Coldcard firmware generated wallet seeds with reduced randomness
Coldcard · VULNERABILITY
- Incident date
- 2026-07-30
- Recorded
- 2026-07-30
- Reviewed
- 2026-08-07
A 2021 firmware migration silently routed wallet-seed generation on Coldcard Mk2 and Mk3, and on pre-hotfix Mk4, Mk5 and Q devices, to a deterministic software fallback instead of the hardware random-number generator. Effective seed entropy fell to roughly 40-72 bits against a 128-bit target. Coinkite disclosed the defect on 2026-07-30 and shipped fixed firmware for every model and track the following day.
What this means for a userFixed firmware stops new weak seeds but does not repair a seed already generated on vulnerable firmware. A user who generated a seed on an affected version must move funds to a newly generated seed unless that seed came from at least 50 independent dice rolls or sits behind a strong BIP-39 passphrase. Independent on-chain trackers report drained totals in the hundreds of millions of dollars across several waves beginning 2026-07-30; those totals are a disputed range, not one confirmed figure.
Why it carries this statusRecorded as unpatched rather than resolved because the firmware defect is fixed while the seeds it produced are not. Unmigrated wallets remain exposed.
- Coldcard Mk3 seed generation warning ↗Coinkite, 2026-07-30 · primary
- Entropy technical backgrounder ↗Coinkite, 2026-07-30 · primary
- Coldcard firmware changelog ↗Coldcard, 2026-07-31 · primary
- Predictable RNG fallback and 32-bit reseed in Coldcard firmware ↗Block Engineering, 2026-07-30 · independent-analysis