Coldcard Security Notice Puts Bitcoin Wallet Entropy Risk Back In Focus

Summary

A Coldcard firmware flaw may have weakened seed generation on older devices, affecting Mk3 firmware 4.0.1–5.0.3, Mk4/Mk5 before 5.6.0, and Q devices before 1.5.0Q. The bug replaced hardware randomness with a predictable software fallback, cutting seed entropy from 128 bits to 72 bits. That could make some wallets guessable even without phishing or key exposure. Reports say about 594 BTC from roughly 500 single-signature wallets were swept on July 30–31, 2026. The main risk depends on whether the seed was created on affected firmware and whether extra protection was used. Seeds generated with a BIP-39 passphrase or at least 50 dice rolls were not considered at risk in the incident notes. The broader lesson is that hardware wallets are only as secure as their firmware, entropy source, and backup practices.