CURRENT SECURITY STATUS
Fixed firmware is available for every supported COLDCARD model.
The fix corrects future seed generation. It does not repair an existing seed created on affected firmware.
MINIMUM FIXED RELEASES
Check the release track, not only the model.
Updating corrects future seed generation but does not repair an existing affected seed. Follow the advisory unless its independent-dice exception applies.
INDEPENDENT VALIDATION
Specific parts of the remediation have been checked independently.
Shiny (@bigshiny0)
Mk4 firmware 5.6.0
Observed eight STM32 hardware RNG reads for the 32-byte seed request, confirming that the fixed seed-generation path reaches the hardware TRNG.
Review evidence source reviewMike Rahel (@itooshatonamask)
Mk2/Mk3 4.2.0, Mk4/Mk5 5.6.0, Q 1.5.0Q, and Edge 6.6.0X/6.6.0QX
Confirmed the hardware RNG implementation, removal of the software fallback, and a build-time check that rejects the wrong implementation.
Review evidence source reviewMars (@Marsmensch)
released hotfix
Confirmed that the hotfix removes the MicroPython fallback, exports the hardware RNG implementation, and stops builds that link the wrong implementation.
Review evidence reproducible build and workflow tracePortlandHODL
Mk4/Mk5 firmware 5.6.0
Rebuilt the release and matched every code and data byte in the published signed firmware, then traced the independent-dice path and recomputed its result.
Review evidenceScope limit: These findings validate specific remediation mechanisms. They include one real-device test, source reviews, and a reproducible build plus dice-path trace for 5.6.0. They are not a complete audit of every firmware binary and do not guarantee that COLDCARD is free of defects.
WHAT TO DO
Use the path that matches your wallet.
Creating a new seed
Install a fixed release for your model and verify the signed download before creating the seed.
Using an existing seed
Follow the advisory's migration instructions. Updating the device alone does not repair the existing seed.
Used independent dice
Read the advisory's exact dice-roll conditions before deciding whether its exception applies to your seed.
Checking the release
Compare the SHA-256 hash and verify the signed signatures.txt file before installing firmware.
PUBLIC RECORD
Inspect the evidence and the limits.
The formal technical postmortem is in progress. The current record preserves the advisory, firmware archive, source, independent checks, and historical disclosures.