🚨 New COLDCARD firmware is available: 5.6.1 for Mk4/Mk5 and 1.5.1Q for Q.
This release follows three weeks of sustained review since our July 31 hotfix. We continue to acknowledge the customers who suffered severe financial losses from the seed-generation attack.
Every newly generated seed now requires one source of user entropy: at least 65 key presses with unpredictable timing, 50 physical dice rolls, or 128 physical coin flips. This input is combined with fresh entropy from the STM32 TRNG, SE1, and SE2.
The release also adds staged-PSBT verification immediately before signing, stronger USB and firmware-update boundaries, improved Delta Mode isolation, active-wallet backup fixes, stronger RNG initialization and fault checks, safer SIGHASH defaults, and many additional security and correctness improvements.
Important: Updating does not repair an existing seed generated on affected firmware. If the advisory applies to your seed, update your device, generate and verify a new seed, then move your funds.
We strongly recommend that all Mk4, Mk5, and Q users update and verify the signed firmware download.
Thank you to every researcher who reported issues, reproduced edge cases, reviewed fixes, and helped make this release stronger.
Show more
NEW: Coinkite issues a new Coldcard firmware update to fix seed phrase security.
Earlier vulnerable seeds remain unsafe and should be replaced.
Ok full breakdown of what happened.
What was affected
They got read / write access to private and public repos and tried to spread malware through it. It was caught pretty early and all affected repos have been fixed.
What was not affected
No iOS apps, android apps, npm releases. Just the github token.
How did it happen
While doing research for the article tracing the wave 1 attacker of the coldcard hack I rented GPUs from
@vast_ai. Vast AI is basically a marketplace where you can rent GPU time on random peoples GPUs.
The rust/cuda code that ran on the GPU was on a private docker container in Github Container Registry (GHCR). To give the GPU access to this private docker image I made a github token running `gh auth refresh -s write:packages`.
This token had access not only to GHCR, but by default gh cli auth tokens have access to repo read/write. One of the GPUs I rented must have been compromised and they were able to steal the token for GHCR and use it to push to my git repos.
Lessons Learned
1. Treat vastai instances as completely untrusted or don't use them at all.
2. Never use gh auth to create tokens even tho its faster than creating a fine grained PAT through the web.
3. Make sure the tokens you use are highly specific and have expiration dates.
Show more
For anyone still using their Coldcard like me, or cares to use for anything else, a new firmware dropped dealing with some of the stability issues with the original patch and changes to the key generation flow to mandate user provided entropy input.
Show more
I think I'm finally at a point where I can put my finger a little more articulately on the gap that is left in the wake of the Coldcard incident, and it's honestly a lot more important and fundamental than I initially thought.
It's not just losing "airgaps" or a specific feature...it's literally losing a MASSIVE degree of freedom that just doesn't exist anywhere else really in the hardware offerings in this space (other than DIY projects, which to each though own, I am not interested in using).
Coldcard didn't require a specific app to sign transactions. It didn't require an app to generate keys. It didn't require an app to update your device firmware.
It wasn't just the airgap, and security arguments around that, it was the FREEDOM that came with that. _You did not depend on Coinkite in anyway to actually use your device after you bought it from them_.
Name me another device you can say that about. Show me one reputable hardware wallet that doesn't REQUIRE their app to generate keys, or update firmware, doesn't leak your xpub to their server during initial set up if your computer is online.
As someone who has only used Coldcard for close to a decade, the reality of how much vendor lock, and dependency on manufacturers software, and the inability to opt out of that or the information leaks it creates is finally sinking in.
It's disgusting. There are a lot of solid teams out there, solid hardware architectures, solid devices, but the totality of the entire user experience around all of them in one way or another leaves me feeling gross.
The idea of using any of them makes me feel like I am trapped, not fully in control of my own money. Just the thought feels constricting.
I don't know what to do about this, and I know for a lot of normie users these things won't matter, but they do to me. It's incredibly disappointing, and I don't know what to do about it.
Show more
Important: If you generated a seed on affected firmware and haven’t migrated, update your COLDCARD, create a new seed with our guidance, then move your funds to it.
Updating alone does not secure an affected seed.
Migration, dice and passphrase guidance:
Show more
The only reason all these vulnerabilities were found was because someone pointed K3 at Bitcoin apps.
And Bitcoin is one of the most secure and harden FOSS projects on the planet.
Now the rest of the world is soon going to understand practically nothing is secure.
Buckle up.
Show more
Yesterday I began fully integrating the
@OpenAI trust cyber program into my Bitcoin Red Team efforts.
This morning I woke up to see this.
I am now being blocked from doing additional analysis on a codebase which I've already responsibly disclosed to, and have received confirmation had legitimate findings.
To be clear, this is after having already KYC'd and completed the onboarding process months ago to use the cyber capabilities OpenAI has to offer.
I am now prevented from being able to continue the investigation in a further effort to make sure their code changes are sufficient, as well as understand if there are other issues that have yet to be discovered.
It absolutely guts me as a patriotic American to have to do this, but I will be going back to using Chinese open source models to conduct my research to protect Bitcoin infrastructure.
Black hats will not hit these issues. The white hats will. We've hit a local minima in policy. Intelligence is unrestricted for those who don't follow rules, and those who engadge in harm reduction are left on the sidelines.
What are we doing in this country? How is this keeping people safe?
Please do something
@DavidSacks @sama @realDonaldTrump
Show more
Thanks everybody for the support despite this gigantic failure.
The lesson is that regardless of the reputation of any project, limit your hot wallet exposure!
Software is hard and unforgiving, even assisted with AI, I am at best cautiously optimistic of my own abilities.
Show more
My current informed perspective of the bitcoin software ecosystem.
🚨 🚨 🚨 macOS users! Update your mac! Critical bug fixed.
Crazy to think about what Bitcoin has gone through in the last week.
I will be watching with interest the attacks and responses that happen in the coming weeks and months.
I seriously doubt many will have as robust a response as we’ve had.
Some big projects will be completely wiped out.
Show more
After
@COLDCARDwallet firmawe bug, developers from red team, are working to find bugs in the code before everyone else!
Such a great initiative 👏 ✌️
#
bitcoin# #
redteam#
If you have a mailing list, for anything, I don't even care if it's some degen trading mailing list, and you already haven't sent out an alert about the Coldcard:
DO IT NOW. Please. Every single new person notified is another person saved.
Show more
BE AWARE:
If you are adding a new passphrase to your Mk Coldcard, be aware that you might be adding an additional [space] to your passphrase. Make sure this symbol does not appear after your last character before applying the passphrase.
Be sure to write down the fingerprint.
Show more
You can follow COLDCARD's next firmware updates on GitHub, we are focusing the next release and customer key migration.
Follow the warning below.
55 hours in, the Bitcoin Red Team campaign led by
@callebtc and
@Rob1Ham has grown to 24 contributors working around the clock scanning bitcoin ecosystem code for vulnerabilities using AI.
The numbers so far are staggering. 425 projects scanned, 6,700 total findings filed, and 1,029 classified as high or critical severity. That's roughly 19 high-or-critical findings per hour.
Perhaps the most notable detail: not a single vulnerability was found by a US frontier model. The team is spending $10k a day running open-weights models like Kimi K3 and Qwen 3.8 instead because US models refuse to assist with vulnerability research without heavy gatekeeping.
The campaign is funded by
@OpenSats and individual donors.
Show more