Login
Sign Up
Woofun AI reports that Coinkite has deployed a critical firmware update for Coldcard devices, a direct response to a seed-generation defect that has been linked to reported Bitcoin thefts. The core of the security incident does not involve an attacker remotely unlocking every Coldcard device in existence. Instead, the vulnerability stems from the specific manner in which certain recovery seeds were originally created. This structural flaw in the initial generation process has necessitated immediate remediation for users who may have been compromised by insufficient cryptographic randomness.
The technical root cause of this vulnerability traces back to a code migration event that occurred in 2021. During this transition, the seed generation process inadvertently routed through a software pseudo-random-number generator rather than engaging Coldcard's intended hardware random-number generator. This misdirection resulted in insufficient randomness within the generated seeds, creating a predictable pattern that could theoretically be exploited. The failure to utilize the dedicated hardware component meant that the entropy injected into the seed creation process was significantly lower than the security standards required for robust Bitcoin custody.
Impact assessments vary significantly by device model and the specific entropy levels achieved during the flawed generation period. Coldcard estimates that affected Mk2 and Mk3 seeds may have possessed an effective search space of only about 40 bits, a level of security that is critically vulnerable to brute-force attacks. Later models, specifically the Mk4, Mk5, and Q models, received additional entropy from their secure elements, raising the preliminary estimate to around 72 bits.
However, neither the 40-bit nor the 72-bit estimates met the company's strict 128-bit target for cryptographic strength, leaving all affected devices exposed to potential compromise.
The limitations of the firmware update are absolute regarding existing keys, meaning it cannot retroactively fix private keys that have already been derived from a weak seed. A firmware download can only change the process used for the next seed generation, ensuring future keys are secure. For an affected holder, the remedy therefore has three distinct parts: verify the firmware, make a replacement seed, and move the balance to a receiving address derived from the new seed. Skipping the final step of moving the balance leaves the Bitcoin under the same old, vulnerable keys, rendering the firmware update ineffective for asset protection.
Firmware version tracking requires careful attention to specific exceptions and release tracks to ensure accurate risk assessment. Coldcard's security-status page separates device models and release tracks, noting that Standard firmware and Edge firmware use different version numbers. Holders should check the specific track they were using rather than comparing the version numbers alone, as this can lead to misidentification of risk. Coldcard offers one important exception: a user who added at least 50 fair, independent, and private dice rolls when creating the seed supplied enough additional entropy to avoid this particular RNG risk, according to the company.
Woofun AI data shows that the role of BIP-39 passphrases in mitigating this risk is nuanced, and migration advice remains critical for most users. A strong, unique BIP-39 passphrase also makes it harder to use an affected seed, but it does not correct the underlying flaw in the seed generation itself. Coldcard still recommends migration as soon as practical for passphrase wallets unless the documented dice condition applies. Anyone who cannot clearly establish that their setup met the exception should follow the migration guidance rather than rely on memory, as uncertainty regarding the dice sequence's privacy or fairness invalidates the protection.
New seed generation requirements in the updated firmware impose strict user contributions to ensure adequate entropy. New seed generation now combines fresh device entropy with a required user contribution: at least 65 key presses with unpredictable timing, 50 physical six-sided-die rolls, or 128 physical coin flips. Coinkite says AI-assisted review also identified issues involving transaction approval, USB handling, and firmware validation, prompting these stricter controls. These measures are designed to prevent any single point of failure in the randomness generation process, ensuring that the seed creation is robust against both software and hardware defects.
External review scope and migration risks highlight the complexity of verifying device security and executing safe transfers. Its security page lists targeted work by outside reviewers, including a real-device RNG test, source reviews, and reproducible-build work. The stated scope matters: these checks validate the listed mechanisms, not every possible condition across every firmware binary. Coldcard's own migration guidance is deliberately cautious, warning that moving Bitcoin under pressure can create a new problem if a user sends to the wrong address, loses the replacement backup, or installs a counterfeit firmware file. Coldcard's technical backgrounder provides the model-specific migration instructions to mitigate these operational risks.
Phishing threats and handling unconfirmed transactions require heightened vigilance during this migration period. Security incidents create a ready-made pretext for phishing, where a fake support account can offer an "RNG checker," a recovery tool, or a temporary address for moving Bitcoin. None of those services need the recovery phrase, PIN, or private key to help a holder verify a public transaction. Use a saved Coldcard address or type the official domain directly. Do not install firmware from a message, ad, or social-media reply.
The same principle applies to any genuine security alert: as our team covered in its report on MiCA-related migration scams, a real announcement can be copied to direct users toward a fake support channel. If an unauthorised transaction is still unconfirmed and marked replaceable, there may be a narrow chance to supersede it with a higher-fee transaction to a secure wallet. That process is technical and time-sensitive. Our guide on stopping eligible pending Coldcard transfers explains the conditions; holders who are unsure should seek help from a trusted Bitcoin security professional rather than improvise with the remaining balance.
Coldcard's new releases address the published seed-generation defect and add several controls around setup, signing, and firmware handling. For a seed created on the affected versions without the qualifying dice protection, the remaining task is straightforward in principle: establish a verified replacement wallet and move the Bitcoin under its new keys. Source review: Technical cause, affected versions, current release recommendations, seed-creation requirements, migration steps, and validation scope are based on Coldcard's security-status page and Coinkite's technical backgrounder. Coldcard says its advisory does not establish the cause of any individual reported loss; this article therefore does not present reported theft totals as a conclusion confirmed by the firmware update.