Coldcard Vulnerability: What You Need to Do Now

Coldcard maker Coinkite has issued a warning about a serious flaw in seed generation. Affected firmware used a predictable software fallback instead of the hardware random number generator. Seeds generated on a Coldcard since March 2021 are significantly weaker than intended. Here is what you need to know and exactly what to do.

What happened?

The faulty code entered the Coldcard Mk3 with firmware 4.0.1 (March 2021) and, in a weaker form, also affects Mk4, Mk5 and Q. Instead of the expected 128 bits of entropy, affected seeds reached only about 40 bits (Mk3) or about 72 bits (Mk4, Mk5, Q) according to Coinkite. With enough computing power, an attacker can search such seeds.

On July 30, roughly 594 BTC were swept from around 500 wallets within minutes. It is not yet conclusively proven that all of these outflows are linked to the Coldcard flaw, but the overall picture is reason enough to act.

Am I affected?

What matters is not which device you use today, but on which device and firmware your seed was originally generated:

Seed generated on Affected
Coldcard Mk3, firmware 4.0.1 to 5.0.3 Yes, severely
Coldcard Mk4 or Mk5, firmware before 5.6.0 Yes, reduced entropy
Coldcard Q, firmware before 1.5.0Q Yes, reduced entropy
Seed imported via dice rolls No
Tapsigner, Opendime, Satscard No (different codebase)

Important: A weakly generated seed does not become secure by importing it into another device or by updating the firmware. The flaw lives in the seed itself. If you use your seed with a BIP39 passphrase, Coinkite considers the risk minimal. We still recommend migrating to a new seed.

How to migrate safely

Take your time. Rushing a wallet migration is a bigger risk than the vulnerability itself.

  1. Update the firmware: Mk4 and Mk5 to version 5.6.0 or later, Coldcard Q to 1.5.0Q or later. Only then generate a new seed. Coinkite has not announced a fix for the Mk3: generate the new seed on an unaffected device instead.
  2. Generate a new seed: On the updated or new device. Coinkite additionally recommends a strong, unique BIP39 passphrase, at least 99 independent dice rolls, or both.
  3. Create and verify your backup: Record the seed words (and the passphrase separately) before depositing any Bitcoin.
  4. Verify a receive address: Always directly on the device screen.
  5. Send a small test transaction: A small amount first, confirm it arrived.
  6. Move the remaining funds: Then transfer all remaining UTXOs to the new wallet.
  7. Keep the old backup until the migration is fully complete.

Interim solution if the Mk3 is your only device: Set up a long, random, unique BIP39 passphrase on the device and move your Bitcoin to that new passphrase wallet. This does not replace the migration, but it buys you time.

And as always: never enter your seed or passphrase on a computer, phone or website.

Sources and further reading

Need an unaffected device for your new seed? Copiaro carries current hardware wallets in stock.