{"advisory_url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/","downloads_url":"https://coldcard.com/downloads/all","existing_affected_seed_status":"migration_required_unless_advisory_dice_exception_applies","independent_validation":[{"evidence_type":"real-device instrumentation","finding":"Observed eight STM32 hardware RNG reads for the 32-byte seed request, confirming that the fixed seed-generation path reaches the hardware TRNG.","reviewer":"Shiny (@bigshiny0)","scope":"Mk4 firmware 5.6.0","url":"https://x.com/bigshiny0/status/2085548104158208393"},{"evidence_type":"source review","finding":"Confirmed the hardware RNG implementation, removal of the software fallback, and a build-time check that rejects the wrong implementation.","reviewer":"Mike Rahel (@itooshatonamask)","scope":"Mk2/Mk3 4.2.0, Mk4/Mk5 5.6.0, Q 1.5.0Q, and Edge 6.6.0X/6.6.0QX","url":"https://x.com/itooshatonamask/status/2084345536291721397"},{"evidence_type":"source review","finding":"Confirmed that the hotfix removes the MicroPython fallback, exports the hardware RNG implementation, and stops builds that link the wrong implementation.","reviewer":"Mars (@Marsmensch)","scope":"released hotfix","url":"https://x.com/Marsmensch/status/2083685917756166531"},{"evidence_type":"reproducible build and workflow trace","finding":"Rebuilt the release and matched every code and data byte in the published signed firmware, then traced the independent-dice path and recomputed its result.","reviewer":"PortlandHODL","scope":"Mk4/Mk5 firmware 5.6.0","url":"https://github.com/portlandhodl/coldcard_fw_dicerolls_trace/blob/9c04064ca1f84925017dcc5bd019a860f662f03d/dice-roll-5-6-0.pdf"}],"independent_validation_caveat":"These findings validate specific remediation mechanisms. They include one real-device test, source reviews, and a reproducible build plus dice-path trace for 5.6.0. They are not a complete audit of every firmware binary and do not guarantee that COLDCARD is free of defects.","migration_note":"Updating corrects future seed generation but does not repair an existing affected seed. Follow the advisory unless its independent-dice exception applies.","minimum_fixed_releases":[{"track":"Mk2/Mk3","version":"4.2.0"},{"track":"Mk4/Mk5 standard","version":"5.6.0"},{"track":"Q standard","version":"1.5.0Q"},{"track":"Mk4/Mk5 Edge","version":"6.6.0X"},{"track":"Q Edge","version":"6.6.0QX"}],"postmortem_status":"in_progress","release_source_lineage":[{"fix_commit":"https://github.com/Coldcard/firmware/commit/ca72463709f4e3f8964952039d5caf955f566a87","release_tags":["2026-07-31T0519-v5.6.0","2026-07-31T0517-v1.5.0Q"]},{"fix_commit":"https://github.com/Coldcard/firmware/commit/4543629941a83a3e2788ac06a12b208338cb8314","release_tags":["2026-07-31T1248-v4.2.0"]},{"fix_commit":"https://github.com/Coldcard/firmware/commit/b987de50360a00bcd8e8a1550e7cb7f9258e0b4f","release_tags":["2026-07-31T1609-v6.6.0X","2026-07-31T1605-v6.6.0QX"]}],"status":"fixed_releases_available","status_url":"https://coldcard.com/security/status","summary":"Fixed firmware is available for every affected COLDCARD model and release track.","verified_at":"2026-08-08"}
