AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Critical 90 Bitcoin

release notes udpated

Public commit record

What the developer wrote

Authored by Peter D. Gray

28/100 · Opaque
release notes udpated
✓ Subject identifies a change! No meaningful explanatory body
The short version

What changed, and why it matters

This commit updates Coldcard's release notes to announce an urgent security fix for a 'limited entropy' bug in how the device generates wallet seeds. On older Mk3 hardware, seeds created after firmware 4.0.1 may have only about 40 bits of randomness—far weaker than the intended 256 bits—making them far easier for an attacker to guess. Newer Mk4, Mk5, and Q devices may also have seeds with only about 72 bits. The company is telling users to regenerate their seeds with the new firmware and to stop generating seeds on Mk3 devices. This specific commit only changes documentation; the actual code fix is in a different commit.

Recommended action

Users should treat this as a critical advisory: upgrade to firmware 5.5.2/1.4.2Q or later, regenerate wallet seeds using the fixed firmware, and move funds from any seed generated on affected firmware. Mk3 users should stop generating seeds on that hardware and either migrate to newer hardware or protect existing seeds with a strong BIP-39 passphrase. Security reviewers should locate the companion source-code commit that actually changes the entropy source/seed generation logic to verify the fix.

Security signals we found

01

Vendor-disclosed urgent hotfix for limited entropy in seed generation

02

Mk3 seeds after v4.0.1 reported to have ~40 bits of entropy

03

Mk4/Mk5/Q seeds reported to have as low as ~72 bits of entropy

04

Advisory to regenerate seeds and stop generating seeds on Mk3 hardware

05

Recommendation to move funds or use BIP-39 passphrase for affected devices

06

Documentation-only commit; actual entropy fix is not shown here

Risk score

Why this scored 90/100

Our methodology →
Potential impact 30/30
Exploitability 20/25
Stealth signal 12/15
Affected reach 15/15
Confidence 9/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.