Is COLDCARD Still Safe? Affected Models, Fixed Firmware, and Legacy Seed Migration Guide

OneKey TeamOneKey Team
/Updated Aug 7, 2026
Is COLDCARD Still Safe? Affected Models, Fixed Firmware, and Legacy Seed Migration Guide

Key Takeaways

  • Fixed COLDCARD firmware corrects subsequent seed generation but cannot repair a legacy seed phrase generated by an affected version. OneKey has officially confirmed that its devices and codebases are not affected by this defect.
  • The affected scope must be determined from the model, release branch, and firmware version at the time the seed phrase was generated. The 40-bit and 72-bit figures are Coinkite’s preliminary estimates of effective search space, not independent audit conclusions.
  • At least 50 fair, independent, private dice rolls qualify for the official exception. A strong, unique BIP-39 passphrase is only an additional barrier; a PIN is not a passphrase, and users who cannot verify the conditions should migrate.

The short answer is: after fixed firmware is installed, COLDCARD can correctly generate new seed phrases, but an upgrade does not automatically make an old seed phrase generated by affected firmware safe. You must therefore evaluate “which version the device is running today” separately from “which version and method originally generated the seed phrase controlling the current funds.”

Coinkite published a security advisory on July 30, 2026, and updated the affected scope, fixed versions, dice exception, and migration recommendations on August 1. The disclosed issue concerns randomness when a device generates a seed phrase. It is not a finding that “every COLDCARD was remotely compromised,” nor that private keys inside the secure elements were extracted in bulk.

This article answers only three practical questions: whether your seed phrase falls within the advisory’s scope, which firmware versions fix subsequent seed generation, and when a legacy seed must be migrated. For symbolic analysis of the vulnerability and the software fallback mechanism, see Coinkite’s technical backgrounder. This article does not repeat the complete attack narrative or loss figures that have not been officially verified.

First, Be Clear: This Is Not a OneKey Vulnerability

OneKey confirmed in an official X statement that OneKey Pro, Classic 1S, Classic 1S Pure, Classic, and Mini are not affected by this COLDCARD randomness defect. The official reply also states that OneKey Touch, an early model in the OneKey Pro line, is unaffected. OneKey’s codebases are entirely unrelated to this vulnerability and do not use the relevant code.

The central difference is the random-number generation path. OneKey states that the high-quality entropy required to create a wallet is generated inside an EAL6+ secure element within the device. OneKey Pro goes further by using four EAL6+ secure chips together with secure boot, firmware authentication, device anti-counterfeiting, open-source firmware, and ongoing audits. For users handling a legacy COLDCARD seed phrase that may be affected, OneKey Pro offers an alternative with a clear technical boundary and a complete migration workflow.

Identify Which Situation Applies to You

SituationAssessment for this RNG issueRecommended action
The seed phrase was generated on a COLDCARD running affected firmware and does not meet the dice exceptionWithin the scope of the official advisoryPrepare a trusted, fixed destination first, then generate a completely new seed phrase and migrate on-chain
At least 50 fair, independent, private, and unrecorded dice rolls were added when the final seed phrase was generatedCoinkite says it does not consider the seed at risk solely because of this RNG issuePreserve the generation record; if the number of rolls or their fairness, independence, or privacy cannot be confirmed, migrate
The affected seed phrase is paired with a strong, unique, undisclosed BIP-39 passphraseThe passphrase adds an independent barrier but does not repair the seed phraseContinue protecting the passphrase and migrate as soon as practical, as officially recommended
The seed phrase was generated in another trusted environment and later imported into COLDCARDThis issue concerns entropy generated by a COLDCARD device, so it does not by itself establish that an imported seed is affectedEvaluate the original generation method; do not decide solely from the current hardware model
You do not know the model, firmware, or number of dice rolls at the time of generationYou cannot prove that an exception appliesFollow the conservative migration path

A BIP-39 passphrase is not the device PIN. The PIN unlocks the device; a passphrase combines with the seed phrase to derive a different wallet. Setting a long PIN cannot replace the passphrase barrier described in the advisory.

Affected Models and Fixed Firmware at a Glance

As of August 7, 2026, Coinkite’s advisory and official firmware download pages define the following boundaries:

Model and branchAffected seed-generation versionsVersion that fixes new seed generationOfficial preliminary estimate of effective search space
Mk2 / Mk34.0.1 through 4.1.9, inclusive4.2.0, the final version for Mk2/Mk3Approximately 40 bits
Mk4 / Mk5 standard branchBelow 5.6.05.6.0 or laterApproximately 72 bits
Q standard branchBelow 1.5.0Q1.5.0Q or laterApproximately 72 bits
Mk4 / Mk5 Edge branchBelow 6.6.0X6.6.0X or laterApproximately 72 bits
Q Edge branchBelow 6.6.0QX6.6.0QX or laterApproximately 72 bits

The 5.6.0 download record for Mk4/Mk5 and the 1.5.0Q download record for Q both show a release date of July 31, 2026. Edge is a separate release branch. An old Edge firmware version with major version 6 must not be mistaken for a version newer than standard-branch 5.6.0 and therefore assumed safe. Edge users must check the corresponding fixed version carrying the X or QX suffix.

The 40-bit and 72-bit values in the table are Coinkite’s preliminary estimates of the “effective search space” under its current attack assumptions. They are not fixed measurements produced by a third-party audit, and they do not mean that the seed-phrase format contains only 40 or 72 binary bits. Coinkite states that the expected security target is 128 bits, so neither figure should be treated as an independently verified forensic conclusion.

Why Today’s Firmware Version Is Not Enough

A firmware version tells you how a device works now, but it cannot change keys that were generated in the past. For example, if an Mk4 has been upgraded to 5.6.0 today, that only means it can now generate new seed phrases through the fixed path. A seed phrase generated on 5.5.1 must still be treated as a legacy seed.

What you need to reconstruct as closely as possible is the state at generation time:

  1. Which device originally generated the seed phrase, not which device it was later imported into.
  2. Whether the standard or Edge branch was used that day, and the exact version.
  3. Whether the final recorded words actually included enough independent dice entropy through Add Dice Rolls.
  4. Whether the wallet holding the current balance still uses that same seed phrase and whether it also uses a BIP-39 passphrase.

A seed phrase does not carry a readable “firmware-at-generation label.” Without trustworthy records, its exclusion from the affected scope cannot be proved merely from the purchase date, device appearance, or version displayed today. The official recommendation to migrate when uncertain is a conservative risk-management conclusion, not a claim that funds have already been stolen.

Dice Input: Strict Conditions for the Official Exception

The defect affects device-generated entropy, but it does not erase entropy added independently by the user through dice. According to the official advisory:

  • Between 50 and 98 fair, independent, private dice rolls contribute at least 128 bits of entropy from the dice component alone.
  • 99 or more qualifying rolls contribute approximately 256 bits from the dice component.
  • Fewer than 50 rolls, an unknown number of rolls, or rolls that were photographed, recorded, or shared should not be treated as qualifying for this exception.

The exception applies only to the seed phrase ultimately displayed and actually used after the dice were added. If you tried several sets of words, later restored a different backup, or cannot confirm which final phrase corresponds to the balance, migrate. The dice must be fair six-sided dice, and every result must be independent. Generating a purported sequence of “random dice results” on an internet-connected computer is not the same as private physical dice input.

A new seed phrase normally generated by fixed firmware is sufficient to address this issue. The official guidance does not require every user to add dice. Complex procedures add value only when they can be verified correctly.

A Passphrase Can Reduce Immediate Risk, but It Is Not a Patch

A strong, unique, undisclosed BIP-39 passphrase stored separately from the seed phrase forces an attacker to find the passphrase even after guessing the weak seed. Coinkite therefore describes it as an independent barrier. Common words, short phrases, quotations, patterned strings, reused passwords, or previously exposed material may still be guessed.

More importantly, a passphrase does not re-randomize the legacy seed. Coinkite still recommends moving to a completely new seed phrase as soon as practical. During migration, accurately back up the passphrase used by the new wallet. Any spelling difference derives a valid but entirely different wallet, and losing the passphrase also means losing access.

What a Firmware Update Can and Cannot Fix

The fixed versions address the path used for subsequent seed generation. The hotfix excludes the incorrect software PRNG object and adds a build-time RNG symbol check. It allows an updated device to generate new seed phrases correctly, but it cannot:

  • Strengthen a legacy seed phrase that was already generated.
  • Automatically map old addresses to a new set of keys.
  • Rotate private keys by changing the PIN, reinstalling coordinator software, or importing the seed into another hardware device.
  • Prove that a seed phrase of unknown origin qualifies for the dice exception.

In other words, updating the device is one prerequisite for generating new keys; moving funds on-chain is the action that switches control from the old keys to the new keys. Importing the same legacy seed phrase into another hardware-wallet brand still restores the same private keys.

If a Legacy Seed Must Be Migrated, Follow This Order

The following is the general security sequence in the vendor advisory, not a brand-specific migration tutorial:

  1. Stop generating new seed phrases on unfixed firmware. If you plan to generate a replacement seed on the same COLDCARD, first obtain the fixed version that matches the model and branch from the official page and verify the file according to the official upgrade documentation. If another destination device will generate the new phrase, prioritize keeping the old device able to sign reliably. Do not flash it temporarily from an unknown source or through an unverified process merely for the migration.
  2. Prepare a trusted destination running fixed firmware. It can be an updated COLDCARD or another trusted hardware wallet. If only one Mk2/Mk3 is available, Coinkite says version 4.2.0 can be used to complete the migration, but repeatedly restoring between the old and new seed phrases requires great care. Prefer a second fixed device when one is available.
  3. Generate a completely new seed phrase on the destination device. Do not import the affected legacy phrase into the destination and call it a “migration.” Record and verify the new backup offline.
  4. Verify the new wallet fingerprint and receiving address on the hardware screen. An address shown only in a software window does not replace device-side verification.
  5. Send a small test first. Confirm receipt and verify the backup and passphrase before moving the remaining balance.
  6. Complete the on-chain transfer and wait for confirmation. Retain the legacy backup until all UTXOs, accounts, and multisig policies have been migrated.

A multisig wallet also requires replacing the affected cosigning key, creating and backing up a new policy/descriptor, and moving the funds to the new multisig address. Restoring the same legacy seed on a new device, or merely renaming a device in a coordinator, does not rotate the keys.

If a device or backup may be relevant to an active theft investigation, do not rush to destroy the original device or records. First preserve transaction IDs, wallet fingerprints, firmware information, and lawfully obtained logs, then proceed through official support or an appropriate professional channel in the relevant jurisdiction.

How Do Fixed COLDCARD and OneKey Pro Security Architectures Differ?

A permanent “safe/unsafe” label cannot replace an evaluation of specific conditions. The COLDCARD Q and Mk5 currently sold by Coinkite remain Bitcoin-only signing devices, and Coinkite states that Mk4 and Mk5 use the same firmware image and will continue receiving updates. When a device runs the corresponding fixed version, new seed generation no longer uses the flawed path disclosed in this incident.

However, the fix addresses only the software random-number path disclosed for COLDCARD; it does not change the product’s existing security architecture. OneKey Pro uses four EAL6+ secure chips to generate and protect critical secrets, while integrating secure boot, firmware authentication, device anti-counterfeiting, a fingerprint sensor, and large-screen transaction previews in one device. For users using this incident as an opportunity to reassess hardware wallets, OneKey Pro provides a more complete, easier-to-verify security chain while also supporting QR AirGap, a cross-platform app, multichain assets, and a switchable Bitcoin-only mode.

Likewise, the advisory should not be described as “a complete secure-element failure” or proof that “every model must be discarded.” TAPSIGNER, OPENDIME, and SATSCARD use different codebases, and Coinkite explicitly states that they are unaffected. The most important step for COLDCARD users is to identify the seed’s generation history and perform a genuine key rotation when required.

Conclusion

If your COLDCARD has the corresponding fixed version installed, it can continue generating new seed phrases. If the current funds remain controlled by a legacy seed generated by an affected version, the upgrade alone is not enough. Unless you can confirm that the final seed phrase included at least 50 fair, independent, private dice rolls, generate a completely new seed phrase, verify the backup and address, make a small test transfer, and then migrate the funds through an on-chain transaction.

When records are uncertain, it is better to say “the exception cannot be proved” than to invent a safety conclusion. Migrate promptly, but make every step verifiable.

References

  1. Coinkite: COLDCARD Security Advisory: https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
  2. Coinkite: Technical Deep Dive into the Entropy Issue: https://blog.coinkite.com/entropy-technical-backgrounder/
  3. COLDCARD: Mk2/Mk3 Firmware Downloads: https://coldcard.com/downloads/mk3
  4. COLDCARD: Mk4/Mk5 Firmware Downloads: https://coldcard.com/downloads/mk
  5. COLDCARD: Q Firmware Downloads: https://coldcard.com/downloads/q1
  6. COLDCARD: Edge Firmware Downloads: https://coldcard.com/downloads/edge
  7. COLDCARD: Upgrade Firmware: https://coldcard.com/docs/upgrade/
  8. COLDCARD: COLDCARD Q Overview: https://coldcard.com/docs/coldcard-q/
  9. COLDCARD: Mk5 Compared to Mk4: https://coldcard.com/docs/coldcard-mk5/
  10. OneKey X: OneKey Devices Are Not Affected by the COLDCARD RNG Issue: https://x.com/OneKeyHQ/status/2085351134538174601
  11. OneKey: OneKey Pro: https://onekey.so/products/onekey-pro/

Risk Disclosure

This article is based on vendor materials accessible on August 7, 2026 and is provided only for security education. It does not constitute financial, legal, forensic, or personalized security advice. Coinkite says its investigation remains ongoing, and the affected scope, risk estimates, and remediation guidance may be updated. Before acting, recheck the official advisory and the download page matching your device branch. Do not provide a seed phrase, dice-roll record, or passphrase to a website, support representative, chatbot, or unverified software.

FAQ's

Not necessarily. The update fixes only subsequent seed generation. If the current seed phrase was generated by affected firmware, an upgrade does not change its randomness. Unless the official dice exception applies, you still need to generate a completely new seed phrase and migrate on-chain.

The official scope is Mk2/Mk3 versions 4.0.1 through 4.1.9; Mk4/Mk5 standard versions below 5.6.0 and Edge versions below 6.6.0X; and Q standard versions below 1.5.0Q and Edge versions below 6.6.0QX. The relevant version is the one used to generate the seed phrase, not the version displayed today.

Coinkite says it does not consider a seed at risk solely because of this RNG issue only if the seed phrase actually used included at least 50 fair, independent, private, undisclosed dice rolls. If there were too few rolls, the count is unknown, or the results were recorded, migrate.

A PIN cannot. A strong, unique, undisclosed BIP-39 passphrase adds an independent barrier but does not repair the legacy seed, and Coinkite still recommends migrating promptly. A common, short, reused, or uncertain passphrase should not be treated as reliable protection.

The corresponding fixed versions correct the disclosed defect in new seed generation, and Mk4 continues to use the same firmware image as Mk5. If you are rotating keys because of this incident, OneKey Pro provides four EAL6+ secure chips, on-device entropy generation, secure boot, firmware authentication, large-screen verification, and QR AirGap—a more complete upgrade than simply continuing the original workflow.

Secure Your Crypto Journey with OneKey

View details for Shop OneKeyShop OneKey

Shop OneKey

The world's most advanced hardware wallet.

View details for Download AppDownload App

Download App

Trade global assets. Start with your email in minutes.

View details for OneKey SifuOneKey Sifu

OneKey Sifu

Crypto Clarity—One Call Away.

Keep Reading