Is My Coldcard Model Affected? Mk3, Mk4, Mk5, and Q Firmware Scope Breakdown
Comprehensive guide to affected Coldcard hardware models (Mk3, Mk4, Mk5, Q), vulnerable release tracks, patched firmware versions, and why updating firmware alone does not repair existing seeds.
Expanded Device Scope: Mk3, Mk4, Mk5, and Q Series Breakdown
Following the initial reports of the Coldcard RNG flaw, updated security advisories from Coinkite and independent researchers at Galaxy Digital expanded the list of affected hardware devices.
Initial assumptions suggested the bug was isolated to older Mk3 units. However, build pipeline audits confirmed that the compilation header flag (MICROPY_HW_ENABLE_RNG (0)) affected multiple release tracks across Mk3, Mk4, Mk5, and Q series models.
Understanding whether your specific hardware unit and firmware build tracks are affected is the first critical step toward securing your Bitcoin holdings.
Model-by-Model Fixed Firmware Version Matrix
To determine if your Coldcard generated weak seed material, compare your device model and installed firmware against the official security release matrix:
1. Coldcard Mk3 Series
- Vulnerable Firmware: All firmware versions prior to v4.2.0.
- Fixed Firmware: v4.2.0 or higher.
- Entropy State: Weakened to ~40 bits (~1 trillion combinations) under default software PRNG generation.
2. Coldcard Mk4 & Mk5 Series
- Vulnerable Firmware: All versions prior to v5.6.0 (including both Standard and Edge release tracks).
- Fixed Firmware: v5.6.0 or higher.
- Entropy State: Weakened to ~72 bits under software fallback.
3. Coldcard Q Series (Q1 / Q2)
- Vulnerable Firmware: All versions prior to v1.5.0Q.
- Fixed Firmware: v1.5.0Q or higher.
- Entropy State: Weakened to ~72 bits under software fallback.
Why Updating Firmware Does NOT Repair Existing Seed Phrases
A frequent misunderstanding among hardware wallet users is assuming that applying a firmware update automatically secures their current wallet.
Firmware updates patch code execution paths, not mathematical seed derivations.
When you install patched firmware (e.g., Mk4 v5.6.0+), the update re-enables the hardware TRNG peripheral for future wallet creation routines. However, if your existing 24-word seed phrase was created when the device was running vulnerable firmware, that seed phrase was generated from weak entropy.
Updating the operating code on the device does not alter the historical math used to derive your master private key. Your wallet remains 100% vulnerable to offline brute-force cracking until you generate a completely new seed phrase and transfer your Bitcoin to it.
Actionable Device Audit and Migration Protocol
If you hold funds on a Coldcard device initialized before August 2026:
- Verify Current Firmware Version: Boot your Coldcard, navigate to
Advanced/Tools -> Settings -> Version, and note the firmware version number and release track. - Download Patched Firmware: Download the official hotfix binary from Coinkite's official repository and verify the PGP signature using
gpg --verify. - Generate a Fresh Seed Phrase: Flash the patched firmware onto your Coldcard. Create a fresh wallet using manual dice rolls (BIP-39 physical entropy addition) or initialize a separate device like a BitBox02.
- Sweep Full Balances: Broadcast an air-gapped transaction transferring all funds from the old seed to the new seed.
- Update Emergency Vault Instructions: Update your emergency dead man's switch runbooks in ZeroLatch to ensure your beneficiaries do not attempt to access legacy, deprecated seed phrases.
ZeroLatch Editorial Team
We publish practical guidance about secure future delivery, digital continuity, and the decisions families and small businesses should discuss before an emergency. Review our security model.
Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute legal, financial, or technical advice. ZeroLatch is a software service, not a law firm. We recommend consulting with qualified professionals regarding your specific estate planning, data privacy, and security needs.
Leave instructions, not wallet seeds
Prepare a separate encrypted delivery with the inventory, contacts, and recovery sequence your chosen person will need.
Prepare a crypto continuity delivery →Every plan includes a 14-day free trial. View pricing.