AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Critical 100 Bitcoin

packaging

Public commit record

What the developer wrote

Authored by Peter D. Gray

0/100 · Opaque
packaging
! Very short subject! Too few words to establish purpose! No meaningful explanatory body
The short version

What changed, and why it matters

This commit is a changelog-only update that publicly discloses a severe, long-running security flaw in COLDCARD hardware wallets: for roughly five years, the devices generated cryptographic seeds with far less randomness than intended. On older Mk3 devices, seed entropy may have been as low as about 40 bits, and on Mk4/Mk5/Q devices as low as about 72 bits. That makes generated private keys much easier for an attacker to guess or reproduce, putting any funds secured by those keys at risk. The changelog also lists many other security fixes, including protections against a compromised USB host altering transactions before signing, restrictions on reading sensitive staged data over USB, and hardening of the random-number generator. Users are advised to upgrade immediately and regenerate any seeds created with affected firmware.

Recommended action

Upgrade to the fixed firmware versions (5.6.0+ for Mk4/Mk5, 1.5.0Q+ for Q1, 4.2.0+ for Mk3, 6.6.0+ for Edge Mk/Q) and regenerate all seeds, temporary seeds, and CCC keys created with affected firmware. Move funds from old addresses to newly generated addresses immediately. Review the vendor blog posts for detailed migration guidance and verify firmware signatures before installing.

Security signals we found

01

Vendor-disclosed critical entropy weakness affecting seed generation across multiple hardware platforms

02

Advisory states generated secrets may have only ~40 bits (Mk3) or ~72 bits (Mk4/Mk5/Q) of entropy, well below 128-bit target

03

Mandatory user-supplied entropy added for new master seeds, temporary seeds, and CCC key C

04

PRNG replaced with NIST SP 800-90A SHA-256 Hash_DRBG

05

Secure-element entropy now sampled directly per seed and boot seeding expanded from 32 to 256 bits

06

Multiple additional security bugfixes disclosed: USB dwld arbitrary PSRAM readback, PSBT rewrite before signing, callgate buffer validation, RNG fault detection, SIGHASH_SINGLE restrictions, Delta mode leaks, multisig duplicate/self-key rejection, firmware length/timestamp checks, Base58/SegWit parsing hardening

07

External researchers credited for several findings

Risk score

Why this scored 100/100

Our methodology →
Potential impact 30/30
Exploitability 25/25
Stealth signal 15/15
Affected reach 15/15
Confidence 10/10
Evidence quality 5/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.