Coldcard Patches Seed-Generation Flaw Dating to 2021, Users Still Urged to Migrate Wallets
AI Market Summary
Coldcard disclosed and patched a long-running firmware RNG flaw that could have generated reduced-entropy Bitcoin seeds since 2021; firmware updates do not remediate already-created seeds, requiring full wallet migration. Reports of thefts linked to the issue heighten self-custody operational risk and may temporarily increase on-chain transfer activity as users rotate wallets. The incident also underscores limitations of open-source review and hardware wallet trust assumptions.
Impact level
● Medium
Affected assets
BTC/USDT-0.47%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Coldcard has issued firmware updates to address a critical weakness in how its devices generated wallet seeds, a flaw that traces back to firmware v4.0.1 released in March 2021. The company says the bug could have resulted in seeds being created with materially reduced entropy, meaning the randomness underpinning users' master keys may have been far weaker—and more guessable—than expected.
The issue is tied to defective random number generation (RNG) behavior in affected firmware builds, which could produce more predictable seed phrases. Coldcard models impacted include Mk3, Mk4, Mk5 and Q units running firmware released after March 2021 and prior to the July 31, 2026 fix—spanning more than five years across the product line.
Coldcard notes the risk has not been merely academic. Reports have linked the vulnerability to hundreds of millions of dollars in Bitcoin thefts.
On July 31, 2026, Coldcard released patched versions: v5.6.0 for Mk4 and Mk5, v1.5.0Q for the Q standard model, and v4.2.0 for Mk3. The releases, along with source code, security advisories and changelogs, are available via Coldcard's GitHub repository at github.com/Coldcard/firmware.
Coldcard also warns that updating firmware alone does not remediate seeds that were generated under the flawed process. Wallets created with affected firmware remain at risk even after upgrading. The required remediation is a full wallet migration: users should generate entirely new seeds using the patched firmware and move all Bitcoin to addresses derived from those new seeds.
For users seeking added safeguards during migration, Coldcard recommends introducing external entropy through at least 50 independent dice rolls, and/or using a strong BIP39 passphrase to add an additional layer of entropy. Both measures reduce reliance on the device's internal RNG.
The incident lands uncomfortably for a brand positioned as a Bitcoin-only self-custody benchmark. It also underscores a challenge in open-source security: despite Coldcard's publicly available firmware repository, the entropy weakness appears to have gone unnoticed or unpatched for more than five years.