Coldcard Vulnerability: What You Need to Do Now

Updated 25 August 2026: On 20 August, Coinkite released firmware 5.6.1 (Mk4, Mk5) and 1.5.1Q (Q) and strongly recommends the update to all users of these models. The affected version ranges and the entropy estimates are unchanged. Coinkite has also launched an official Security Status page and a step-by-step migration guide. The formal technical review Coinkite announced has not been published yet. We have updated the figures on the outflows to the state as of 24 August.

Coldcard maker Coinkite has issued a warning about a serious flaw in seed generation. Affected firmware used a predictable software fallback instead of the hardware random number generator. Seeds generated on a Coldcard since March 2021 are significantly weaker than intended. Here is what you need to know and exactly what to do.

What happened?

The faulty code entered the Coldcard Mk2 and Mk3 with firmware 4.0.1 in March 2021 and, in a weaker form, also affects Mk4, Mk5 and Q. Instead of the expected 128 bits of entropy, affected seeds reached only about 40 bits (Mk2, Mk3) or about 72 bits (Mk4, Mk5, Q) according to Coinkite. With enough computing power, an attacker can search such seeds.

On 30 July, roughly 594 BTC were swept from around 500 wallets within minutes. Several further waves of attacks have followed since. As of 24 August, Galaxy Research attributes approximately 1,789 BTC from 8,865 addresses to the incident, worth around 114.7 million US dollars at the time of the thefts. According to Galaxy Research, about 87 per cent of that amount (roughly 1,561 BTC) remains unmoved in attacker-controlled addresses and is traceable. Some of the coins stolen in later attacks have since been moved through CoinJoin transactions and other obfuscation methods. Galaxy Research continues its count and the figures are preliminary. It is not yet conclusively proven that all of these outflows are linked to the Coldcard flaw, but the overall picture is reason enough to act.

Am I affected?

What matters is not which device you use today, but on which device and firmware your seed was originally generated:

Seed generated on Affected
Coldcard Mk2 or Mk3, firmware 4.0.1 to 4.1.9 Yes, severely (approx. 40 bits)
Coldcard Mk4 or Mk5, before standard 5.6.0 or Edge 6.6.0X Yes, approx. 72 bits
Coldcard Q, before standard 1.5.0Q or Edge 6.6.0QX Yes, approx. 72 bits
Seed created with at least 50 independent, private dice rolls Not at risk according to Coinkite
Tapsigner, Opendime, Satscard Not affected according to Coinkite (different codebase)

Important: A weakly generated seed does not become secure by importing it into another device or by updating the firmware. The flaw lives in the seed itself. The update only corrects future seed generation.

Fixed firmware by model

A fixed version is now available for every affected model. Do not generate a new seed before the update is installed.

Model Fixed version
Mk2 and Mk3 4.2.0 or later
Mk4 and Mk5 (standard) 5.6.0 or later, currently recommended: 5.6.1
Mk4 and Mk5 (Edge) 6.6.0X or later
Q (standard) 1.5.0Q or later, currently recommended: 1.5.1Q
Q (Edge) 6.6.0QX or later

Standard and Edge are separate release tracks. If you run Edge, you need the fixed Edge release for your model. A higher version number does not automatically mean the flaw is fixed. Coinkite maintains the current version matrix on its Security Status page.

New since 20 August: With firmware 5.6.1 (Mk4, Mk5) and 1.5.1Q (Q), Coinkite has further hardened seed generation. Every new seed now requires additional user-sourced entropy: At least 65 key presses with unpredictable timing, 50 dice rolls or 128 coin flips, combined with the device's hardware randomness. The update also includes further security improvements, such as re-verifying a transaction immediately before signing. Coinkite recommends this update to all Mk4, Mk5 and Q users. As before: The update does not repair an existing affected seed.

If you added dice rolls when creating the seed

According to Coinkite, the flaw only concerns the entropy generated by the device. Coinkite states that your own dice rolls, entered via "Add Dice Rolls", are unaffected and were mixed into the seed. The manufacturer gives the following thresholds:

  • 50 to 98 independent, private rolls: The dice alone are said to have contributed at least 128 bits of entropy. Coinkite does not consider such a seed to be at risk from this issue.
  • 99 or more rolls: Approximately 256 bits of entropy.
  • Fewer than 50 rolls, or you cannot remember: Coinkite recommends treating the seed as at risk and migrating.

We are not in a position to judge whether any particular seed is secure. This assessment comes from the manufacturer. If in doubt, migrating to a new seed is the conservative choice.

If you use a passphrase

According to Coinkite, a strong, unique BIP39 passphrase acts as an additional, independent barrier: an attacker would have to guess the passphrase as well as the weak seed. Coinkite states that short, common or reused passphrases do not provide that protection. The manufacturer explicitly recommends that passphrase users also migrate to a new seed as soon as practical. A passphrase does not repair the affected seed.

How to migrate safely

Take your time. Rushing a wallet migration is one of the biggest risks. Coinkite has also published its own migration guide.

  1. Update the firmware to the fixed version for your model (see table above) and confirm the version on the device.
  2. Generate a new seed on the updated device. From firmware 5.6.1 and 1.5.1Q onwards, the device additionally requires user-sourced entropy (key presses, dice rolls or coin flips). On Mk2 and Mk3 running 4.2.0, Coinkite states that the corrected device-generated randomness is sufficient; dice rolls are optional there.
  3. Create and verify your backup: Record the seed words (and any passphrase separately) before depositing any Bitcoin.
  4. Verify the fingerprint and a receive address directly on the device screen.
  5. Send a small test transaction and confirm it arrived.
  6. Move the remaining funds: Then transfer all remaining UTXOs to the new wallet.
  7. Keep the old backup until the migration is complete and confirmed.

And as always: never enter your seed or passphrase on a computer, phone or website.

Coinkite has suspended its automatic deletion of customer data

On 7 August, Coinkite announced that its automatic blanking of customer records after 120 days is temporarily suspended. Coinkite gives legal preservation obligations in connection with anticipated legal proceedings as the reason. Records that would have been blanked under the previous schedule will be retained until further notice. Coinkite states that customers who do not want this can contact its support by email and ask for the existing retention policy to be applied. This concerns orders placed directly with Coinkite, not your orders with us.

Please note: The technical details in this article, in particular the affected firmware versions and the entropy estimates, come from Coinkite and reflect the state as of 25 August 2026. The figures on the outflows come from Galaxy Research and reflect the state as of 24 August 2026. Coinkite explicitly describes its own analysis as preliminary and has already revised the advisory several times. A formal technical review has been announced but not yet published. Coinkite consolidates current, verified information on its Security Status page. We pass this information on to the best of our knowledge but accept no liability for its accuracy, completeness or timeliness. The manufacturer's official advisory always takes precedence.

Sources and further reading

If you would like to use an additional device for the migration: Copiaro carries current hardware wallets in stock.