Evidence and risk■Verified evidence/▲Documented riskMaterial claims checked against current sources.; those sources document a material risk.
Last reviewedReviewed 5 Sep 2026KYC checked 5 Sep 2026 · verified jurisdiction · Source → official siteHow to cite this pageSource coverageVerified evidenceRecorded riskDocumented risk
Evidence and facts
Evidence and facts
CUNICULA SCORE 4.0
19/100△Limited evidencePrivacy 12/25 · Control 0/20 · Transparency 0/20 · Security 0/25 · Accountability 7/10 · Cap 20 · Method
JURISDICTIONCA
INCIDENT2021-2026 firmware RNG entropy defect and Bitcoin theft monitoring · critical · since 2026-07-30 Affected firmware could generate wallet seeds through a deterministic software fallback rather than the hardware RNG. Affected releases include Mk2 and Mk3 4.0.1 through 4.1.9, Mk4 and Mk5 before 5.6.0, Q before 1.5.0Q, and Edge before 6.6.0X or 6.6.0QX. Current recommended standard releases are Mk4 and Mk5 5.6.2 and Q 1.5.2Q. Updating firmware prevents newly affected seeds but does not repair an existing affected seed. A BIP-39 passphrase does not repair the seed; users must migrate under the official guidance unless its exact independent-dice condition applies. The formal technical postmortem remains unpublished.Coinkite security advisory, Coinkite technical backgrounder, Coldcard firmware changelog, Block Engineering independent analysis, COLDCARD current security status and release guidance, COLDCARD affected-seed migration guide
AUDITED BYNo audit listed
OPERATOR DATAUnknown
SOURCE COVERAGE
■Verified evidenceTHIRD-PARTY REPORTED7/12Reviewed 5 Sep 2026 · Source → official site
LAST CHECKED2026-08-25
LAST UPDATED2026-09-05
Specs
DOCUMENT CHECKNone recorded
IDENTITY EXPOSURELevel 0/4
KYC TRIGGERSNo account, no KYC for firmware use. Hardware purchase may expose shipping address.
FEEMk5 USD 189; Q USD 289
NETWORKSBTC
CATEGORIESWallet, Privacy Tools
COMMON USESCold storage, Air-gapped Bitcoin signing, Maximum self-custody
FEATURESAir-gapped signing, Bitcoin-only, Verifiable firmware source, Duress PIN, PSBT via MicroSD, Sparrow compatible, No companion app required, Dual secure elements, +1 more
TORNot listed
REGIONSGlobal availability
Review analysis, source material, related services, and history
Analysis
OVERVIEW
Coldcard is a Bitcoin-only hardware signer from Coinkite that signs PSBTs through MicroSD or QR without a computer connection, and ships with a duress PIN and open source firmware.
LIMITS
Coinkite is based in Canada, a Five Eyes jurisdiction, and while the device itself holds no user data, a hardware purchase can expose a shipping address unless ordered with privacy-preserving delivery.
USEFUL FOR
Matches Bitcoin holders who want air-gapped signing and self-custody and who handle their own purchase and shipping privacy.
No identity verification is recorded for typical use. No account, no KYC for firmware use. Hardware purchase may expose shipping address.
Which payment methods are accepted?
Accepted payment methods: BTC.
Where is it available?
Recorded availability: GLOBAL.
Is the operator based in a Five Eyes country?
Yes. The recorded jurisdiction is CA, a Five Eyes country (US, UK, CA, AU, NZ). This is jurisdiction context and does not by itself establish that a service is safer or less safe.
How are identity, operator, and evidence fields reported?
Identity exposure is level 0 of 4. Hosted operator data has not been established. Jurisdiction is shown as context, not a safety verdict. Source coverage is verified evidence, last reviewed 2026-09-05, and recorded risk is danger.
No changes to the documents we watch since we started checking on 9 Aug 2026. Last checked 9 Aug 2026.
Evidence basis: Claims on this page are linked to published sources for comparison, not certification, audit, endorsement, or recommendation; read the methodology and coverage map before relying on an entry.
Service history
Latest meaningful changes to the facts shown on this provider page.
Review overdue providers against current sources
Features, Fee, KYC last checked, Last reviewed, and 3 more
Apply full-service rereview and score 4.0
Checked at, Incidents, Last reviewed, Source reviewed, and 2 more
Corporate registry information updated
Corporate
Full service history
updated
Review overdue providers against current sources
Features
Air-gapped signing, Bitcoin-only, Open source firmware, Duress PIN, PSBT via MicroSD, Sparrow compatible, No computer required, Secure element (SE2) → Air-gapped signing, Bitcoin-only, Verifiable firmware source, Duress PIN, PSBT via MicroSD, Sparrow compatible, No companion app required, Dual secure elements, Mk5 and Q models
Canada = Five Eyes jurisdiction, but Coldcard is a hardware product - Coinkite holds no user data or keys. Purchase anonymously (use a P.O. box or privacy-preserving shipping). Order with Monero or cash-equivalent if possible. Firmware is open source. → A July 2026 firmware random-number-generator defect weakened seeds generated on affected Coldcard versions and was exploited offline to steal funds. Devices were not remotely hacked. Installing fixed firmware does not repair an existing weak seed. Users who generated a seed on an affected version must follow Coinkite's migration procedure and move funds to a new seed unless the documented dice-roll exception applies.
Tagline
Bitcoin-only. Air-gapped. The hardware signer that trusts nothing. → not set
not set → Outcome: HOLD; Checked at: 2026-08-25; Inputs: Operator data exposure: unknown; Control model: unknown; Source model: unknown; Audit: Score eligible: no; Reason: No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit.
Title: 2021-2026 firmware RNG entropy defect and Bitcoin theft; Status: monitoring; Severity: critical; Started at: 2026-07-30; Resolved at: not set; Summary: A 2021 firmware migration silently routed Coldcard Mk2/Mk3 (firmware 4.0.1-4.1.9) and pre-hotfix Mk4/Q/Mk5 wallet-seed generation to a deterministic software fallback instead of the device's hardware random-number generator, reducing effective seed entropy to roughly 40-72 bits against a 128-bit target. Coinkite disclosed the issue and shipped fixed firmware for every model on 31 Jul 2026. Independent on-chain researchers tracked more than $100 million in Bitcoin swept from affected addresses across multiple waves beginning 30 Jul 2026. Fixed firmware prevents new affected seeds but does not repair seeds already generated on vulnerable firmware; migration to a newly generated seed is required unless the seed was created with at least 50 independent dice rolls or is protected by a strong BIP-39 passphrase.; Sources: Label: Coinkite security advisory; Href: https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/, Label: Coinkite technical backgrounder; Href: https://blog.coinkite.com/entropy-technical-backgrounder/, Label: Block Engineering independent analysis; Href: https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware, Label: Coldcard firmware changelog; Href: https://github.com/Coldcard/firmware/blob/master/releases/ChangeLog.md → not set
Last reviewed
2026-06-22 → 2026-08-25
Source reviewed
official site → https://coldcard.com/security/status
Score assessment
not set → Operator data exposure: limited; Control model: local-self-custody; Source model: open
Title: 2021-2026 firmware RNG entropy defect and Bitcoin theft; Status: monitoring; Severity: critical; Started at: 2026-07-30; Resolved at: not set; Summary: A 2021 firmware migration silently routed Coldcard Mk2/Mk3 (firmware 4.0.1-4.1.9) and pre-hotfix Mk4/Q/Mk5 wallet-seed generation to a deterministic software fallback instead of the device's hardware random-number generator, reducing effective seed entropy to roughly 40-72 bits against a 128-bit target. Coinkite disclosed the issue and shipped fixed firmware for every model on 2026-07-31. Independent on-chain researchers tracked more than $100 million in Bitcoin swept from affected addresses across multiple waves beginning 2026-07-30. Fixed firmware prevents new affected seeds but does not repair seeds already generated on vulnerable firmware; migration to a newly generated seed is required unless the seed was created with at least 50 independent dice rolls or is protected by a strong BIP-39 passphrase.; Sources: Label: Coinkite security advisory; Href: https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/, Label: Coinkite technical backgrounder; Href: https://blog.coinkite.com/entropy-technical-backgrounder/, Label: Block Engineering independent analysis; Href: https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware, Label: Coldcard firmware changelog; Href: https://github.com/Coldcard/firmware/blob/master/releases/ChangeLog.md → Title: 2021-2026 firmware RNG entropy defect and Bitcoin theft; Status: monitoring; Severity: critical; Started at: 2026-07-30; Resolved at: not set; Summary: A 2021 firmware migration silently routed Coldcard Mk2/Mk3 (firmware 4.0.1-4.1.9) and pre-hotfix Mk4/Q/Mk5 wallet-seed generation to a deterministic software fallback instead of the device's hardware random-number generator, reducing effective seed entropy to roughly 40-72 bits against a 128-bit target. Coinkite disclosed the issue and shipped fixed firmware for every model on 31 Jul 2026. Independent on-chain researchers tracked more than $100 million in Bitcoin swept from affected addresses across multiple waves beginning 30 Jul 2026. Fixed firmware prevents new affected seeds but does not repair seeds already generated on vulnerable firmware; migration to a newly generated seed is required unless the seed was created with at least 50 independent dice rolls or is protected by a strong BIP-39 passphrase.; Sources: Label: Coinkite security advisory; Href: https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/, Label: Coinkite technical backgrounder; Href: https://blog.coinkite.com/entropy-technical-backgrounder/, Label: Block Engineering independent analysis; Href: https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware, Label: Coldcard firmware changelog; Href: https://github.com/Coldcard/firmware/blob/master/releases/ChangeLog.md
Bitcoin-only air-gapped hardware signer. The most trusted hardware wallet in the Bitcoin privacy community. Never connects to a computer. PSBT signing via MicroSD or QR. Duress PIN support. Open source firmware by Coinkite. → Bitcoin-only air-gapped hardware signer by Coinkite with PSBT signing over MicroSD or QR and duress PIN support.
Add Coldcard RNG entropy incident article and services.json incident record
Incidents
not set → Title: 2021-2026 firmware RNG entropy defect and Bitcoin theft; Status: monitoring; Severity: critical; Started at: 2026-07-30; Resolved at: not set; Summary: A 2021 firmware migration silently routed Coldcard Mk2/Mk3 (firmware 4.0.1-4.1.9) and pre-hotfix Mk4/Q/Mk5 wallet-seed generation to a deterministic software fallback instead of the device's hardware random-number generator, reducing effective seed entropy to roughly 40-72 bits against a 128-bit target. Coinkite disclosed the issue and shipped fixed firmware for every model on 2026-07-31. Independent on-chain researchers tracked more than $100 million in Bitcoin swept from affected addresses across multiple waves beginning 2026-07-30. Fixed firmware prevents new affected seeds but does not repair seeds already generated on vulnerable firmware; migration to a newly generated seed is required unless the seed was created with at least 50 independent dice rolls or is protected by a strong BIP-39 passphrase.; Sources: Label: Coinkite security advisory; Href: https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/, Label: Coinkite technical backgrounder; Href: https://blog.coinkite.com/entropy-technical-backgrounder/, Label: Block Engineering independent analysis; Href: https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware, Label: Coldcard firmware changelog; Href: https://github.com/Coldcard/firmware/blob/master/releases/ChangeLog.md
Canada = Five Eyes jurisdiction, but Coldcard is a hardware product — Coinkite holds no user data or keys. Purchase anonymously (use a P.O. box or privacy-preserving shipping). Order with Monero or cash-equivalent if possible. Firmware is open source. → Canada = Five Eyes jurisdiction, but Coldcard is a hardware product - Coinkite holds no user data or keys. Purchase anonymously (use a P.O. box or privacy-preserving shipping). Order with Monero or cash-equivalent if possible. Firmware is open source.