COLDCARD Security Advisory A seed-generation defect affected releases beginning with firmware 4.0.1. Fixed firmware is available. Existing affected seeds still require migration. Check status

CURRENT SECURITY STATUS

Fixed firmware is available for every supported COLDCARD model.

The fix corrects future seed generation. It does not repair an existing seed created on affected firmware.

FIXED RELEASES AVAILABLE Verified 2026-08-13

MINIMUM FIXED RELEASES

Check the release track, not only the model.

Mk2/Mk3 4.2.0 or later
Mk4/Mk5 standard 5.6.0 or later
Q standard 1.5.0Q or later
Mk4/Mk5 Edge 6.6.0X or later
Q Edge 6.6.0QX or later
An update is not a seed migration.

Updating corrects future seed generation but does not repair an existing affected seed. Follow the advisory unless its independent-dice exception applies.

WHAT TO DO

Use the path that matches your wallet.

Creating a new seed

Install a fixed release for your model and verify the signed download before creating the seed.

Using an existing seed

Follow the advisory's migration instructions. Updating the device alone does not repair the existing seed.

Used independent dice

Read the advisory's exact dice-roll conditions before deciding whether its exception applies to your seed.

Checking the release

Compare the SHA-256 hash and verify the signed signatures.txt file before installing firmware.

DIRECT ANSWERS

Direct answers about current COLDCARD security.

Is current COLDCARD firmware patched?

Published fixed releases are available for every supported model and track: Mk2/Mk3 4.2.0 or later; Mk4/Mk5 standard 5.6.0 or later; Q standard 1.5.0Q or later; Mk4/Mk5 Edge 6.6.0X or later; and Q Edge 6.6.0QX or later. A new seed generated while running the applicable fixed release uses the remediated seed-generation path. Updating firmware does not repair an existing affected seed.

Is COLDCARD safe to use now?

Current fixed releases contain the published seed-generation remediation and are the releases specified for generating new seeds under the current guidance. No hardware wallet is risk-free. Before generating a seed, install the applicable fixed release and verify the signed download. For an existing seed created on affected firmware, follow the advisory's migration guidance.

Does updating firmware change an existing seed?

No. A firmware update corrects future seed generation but does not change or repair an existing seed. Follow the advisory's migration guidance unless its independent-dice exception applies.

Does a strong BIP-39 passphrase repair an affected seed?

No. A strong, unique BIP-39 passphrase can add a barrier to use of the underlying seed, but it does not repair a seed generated on affected firmware. The advisory says passphrase users should migrate as soon as practical.

How do dice rolls affect the migration guidance?

For the affected Add Dice Rolls workflow, the advisory says that at least 50 fair, independent, private rolls whose sequence was never recorded or exposed provide at least 128 bits of added entropy; 99 or more provide about 256 bits. If those conditions are satisfied, the seed is not considered at risk from this RNG issue alone. With fewer rolls or uncertain conditions, migrate.

Was the fixed COLDCARD firmware independently audited?

The published evidence does not establish a complete independent audit of every fixed firmware binary. Independent reviewers performed targeted checks: a real-device hardware-RNG test on Mk4 5.6.0, source review across the fixed release lines, hotfix-mechanism review, and a reproducible build plus dice-path trace for Mk4/Mk5 5.6.0. These checks validate their stated scopes, not the absence of all defects.

Has the formal technical postmortem been published?

No. As of August 13, 2026, the formal technical postmortem remains in progress.

What does the term “hack” mean in this context?

The term “hack” can describe different events and is not used as a technical conclusion on this page. The published advisory documents a seed-generation defect in affected firmware releases and provides fixed-release and migration guidance. This page does not determine the cause of any individual reported loss.

PUBLIC DEVELOPMENT RECORD

COLDCARD firmware has been developed in public since 2018.

This timeline highlights verifiable milestones in the firmware repository. It is a project history, not a claim that every release received an independent security audit.

  1. Firmware source published

    The first signed public commit placed the COLDCARD firmware source and its subsequent development history in public view.

  2. First public firmware release

    The 1.0.0r2 release began the public Mk-series release record that is preserved in the repository.

  3. Reproducible builds introduced

    Firmware 4.0.0 documented a reproducible-build process so reviewers could compare released firmware with tagged source.

  4. Mk4 firmware line released

    Firmware 5.0.0 began the public Mk4 release line.

  5. COLDCARD Q firmware released

    The 1.0.0Q release established the public Q firmware history in the same repository.

  6. Mk5 source published

    Mk5 support and hardware details were added to the public firmware tree.

  7. RNG remediation released

    Fixed releases were published for the supported standard, legacy, and Edge firmware tracks.

  8. Repository reporting policy added

    SECURITY.md added private reporting instructions directly to the firmware repository.

FIRMWARE CONTRIBUTORS

People who contributed to the public repository.

This list combines authors from the firmware commit history and merged pull requests through August 12, 2026. Duplicate commit identities are consolidated and automated accounts are omitted. Inclusion records repository activity; it does not imply employment, endorsement, or a security audit.

COLDCARD firmware GitHub stars COLDCARD firmware GitHub forks COLDCARD firmware last GitHub commit

PUBLIC RECORD

Inspect the evidence and the limits.

The formal technical postmortem is in progress. The current record preserves the advisory, firmware archive, source, independent checks, and historical disclosures. The firmware repository now includes a SECURITY.md with private reporting instructions and the information to include in a report.