COLDCARD Security Advisory A seed-generation defect affected releases beginning with firmware 4.0.1. Fixed firmware is available. Existing affected seeds still require migration. Check status

SEED MIGRATION GUIDE

Migrate an affected COLDCARD seed.

If your seed was generated on affected firmware, updating the device is not enough. Install fixed firmware, generate a completely new seed, verify the new wallet, and transfer the funds to it.

Keep recovery material private. Never enter seed words, a passphrase, dice rolls, a backup password, an XPRV, or a private-key QR into a website or send them to support.

Last reviewed 2026-08-14

STEP 1

Decide whether this applies to your seed.

The issue depends on where and how the seed was originally generated. Standard and Edge are separate tracks; do not compare version numbers across tracks. If you cannot establish how the seed was generated, follow this migration process.

Model and track Seed generated on affected firmware Minimum fixed release
Mk2/Mk3 4.0.1 through 4.1.9 4.2.0 or later
Mk4/Mk5 standard Before 5.6.0 5.6.0 or later
Q standard Before 1.5.0Q 1.5.0Q or later
Mk4/Mk5 Edge Before 6.6.0X 6.6.0X or later
Q Edge Before 6.6.0QX 6.6.0QX or later

Imported or cloned seeds

A seed securely generated outside the affected on-device flow is not weakened merely because it was imported into a COLDCARD. A seed originally generated by an affected COLDCARD remains affected if it is later restored, imported, or cloned.

If you added dice when creating the seed

The advisory's exception applies only if you entered at least 50 fair, independent dice rolls through Add Dice Rolls, the sequence stayed private and unrecorded, and you used the final words shown after adding the rolls. Fifty to 98 qualifying rolls contributed at least 128 bits of independent entropy; 99 or more contributed approximately 256 bits. If you used fewer than 50 rolls or are uncertain, migrate.

If you used a BIP-39 passphrase

A strong, unique passphrase adds a barrier but does not repair the affected seed. Migrate as soon as practical. This means the BIP-39 passphrase, not the COLDCARD PIN.

STEP 2

Prepare before moving funds.

Never destroy the only working copy of a wallet. Never rely on an untested backup.

  1. Identify your model and whether it uses standard or Edge firmware.
  2. Install the applicable fixed release. Verify its SHA-256 hash and signed signatures.txt first.
  3. If available, use a second COLDCARD running fixed firmware for the new wallet.
  4. Verify that you can recover the affected wallet. Record its wallet fingerprint and check its backup before erasing or replacing anything.
  5. Inventory every funded identity: the base wallet, accounts, address types, passphrase wallets, BIP85 children, and multisig policies using the seed.

RECOMMENDED PATH

Use a second device.

This avoids repeatedly restoring the old and new seeds on one device.

  1. Install and confirm fixed firmware on the new or empty COLDCARD.
  2. Select New Wallet and generate a completely new seed. Do not clone or restore the affected seed.
  3. Record and verify the new backup and wallet fingerprint.
  4. If you add a passphrase, record it exactly and separately, then record that wallet's fingerprint.
  5. Power-cycle the new COLDCARD. Confirm the expected fingerprint and verify a new receive address on its screen.
  6. From the affected wallet, send a small test transaction to the verified address.
  7. Confirm the test arrived in the expected new wallet. Recheck its fingerprint and a receive address.
  8. Move the remaining funds only after the test succeeds. Repeat for every funded wallet identity.
  9. Wait for confirmation and reconcile the wallets. Keep the old backup until the full migration is verified.

ALTERNATE PATH

If you have only one COLDCARD.

This requires alternating between the old and new wallets. Proceed only with verified backups and fingerprints for both.

  1. Verify the affected seed backup and its fingerprint.
  2. Install and confirm the applicable fixed firmware.
  3. After confirming the old wallet is recoverable, use Advanced/Tools > Danger Zone > Seed Functions > Destroy Seed, read every device warning, and generate a completely new seed.
  4. Record and verify the new backup, fingerprint, and a receive address.
  5. Restore the affected seed, confirm its fingerprint, and send a small test to the verified new address.
  6. Restore the new seed, confirm its fingerprint, and confirm the test arrived.
  7. Restore the affected seed, confirm its fingerprint, and move the remainder.
  8. Restore the new seed and confirm the complete migration. Keep the old backup until every expected balance has arrived.

Stop if a fingerprint or address does not match. Do not send funds and do not erase either backup.

SPECIAL CASES

Include every wallet derived from the affected seed.

Passphrase wallets

The base wallet and every passphrase wallet are separate. Migrate each funded one. The same passphrase with a new seed creates a different wallet; verify its fingerprint.

BIP85 child wallets

If the parent is affected, include every funded child. Record the child type and index needed to reach each old wallet. The same index under the new parent creates a different child.

Multisig

Create and verify a new policy that replaces the affected cosigner, then transfer funds from the old policy. Verify the complete new policy on-device.

Clone or Migrate COLDCARD

Do not use this feature as the incident fix. It copies the existing master seed and wallet data; it does not create a new seed.

OPTIONAL DEFENSE IN DEPTH

Choose a recovery plan you understand.

The normal seed generated by fixed firmware is sufficient under current guidance. Dice, a BIP-39 passphrase, and multisig can add independent layers, but each adds backup and recovery duties. Do not add a layer during an urgent migration unless you have tested its recovery plan.

FINAL CHECKLIST

Verify before retiring the old seed.

  • Fixed firmware installed and version confirmed
  • New seed generated—not cloned or restored from the affected seed
  • New backup verified
  • New wallet fingerprint recorded and rechecked
  • Receive address verified on the COLDCARD screen
  • Small test received in the expected wallet
  • Every base, passphrase, BIP85, account, and multisig balance considered
  • Remaining funds moved and confirmed
  • Old backup retained until reconciliation is complete
  • Affected seed retired and no longer used for new deposits

Support replies may take longer than usual.

Our team remains focused on helping affected users migrate. Contact [email protected] without including private recovery material. Current verified updates remain on the COLDCARD Security Status page.