SEED MIGRATION GUIDE
Migrate an affected COLDCARD seed.
If your seed was generated on affected firmware, updating the device is not enough. Install fixed firmware, generate a completely new seed, verify the new wallet, and transfer the funds to it.
Last reviewed 2026-08-14
STEP 1
Decide whether this applies to your seed.
The issue depends on where and how the seed was originally generated. Standard and Edge are separate tracks; do not compare version numbers across tracks. If you cannot establish how the seed was generated, follow this migration process.
| Model and track | Seed generated on affected firmware | Minimum fixed release |
|---|---|---|
| Mk2/Mk3 | 4.0.1 through 4.1.9 | 4.2.0 or later |
| Mk4/Mk5 standard | Before 5.6.0 | 5.6.0 or later |
| Q standard | Before 1.5.0Q | 1.5.0Q or later |
| Mk4/Mk5 Edge | Before 6.6.0X | 6.6.0X or later |
| Q Edge | Before 6.6.0QX | 6.6.0QX or later |
Imported or cloned seeds
A seed securely generated outside the affected on-device flow is not weakened merely because it was imported into a COLDCARD. A seed originally generated by an affected COLDCARD remains affected if it is later restored, imported, or cloned.
If you added dice when creating the seed
The advisory's exception applies only if you entered at least 50 fair, independent dice rolls through Add Dice Rolls, the sequence stayed private and unrecorded, and you used the final words shown after adding the rolls. Fifty to 98 qualifying rolls contributed at least 128 bits of independent entropy; 99 or more contributed approximately 256 bits. If you used fewer than 50 rolls or are uncertain, migrate.
If you used a BIP-39 passphrase
A strong, unique passphrase adds a barrier but does not repair the affected seed. Migrate as soon as practical. This means the BIP-39 passphrase, not the COLDCARD PIN.
STEP 2
Prepare before moving funds.
Never destroy the only working copy of a wallet. Never rely on an untested backup.
- Identify your model and whether it uses standard or Edge firmware.
- Install the applicable fixed release. Verify its SHA-256 hash and signed
signatures.txtfirst. - If available, use a second COLDCARD running fixed firmware for the new wallet.
- Verify that you can recover the affected wallet. Record its wallet fingerprint and check its backup before erasing or replacing anything.
- Inventory every funded identity: the base wallet, accounts, address types, passphrase wallets, BIP85 children, and multisig policies using the seed.
RECOMMENDED PATH
Use a second device.
This avoids repeatedly restoring the old and new seeds on one device.
- Install and confirm fixed firmware on the new or empty COLDCARD.
- Select New Wallet and generate a completely new seed. Do not clone or restore the affected seed.
- Record and verify the new backup and wallet fingerprint.
- If you add a passphrase, record it exactly and separately, then record that wallet's fingerprint.
- Power-cycle the new COLDCARD. Confirm the expected fingerprint and verify a new receive address on its screen.
- From the affected wallet, send a small test transaction to the verified address.
- Confirm the test arrived in the expected new wallet. Recheck its fingerprint and a receive address.
- Move the remaining funds only after the test succeeds. Repeat for every funded wallet identity.
- Wait for confirmation and reconcile the wallets. Keep the old backup until the full migration is verified.
ALTERNATE PATH
If you have only one COLDCARD.
This requires alternating between the old and new wallets. Proceed only with verified backups and fingerprints for both.
- Verify the affected seed backup and its fingerprint.
- Install and confirm the applicable fixed firmware.
- After confirming the old wallet is recoverable, use Advanced/Tools > Danger Zone > Seed Functions > Destroy Seed, read every device warning, and generate a completely new seed.
- Record and verify the new backup, fingerprint, and a receive address.
- Restore the affected seed, confirm its fingerprint, and send a small test to the verified new address.
- Restore the new seed, confirm its fingerprint, and confirm the test arrived.
- Restore the affected seed, confirm its fingerprint, and move the remainder.
- Restore the new seed and confirm the complete migration. Keep the old backup until every expected balance has arrived.
Stop if a fingerprint or address does not match. Do not send funds and do not erase either backup.
SPECIAL CASES
Include every wallet derived from the affected seed.
Passphrase wallets
The base wallet and every passphrase wallet are separate. Migrate each funded one. The same passphrase with a new seed creates a different wallet; verify its fingerprint.
BIP85 child wallets
If the parent is affected, include every funded child. Record the child type and index needed to reach each old wallet. The same index under the new parent creates a different child.
Multisig
Create and verify a new policy that replaces the affected cosigner, then transfer funds from the old policy. Verify the complete new policy on-device.
Clone or Migrate COLDCARD
Do not use this feature as the incident fix. It copies the existing master seed and wallet data; it does not create a new seed.
OPTIONAL DEFENSE IN DEPTH
Choose a recovery plan you understand.
The normal seed generated by fixed firmware is sufficient under current guidance. Dice, a BIP-39 passphrase, and multisig can add independent layers, but each adds backup and recovery duties. Do not add a layer during an urgent migration unless you have tested its recovery plan.
FINAL CHECKLIST
Verify before retiring the old seed.
- Fixed firmware installed and version confirmed
- New seed generated—not cloned or restored from the affected seed
- New backup verified
- New wallet fingerprint recorded and rechecked
- Receive address verified on the COLDCARD screen
- Small test received in the expected wallet
- Every base, passphrase, BIP85, account, and multisig balance considered
- Remaining funds moved and confirmed
- Old backup retained until reconciliation is complete
- Affected seed retired and no longer used for new deposits
Support replies may take longer than usual.
Our team remains focused on helping affected users migrate. Contact [email protected] without including private recovery material. Current verified updates remain on the COLDCARD Security Status page.
For the incident record and exact dice exception, read the original security advisory.