Coldcard, one of the most trusted names in Bitcoin hardware wallets, has released firmware updates that patch a critical vulnerability in how its devices generate wallet seeds. The catch: updating your firmware doesn’t actually fix the problem. You still need to move your Bitcoin to an entirely new wallet.
The vulnerability, which has persisted since firmware version 4.0.1 shipped in March 2021, allowed seeds to be generated with significantly reduced entropy. In English: the random number generation process that’s supposed to make your wallet’s master key essentially unguessable was, in fact, far more guessable than anyone realized.
What went wrong and what’s at risk
The flaw stems from faulty RNG (random number generator) processes in Coldcard’s firmware that produced predictable seed phrases. For a device whose entire value proposition is “your keys, your Bitcoin, nobody else’s,” this is about as bad as it gets.
Devices affected include the Mk3, Mk4, Mk5, and Q models running firmware versions released after March 2021 and before the July 31, 2026 patch. That’s over five years of potentially compromised seed generation across Coldcard’s entire product lineup.
The consequences haven’t been theoretical. Hundreds of millions of dollars in Bitcoin thefts have reportedly been linked to this vulnerability.
Fixed firmware versions released on July 31, 2026 include v5.6.0 for Mk4 and Mk5 devices, v1.5.0Q for the Q standard model, and v4.2.0 for the older Mk3. All of these are hosted on Coldcard’s GitHub repository at github.com/Coldcard/firmware, which includes full source code, security advisories, and change logs.
Updating firmware is necessary but not sufficient
Here’s the thing. Coldcard has been explicit that simply flashing the new firmware does not resolve the underlying issue with seeds that were already generated using the flawed process. Those seeds remain compromised regardless of what firmware you’re running.
The required action is a full wallet migration. Users need to generate entirely new seeds on the patched firmware and transfer all their Bitcoin to wallets derived from those new seeds.
For users who want additional protection during the migration process, Coldcard recommends two risk mitigation strategies. The first is using independent dice rolls, at least 50 of them, to introduce genuine physical randomness into seed generation. The second is applying a robust BIP-39 passphrase, which acts as an additional layer of entropy on top of the seed itself.
Both approaches work because they introduce randomness that doesn’t depend on the device’s potentially flawed internal RNG.
The self-custody paradox
Coldcard has built its reputation as the gold standard for Bitcoin-only self-custody. The company doesn’t support altcoins, doesn’t chase DeFi integrations, and has positioned itself squarely as the serious Bitcoiner’s serious hardware wallet.
The vulnerability also highlights a tension in the open-source security model. Coldcard’s firmware is open source, and its GitHub repository has been publicly available for review. Yet this entropy flaw apparently went undetected or at least unpatched for more than five years.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

1 hour ago
14








English (US) ·