: seed generation was supposed to rely exclusively on the hardware TRNG and never use the software RNG. Setting MICROPY_HW_ENABLE_RNG=0 was intended to disable that software path.
The issue is that this setting didn’t have the intended effect, and the symbol instead resolved to the runtime’s default implementation. So what people are describing as a “fallback” wasn’t an intentional design decision or a shortcut in the seed-generation logic—it was inherited behavior from the underlying platform that became active because of a link-time error.
Show more
Jack explains the ColdCard hack in non-technical terms: