Coldcard Firmware Bug Cut Seed Entropy to 40 Bits, Coinkite Urges Fund Migration
Coinkite warned users on July 30 that Coldcard Mk3 wallets running firmware 4.0.1 or later generated seed phrases using a software-based random number generator instead of the intended hardware RNG, due to a bug introduced in 2021. The flaw reduced effective entropy to roughly 40 bits on the Mk3, far below the expected 128 bits, while Mk4, Mk5, and Q devices were also affected but achieved around 72 bits by mixing in randomness from their secure elements. Because the weakness lies within the seed itself, an attacker could derive and check vulnerable wallet addresses against the public blockchain without ever touching the owner's device. Coinkite has released patched firmware — version 5.6.0 for Mk4 and Mk5, and 1.5.0Q for the Q — but the fix only secures newly generated seeds and does not strengthen existing ones. Affected users are advised to install the corrected firmware, generate a fresh wallet, and transfer their funds away from any seed created under the vulnerable versions.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in