COLDCARD SECURITY
Check the code, firmware, and device.
COLDCARD publishes the material needed to inspect important software and device-security claims. Verification does not mean assuming that open source, an air gap, or a green light solves every threat. It means checking the specific control before you depend on it.
Current firmware status
In the July 2026 incident, the COLDCARD devices themselves were not hacked, remotely accessed, or taken over. A firmware bug in affected releases caused weakened seed generation, which attackers exploited offline by regenerating the corresponding private keys and stealing funds.
Fixed firmware is available for every supported COLDCARD model and release track. The minimum fixed releases are Mk2/Mk3 4.2.0, Mk4/Mk5 5.6.0, Q 1.5.0Q, Mk4/Mk5 Edge 6.6.0X, and Q Edge 6.6.0QX.
The current recommended standard releases are Mk4/Mk5 5.6.1 and Q 1.5.1Q. They add required user entropy for standard new seeds, fresh per-seed input from both secure elements, staged-PSBT integrity checks before review and signing, tighter USB and firmware-update boundaries, fail-closed RNG checks, Delta Mode isolation changes, and active-wallet backup behavior. These statements describe specific controls; they do not establish a complete audit or the absence of every possible defect.
Updating corrects future seed generation but does not repair an existing affected seed. Follow the advisory's migration guidance unless its independent-dice exception applies.
Check the current status and evidence Read the security advisory
Model scope and long-term hardware guidance
Do not simplify the incident to “only Mk2/Mk3 were affected.” Block's root-cause analysis found that the older Mk2/Mk3 path was more severely weakened, while Mk4, Mk5, and Q also used an affected construction before their fixed releases. Praveen Perera's public Wave 1 reconstruction modeled the cold-start Mk3 path and recovered 328 wallet seeds behind 1,042 of 1,195 source addresses. That is strong evidence about Wave 1, not a complete model-by-model ledger for every reported victim. The public record therefore does not support claiming that no Mk4/Mk5/Q wallet was robbed.
Mk2/Mk3 4.2.0 is the final release for that hardware line and can correctly generate a replacement seed. A newer device is not required to complete an urgent migration. For long-term custody, however, we recommend moving to a current Mk4, Mk5, or Q so the device remains on a current product line. Whatever model you use, install and verify current firmware before generating a seed. Replacing hardware or updating firmware does not repair an existing affected seed; move the funds to a newly generated seed.
The fixed source is preserved in the release tags. Git ancestry confirms that the mainline remediation is included in the Mk4/Mk5 5.6.0 and Q 1.5.0Q tags. The Mk2/Mk3 remediation is included in 4.2.0. The Edge remediation is included in 6.6.0X and 6.6.0QX.
Public security scrutiny since 2019
COLDCARD has a documented public external security-review record spanning 2019–2026. As of August 20, 2026, Coinkite's Security Disclosure History records 30 security-relevant events, including 13 records with public evidence of coordinated disclosure.
COLDCARD remains Bitcoin's most publicly scrutinized hardware wallet. The dated disclosure history is the evidence for that claim; its raw event count is not a product score.
The chronology includes coordinated reports, professional reviews, credited fixes, public reports, internal findings, and security advisories. It is not a count of independent vulnerabilities or a product score. It does not mean every release received a complete independent audit or that any hardware wallet is free of defects. COLDCARD is not the best fit for every user: multi-asset support, managed custody, or more guided app workflows may be more important in other use cases.
Start with four checks
Read the firmware source
The Q and Mk-series firmware source is published for review. Inspect the implementation, release tags, build instructions, and changes instead of relying only on a product description.
Verify a firmware download
The Downloads page publishes current firmware files. The upgrade guide explains how to compare the SHA-256 hash and verify the signed signatures.txt file before loading firmware.
Check the device before entering a PIN
At boot, the secure element checks the flash contents against its recorded checksum before lighting GENUINE (green) or CAUTION (red). If the CAUTION light remains red, do not enter your PIN. Stop and investigate.
Disclose a vulnerability privately
Coinkite accepts reports at security@coinkite.com, coordinates PGP-encrypted follow-up, and may pay a Bitcoin bounty for a qualifying report with a working proof of concept.
Independent review of the July 2026 RNG remediation
Independent technical reviewers have examined specific parts of the firmware remediation.
A real-device test confirmed the corrected hardware path. Shiny instrumented a Mk4 running firmware 5.6.0 and observed eight STM32 hardware RNG reads for the 32-byte seed request. This confirms that the fixed seed-generation path reaches the hardware TRNG. Read the test.
A source review covered every fixed release line. Mike Rahel reviewed Mk2/Mk3 4.2.0, Mk4/Mk5 5.6.0, Q 1.5.0Q, and Edge 6.6.0X/6.6.0QX. The review confirmed the hardware rng_get() implementation, removal of the software fallback, and the build-time check that rejects the wrong implementation. Read the review.
A separate source review checked the hotfix mechanics. Mars confirmed that the hotfix removes the MicroPython fallback, exports the hardware rng_get() implementation, and stops builds that link the wrong implementation. Read the review.
A reproducible build connected released source to the published Mk firmware. PortlandHODL rebuilt firmware 5.6.0 and matched every code and data byte in the published signed file, excluding its signature and timestamp header. The same report traced the independent-dice path and recomputed its result outside the firmware. This confirms source-to-binary identity and the dice workflow; it is not a hardware-RNG test. Read the report.
Independent technical articles add context without replacing those checks. Wizardsardine's incident analysis identifies the fixed release boundaries and distinguishes future seed generation from migration of an existing seed. Block's root-cause analysis explains the original failure, but it is not a review of the released fix.
These findings validate specific remediation mechanisms. They are not a complete audit of every released firmware binary and do not guarantee that COLDCARD is free of defects. Updating corrects future seed generation but does not repair an existing affected seed. Follow the security advisory unless its independent-dice exception applies.
What each check proves
Published source makes review possible. It lets researchers inspect the firmware and lets advanced users reproduce a release build. Public code does not prove that the code has no bugs or that every hardware claim is correct.
A reproducible build compares source with a binary. A matching result supports the claim that the released firmware corresponds to the tagged source and documented toolchain. It does not prove that the source is free of vulnerabilities.
A signature identifies approved firmware. COLDCARD checks that firmware was signed by an approved Coinkite key. A valid signature does not make every signed release safe forever, so check the current version and release notes before upgrading.
The GENUINE/CAUTION status is a boot-time flash check. It helps detect an unexpected change before PIN entry. It does not replace inspection of the numbered tamper-evident bag, the clear case, your anti-phishing words, or the transaction details on screen.
Before this wallet holds a meaningful balance
Security is not one chip or one badge. "Meaningful" means an amount whose loss would be materially harmful to you; it is not a fixed bitcoin or fiat threshold.
Check the current security status, install the current recommended firmware, and verify the signed download before generating the savings seed. Standard new-seed generation requires one user method: at least 65 key presses with unpredictable timing, 50 physical six-sided-die rolls, or 128 physical coin flips. The device combines that input with fresh device entropy. Dice Rolls Only remains a separate advanced workflow requiring 50 rolls for 12 words or 99 for 24 words.
For any wallet intended to hold a meaningful balance, use a strong, unique BIP-39 passphrase after the seed backup has been checked. Back it up exactly and separately from the seed, record the passphrase wallet's fingerprint, power-cycle the COLDCARD, and test the complete recovery path before depositing funds. A lost or mistyped passphrase cannot be recovered. Reserve the base wallet without a passphrase for setup, testing, or a deliberately limited balance.
Current firmware addresses future seed generation. Required user entropy and passphrase guidance do not repair an existing affected seed or replace the migration guide.
- Buy from Coinkite or an authorized reseller and inspect the numbered tamper-evident bag.
- Confirm the bag numbers, tear-off tab, and bag number shown by the device agree.
- Wait for the GENUINE status before entering the PIN.
- Record and verify the anti-phishing words produced by the PIN prefix.
- Generate the seed with fresh device entropy plus 65 key presses, 50 physical dice rolls, or 128 physical coin flips. Dice Rolls Only is a separate advanced workflow.
- Back up the seed on durable media, pass the on-device quiz, and verify plain-wallet recovery before applying a passphrase.
- Apply a strong, unique passphrase, back it up separately, record its fingerprint, and power-cycle the device.
- Export the passphrase wallet as watch-only and verify a receive address on the COLDCARD screen.
- Receive a small test amount, sign one Partially Signed Bitcoin Transaction (PSBT), and verify destination, amount, fee, and change on the device.
- Test the documented recovery path before relying on the wallet for a meaningful balance. Add multisig only when its fault-tolerance or continuity benefit justifies the operational load.
Start with the first-session checklist
Know the limits
QR and MicroSD signing remove a live data connection between the signer and an internet-connected coordinator. The COLDCARD still parses transaction data carried across that gap. Review the payment details on its screen before signing.
Dual secure elements reduce dependence on a single chip vendor. They do not protect a seed phrase that was photographed, typed into a phone, or stored with its passphrase.
Bitcoin-only firmware reduces protocol scope. It does not mean the remaining code cannot contain a defect.
A clear case and numbered tamper-evident bag make physical inspection easier. They do not replace buying from a known source or checking the device at first use.
Security links
Firmware verification
Check the release hash and PGP signature before an upgrade.
Physical security notes
Review signed boot, GENUINE/CAUTION status, and physical checks.
Found a security issue?
Keep the report private, preserve user data, and send a reproducible proof of concept to Coinkite's security contact.
Methodology and primary evidence
Reviewed on August 13, 2026.
Method. We checked each claim against the current firmware repository, official release files, and the device documentation linked below. We separated controls that a user can observe on a device from design claims that depend on published documentation or source review. Firmware-dependent behavior can change, so release notes and the installed version remain part of the check.
Limits. Coinkite publishes these primary sources. Publication makes the claims inspectable; it is not an independent audit and does not prove the absence of vulnerabilities. Reproducible builds address whether a release binary corresponds to source, not whether that source is safe.
Claim-to-evidence map:
- Source availability and reproducible builds: firmware snapshot and build instructions reviewed plus the official release files.
- Remediation in fixed release tags: mainline fix, Mk2/Mk3 fix, and Edge fix, each linked above to its descendant release tag.
- Released 5.6.0 source-to-binary identity and independent-dice path: PortlandHODL reproducible-build and workflow report.
- Signed firmware and download verification: firmware upgrade and signature-verification procedure.
- GENUINE/CAUTION boot status and dual-secure-element design: hardware documentation and physical security notes.
- Anti-phishing words and Trick PIN behavior: PIN documentation.
- Numbered tamper-evident packaging and first-use checks: COLDCARD quickstart.
- Air-gap scope and PSBT review: air-gapped signing threat model and PSBT signing procedure.
- Encrypted backup format: backup documentation and verification procedure.
- Vulnerability reporting: Coinkite Responsible Disclosure.