• Sources: Coldcard firmware upgrade notes, Coinkite blog index, commit-level analysis by Dusty Daemon, CoinDesk report, HN discussion
  • Summary: The Coldcard upgrade page carries a first-party urgent hotfix dated 2026-07-31. It states that Mk3 seeds generated on firmware 4.0.1 through 4.1.9 inclusive hold about 40 bits of entropy, and that Mk4, Mk5 and Q seeds hold as low as about 72 bits, against a stated target of 128 bits. Fixed builds are v5.6.0, v1.5.0Q, v4.2.0 and Edge 6.6.0X/QX, all released 2026-07-31, and the page names a BIP-39 passphrase as a stopgap. A separate commit-level analysis by a Core Lightning developer traces the cause through public commits to #define MICROPY_HW_ENABLE_RNG (0), which removed the STM32 hardware RNG path so that random.bytes(32) in make_new_wallet() fell through to MicroPython's Yasmarang generator, and argues the define was set to silence a duplicate-symbol compiler error. The Coinkite blog index lists two first-party posts dated 2026-07-30, a technical deep dive into the entropy issue and a security advisory whose deck states that funds from affected Coldcard seeds are at risk if the seed lacks 50 independent private dice rolls, and the upgrade page points readers to that blog announcement. Neither post resolved from this environment and three slug guesses returned HTTP 404, so the mechanism above is attributed to the commit-level analysis and has not been compared against the vendor deep dive. CoinDesk reports losses of 38 million US dollars so far.
  • Why it matters: A single build-time define silenced a duplicate-symbol compiler error and swapped a hardware entropy source for a toy pseudorandom generator, and nothing in the running firmware surfaced the downgrade, so seeds looked normal while carrying a third of the intended entropy.
  • Follow-up: Resolve the URL of the Coinkite technical deep dive and check whether it confirms or contradicts the commit-level mechanism.

send feedback on this story