Coinkite, the manufacturer of COLDCARD hardware wallets, has disclosed a security issue affecting the randomness used to generate seed phrases on certain firmware versions. Customers who generated their current seed phrase using an affected COLDCARD should review the information below and take the appropriate precautions.
This was not a breach of 1Bitcoin.ca, and 1Bitcoin.ca’s systems were not affected. As a non-custodial Bitcoin service, we do not hold customers’ bitcoin, private keys, seed phrases, or wallet passphrases. However, customers who use certain COLDCARD devices may be affected by the issue.
CRITICAL SECURITY WARNING
NEVER TYPE YOUR SEED PHRASE INTO ANY BROWSER, WEBSITE, COMPUTER, PHONE, EMAIL, CHAT, OR ONLINE FORM.
No legitimate representative from 1Bitcoin.ca, Coinkite, or COLDCARD will ever call, email, or message you asking for your seed phrase, private keys, passphrase, PIN, or remote access to your device. Never share this information with anyone.
What happened
Coinkite identified a firmware bug that could cause affected COLDCARD devices to use weaker software-generated randomness instead of the intended hardware-generated randomness when creating seed phrases.
According to Coinkite:
- Seeds generated on affected Mk3 firmware may have approximately 40 bits of entropy.
- Seeds generated on affected Mk4, Mk5, and Q firmware may have approximately 72 bits of entropy, below the intended 128-bit security target.
- TAPSIGNER, OPENDIME, and SATSCARD are not affected because they use different codebases.
Installing corrected firmware fixes future seed generation. It does not repair or strengthen a seed phrase previously generated using affected firmware.
Which devices and firmware versions are affected?
Seeds generated under the following conditions may be affected unless the independent dice-roll exception described below applies:
- Mk3 running firmware 4.0.1 through 4.1.9 inclusive
- Mk4 or Mk5 running standard firmware before 5.6.0
- Q running standard firmware before 1.5.0Q
- Mk4 or Mk5 running Edge firmware before 6.6.0X
- Q running Edge firmware before 6.6.0QX
Do not generate a replacement seed until you have installed the corrected firmware for your device and release track.
What COLDCARD users should do
Before taking action, remember:
Never enter your seed phrase into a browser, website, computer, phone, email, chat, or online form. No one from 1Bitcoin.ca, Coinkite, or COLDCARD will ever call or message you asking for it.
Follow these steps carefully:
- Check your COLDCARD model, release track, and current firmware version.
- Install the corrected firmware for your device:
- Mk3: 4.2.0 or later
- Mk4/Mk5 standard: 5.6.0 or later
- Q standard: 1.5.0Q or later
- Mk4/Mk5 Edge: 6.6.0X or later
- Q Edge: 6.6.0QX or later
- After updating, generate a brand-new seed phrase directly on the updated COLDCARD. Updating the firmware alone does not make an existing affected seed secure.
- Record the new seed phrase offline and verify the backup before depositing funds. Never photograph it, save it digitally, or type it into an internet-connected device.
- Verify the new wallet fingerprint and receiving address directly on the COLDCARD screen.
- Send a small test transaction and confirm that it arrives in the new wallet.
- After confirming the test, transfer the remaining balance.
- Keep the previous backup until the complete balance has arrived and the migration has been fully verified.
Take your time. Rushing a wallet migration can create a more immediate risk than the issue being addressed.
If you added dice rolls when creating the seed
Coinkite states that this issue affects device-generated entropy but does not remove independent entropy supplied through dice rolls.
If you added at least 50 fair, independent, and private dice rolls when generating the final seed—and those rolls were never recorded or exposed—Coinkite does not consider that seed at risk from this randomness issue alone.
If you used fewer than 50 rolls, cannot remember how many were used, or are uncertain whether the rolls remained private, follow the migration guidance.
Dice rolls are optional after installing corrected firmware. According to Coinkite, the fixed firmware’s device-generated seed is sufficient.
If you used a BIP-39 passphrase
A strong and unique BIP-39 passphrase provides an additional independent barrier. This is different from the COLDCARD PIN.
However, Coinkite still recommends migrating affected seeds as soon as practical. Short, common, patterned, quoted, or reused passphrases should not be assumed to provide adequate protection.
Never enter your seed phrase or BIP-39 passphrase into a website or share it with anyone.
Watch for impersonation and phishing attempts
Security announcements are often used by scammers to create urgency and impersonate wallet providers or support teams.
If anyone contacts you asking for your seed phrase, private keys, passphrase, PIN, wallet information, screen sharing, or remote access:
- End the call or conversation immediately.
- Do not click any links they provide.
- Do not install software.
- Do not share your screen.
- Do not approve transactions.
- Do not provide any wallet or security information.
1Bitcoin.ca, Coinkite, and COLDCARD will never call, email, or message you asking for your seed phrase.
Official information
Review Coinkite’s official information before beginning:
If you need help understanding this advisory before moving your funds, contact 1Bitcoin.ca directly at he**@******in.ca. Our team can explain the published guidance, but we will never ask you to reveal or enter your seed phrase, private keys, passphrase, or PIN.
1Bitcoin.ca will update this notice if Coinkite releases material new information.

