<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>News &#8211; CryptoCloaks</title>
	<atom:link href="https://www.cryptocloaks.com/category/news/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.cryptocloaks.com</link>
	<description>Bitcoin Products you definitely want! Cases, Nodes, Grenades and Badgers!</description>
	<lastBuildDate>Wed, 05 Aug 2026 14:33:30 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.2</generator>

<image>
	<url>https://www.cryptocloaks.com/wp-content/uploads/2024/01/cropped-PmYsvtmG-32x32.jpg</url>
	<title>News &#8211; CryptoCloaks</title>
	<link>https://www.cryptocloaks.com</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">228523443</site>	<item>
		<title>Coldcard Entropy Bug: Why CryptoCloaks Does Not Recommend Coldcard</title>
		<link>https://www.cryptocloaks.com/2026/08/coldcard-entropy-bug-security-advisory-2026/</link>
					<comments>https://www.cryptocloaks.com/2026/08/coldcard-entropy-bug-security-advisory-2026/#respond</comments>
		
		<dc:creator><![CDATA[Pix the Intern]]></dc:creator>
		<pubDate>Wed, 05 Aug 2026 13:39:16 +0000</pubDate>
				<category><![CDATA[Bitcoin Education]]></category>
		<category><![CDATA[Hardware Wallets]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Bitcoin]]></category>
		<category><![CDATA[bitcoin security]]></category>
		<category><![CDATA[bitcoin self custody]]></category>
		<category><![CDATA[cold storage]]></category>
		<category><![CDATA[Coldcard]]></category>
		<category><![CDATA[hardware wallet]]></category>
		<category><![CDATA[seed phrase]]></category>
		<category><![CDATA[self-custody]]></category>
		<guid isPermaLink="false">https://www.cryptocloaks.com/2026/08/coldcard-entropy-bug-security-advisory-2026/</guid>

					<description><![CDATA[<p>Verified Coldcard entropy-bug details, affected firmware, dice and passphrase exceptions, careful migration steps, and why CryptoCloaks does not recommend using Coldcard for Bitcoin custody.</p>
<p>The post <a rel="nofollow" href="https://www.cryptocloaks.com/2026/08/coldcard-entropy-bug-security-advisory-2026/">Coldcard Entropy Bug: Why CryptoCloaks Does Not Recommend Coldcard</a> appeared first on <a rel="nofollow" href="https://www.cryptocloaks.com">CryptoCloaks</a>.</p>
]]></description>
										<content:encoded><![CDATA[<style>
.cc-security-brief{--ink:#080a0d;--panel:#10141a;--panel-2:#151a22;--line:#2a313d;--muted:#9aa6b5;--white:#f7f9fc;--orange:#f7931a;--red:#ff4d4d;--gold:#f4c95d;--cyan:#5ce1e6;background:radial-gradient(circle at 88% 3%,rgba(247,147,26,.16),transparent 25%),radial-gradient(circle at 5% 28%,rgba(255,77,77,.10),transparent 24%),var(--ink);color:var(--white);border:1px solid #202632;border-radius:24px;box-shadow:0 28px 80px rgba(0,0,0,.32);font-size:17px;line-height:1.72;overflow:hidden;margin:22px 0 40px}
.cc-security-brief *{box-sizing:border-box}.cc-security-brief a{color:#ffad42;text-decoration-color:rgba(255,173,66,.45);text-underline-offset:4px}.cc-security-brief a:hover,.cc-security-brief a:focus{color:#fff;text-decoration-color:var(--orange)}.cc-security-brief p,.cc-security-brief li{color:#d7dee8}.cc-security-brief strong{color:#fff}.cc-security-brief h2,.cc-security-brief h3{color:#fff;letter-spacing:-.025em}.cc-security-brief h2{font-size:clamp(29px,4vw,46px);line-height:1.08;margin:0 0 20px}.cc-security-brief h3{font-size:22px;line-height:1.25;margin:30px 0 12px}.cc-security-brief code{background:#050608;border:1px solid #2f3744;color:#ffd08a;padding:2px 6px;border-radius:6px}.cc-wrap{max-width:1080px;margin:auto;padding:clamp(24px,5vw,64px)}
.cc-hero{position:relative;min-height:570px;display:flex;align-items:flex-end;background:#050608}.cc-hero:after{content:"";position:absolute;inset:0;background:linear-gradient(90deg,rgba(3,4,6,.96) 0%,rgba(3,4,6,.80) 48%,rgba(3,4,6,.24) 100%),linear-gradient(0deg,#080a0d 0%,transparent 42%)}.cc-hero img{position:absolute;inset:0;width:100%;height:100%;object-fit:cover;object-position:center}.cc-hero-content{position:relative;z-index:2;max-width:780px;padding:clamp(30px,6vw,76px)}.cc-kicker{display:flex;align-items:center;gap:10px;font:700 12px/1.2 ui-monospace,SFMono-Regular,Menlo,monospace;letter-spacing:.17em;text-transform:uppercase;color:#ffbd67;margin-bottom:22px}.cc-pulse{width:9px;height:9px;border-radius:50%;background:var(--red);box-shadow:0 0 0 7px rgba(255,77,77,.13)}.cc-hero h2{font-size:clamp(38px,6.3vw,72px);max-width:820px;margin:0 0 22px;line-height:.98;letter-spacing:-.045em}.cc-hero .cc-deck{font-size:clamp(18px,2.1vw,24px);line-height:1.48;max-width:720px;color:#dbe1e9;margin:0}.cc-chip-row{display:flex;flex-wrap:wrap;gap:10px;margin-top:28px}.cc-chip{border:1px solid rgba(255,255,255,.19);background:rgba(0,0,0,.46);backdrop-filter:blur(10px);border-radius:999px;padding:9px 13px;font:700 11px/1.2 ui-monospace,SFMono-Regular,Menlo,monospace;letter-spacing:.07em;text-transform:uppercase;color:#f4f7fb}
.cc-verdict{margin-top:-1px;background:linear-gradient(135deg,#2a0808,#130c0d 62%,#24140a);border-top:1px solid rgba(255,77,77,.42);border-bottom:1px solid rgba(255,77,77,.28)}.cc-verdict-grid{display:grid;grid-template-columns:160px 1fr;gap:28px;align-items:start}.cc-verdict-label{font:800 12px/1.35 ui-monospace,SFMono-Regular,Menlo,monospace;letter-spacing:.15em;text-transform:uppercase;color:#ff9292}.cc-verdict h2{font-size:clamp(28px,4vw,43px);margin:-5px 0 14px}.cc-verdict p{font-size:18px;margin:0}.cc-verdict .cc-disclosure{font-size:13px;color:#aeb7c4;margin-top:16px}
.cc-stat-grid{display:grid;grid-template-columns:repeat(4,1fr);gap:12px;margin:0 0 36px}.cc-stat{background:linear-gradient(145deg,#171c24,#0e1217);border:1px solid var(--line);border-radius:16px;padding:22px;min-height:138px}.cc-stat b{display:block;color:#fff;font-size:27px;line-height:1.1;margin-bottom:10px}.cc-stat span{display:block;color:var(--muted);font-size:13px;line-height:1.45}.cc-stat.alert{border-color:rgba(255,77,77,.4)}.cc-stat.alert b{color:#ff7777}.cc-stat.good{border-color:rgba(92,225,230,.3)}.cc-stat.good b{color:var(--cyan)}
.cc-source-line{display:flex;flex-wrap:wrap;align-items:center;justify-content:space-between;gap:12px;border-bottom:1px solid var(--line);padding-bottom:20px;margin-bottom:34px;color:var(--muted);font:600 12px/1.5 ui-monospace,SFMono-Regular,Menlo,monospace;letter-spacing:.035em}.cc-source-line strong{color:#fff}.cc-source-badges{display:flex;flex-wrap:wrap;gap:7px}.cc-source-badge{border:1px solid #36404d;border-radius:999px;padding:5px 9px;color:#cbd3dc;background:#10151b}
.cc-callout{border:1px solid var(--line);border-radius:18px;padding:25px 26px;margin:28px 0;background:linear-gradient(135deg,#161b22,#0d1116)}.cc-callout.warning{border-color:rgba(247,147,26,.48);box-shadow:inset 4px 0 0 var(--orange)}.cc-callout.danger{border-color:rgba(255,77,77,.44);box-shadow:inset 4px 0 0 var(--red);background:linear-gradient(135deg,rgba(255,77,77,.09),#0d1116)}.cc-callout.fact{border-color:rgba(92,225,230,.32);box-shadow:inset 4px 0 0 var(--cyan)}.cc-callout-label{display:block;font:800 11px/1.2 ui-monospace,SFMono-Regular,Menlo,monospace;letter-spacing:.15em;text-transform:uppercase;color:#ffbd67;margin-bottom:9px}.cc-callout.danger .cc-callout-label{color:#ff9292}.cc-callout.fact .cc-callout-label{color:var(--cyan)}.cc-callout p:last-child{margin-bottom:0}
.cc-action-grid{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:26px 0 10px}.cc-action{position:relative;background:#11161d;border:1px solid #2d3541;border-radius:18px;padding:25px}.cc-action-num{display:inline-grid;place-items:center;width:35px;height:35px;border-radius:10px;background:#241308;color:#ffad42;font:800 14px/1 ui-monospace,SFMono-Regular,Menlo,monospace;margin-bottom:18px}.cc-action h3{font-size:19px;margin:0 0 8px}.cc-action p{font-size:14px;line-height:1.55;color:#aeb8c5;margin:0}
.cc-toc{background:#0e1217;border:1px solid var(--line);border-radius:18px;padding:26px;margin:30px 0 8px}.cc-toc-title{font:800 12px/1.2 ui-monospace,SFMono-Regular,Menlo,monospace;letter-spacing:.15em;text-transform:uppercase;color:#ffad42;margin-bottom:16px}.cc-toc ol{display:grid;grid-template-columns:repeat(2,1fr);gap:8px 32px;margin:0;padding-left:22px}.cc-toc li{color:#8e9aaa;padding:3px 0}.cc-toc a{color:#dce3eb;text-decoration:none}.cc-toc a:hover{color:#fff}
.cc-section{border-top:1px solid var(--line)}.cc-section-head{display:grid;grid-template-columns:66px 1fr;gap:18px;align-items:start;margin-bottom:24px}.cc-section-no{font:800 12px/1.2 ui-monospace,SFMono-Regular,Menlo,monospace;letter-spacing:.13em;color:#ffad42;padding-top:8px}.cc-section-head h2{margin:0}.cc-lede{font-size:20px;line-height:1.58;color:#f0f3f7!important;max-width:850px}
.cc-table-wrap{overflow-x:auto;border:1px solid #303947;border-radius:18px;margin:24px 0;background:#0d1116}.cc-security-brief table{border-collapse:collapse;width:100%;min-width:780px;margin:0}.cc-security-brief th{background:#171d25;color:#fff;font:800 11px/1.45 ui-monospace,SFMono-Regular,Menlo,monospace;letter-spacing:.08em;text-transform:uppercase;text-align:left;padding:16px;border-bottom:1px solid #333d4a}.cc-security-brief td{padding:17px 16px;border-bottom:1px solid #252d38;color:#d3dae4;vertical-align:top}.cc-security-brief tr:last-child td{border-bottom:0}.cc-security-brief tbody tr:hover{background:rgba(247,147,26,.035)}.cc-status{display:inline-block;border:1px solid rgba(255,77,77,.4);background:rgba(255,77,77,.09);color:#ff9494;border-radius:999px;padding:4px 9px;font:800 10px/1.2 ui-monospace,SFMono-Regular,Menlo,monospace;letter-spacing:.07em;text-transform:uppercase}.cc-fix{color:#86ecef;font-weight:800}
.cc-steps{counter-reset:step;list-style:none;padding:0;margin:28px 0}.cc-steps li{position:relative;counter-increment:step;margin:0 0 12px;padding:21px 22px 21px 72px;background:#10151b;border:1px solid #29313c;border-radius:16px}.cc-steps li:before{content:counter(step);position:absolute;left:20px;top:21px;display:grid;place-items:center;width:34px;height:34px;border-radius:10px;background:#241308;color:#ffad42;font:800 14px/1 ui-monospace,SFMono-Regular,Menlo,monospace}.cc-steps li strong{display:block;margin-bottom:5px}
.cc-quote{margin:30px 0;padding:25px 28px;border-left:4px solid var(--orange);background:#11161d;border-radius:0 16px 16px 0}.cc-quote p{font-size:19px;color:#f4f6f9;margin:0 0 12px}.cc-quote cite{color:#9ba7b5;font-style:normal;font:600 12px/1.4 ui-monospace,SFMono-Regular,Menlo,monospace}
.cc-faq details{background:#10151b;border:1px solid #2a323e;border-radius:14px;margin:10px 0;overflow:hidden}.cc-faq summary{cursor:pointer;list-style:none;padding:20px 54px 20px 21px;color:#fff;font-weight:800;position:relative}.cc-faq summary::-webkit-details-marker{display:none}.cc-faq summary:after{content:"+";position:absolute;right:20px;top:16px;color:#ffad42;font-size:26px}.cc-faq details[open] summary:after{content:"−"}.cc-faq details p{padding:0 21px 20px;margin:0;color:#c8d0da}
.cc-cta{position:relative;overflow:hidden;background:linear-gradient(135deg,#2a1607,#121820 62%,#082225);border:1px solid rgba(247,147,26,.42);border-radius:22px;padding:clamp(28px,5vw,50px);margin-top:34px}.cc-cta:after{content:"";position:absolute;width:240px;height:240px;border-radius:50%;right:-80px;top:-100px;background:rgba(92,225,230,.08);pointer-events:none}.cc-cta h2,.cc-cta p,.cc-buttons{position:relative;z-index:1}.cc-cta h2{max-width:720px}.cc-cta p{max-width:800px}.cc-buttons{display:flex;flex-wrap:wrap;gap:12px;margin-top:24px}.cc-button{display:inline-flex;align-items:center;justify-content:center;min-height:48px;padding:12px 18px;border-radius:10px;font-weight:800;text-align:center;text-decoration:none!important}.cc-button.primary{background:var(--orange);color:#090a0c!important;-webkit-text-fill-color:#090a0c!important}.cc-button.secondary{border:1px solid #46515f;background:#12171d;color:#fff!important;-webkit-text-fill-color:#fff!important}.cc-fineprint{font-size:12px!important;color:#8e9aaa!important;margin-top:18px!important}.cc-sources{columns:2;column-gap:34px;padding-left:20px}.cc-sources li{break-inside:avoid;margin:0 0 12px}.cc-security-note{font:700 12px/1.65 ui-monospace,SFMono-Regular,Menlo,monospace;letter-spacing:.02em;color:#ffbe6c!important;border-top:1px solid var(--line);padding-top:22px;margin-top:28px}
@media(max-width:850px){.cc-stat-grid{grid-template-columns:repeat(2,1fr)}.cc-action-grid{grid-template-columns:1fr}.cc-verdict-grid{grid-template-columns:1fr;gap:12px}.cc-toc ol{grid-template-columns:1fr}.cc-sources{columns:1}}
@media(max-width:620px){.cc-security-brief{border-radius:14px;margin-left:-12px;margin-right:-12px;font-size:16px}.cc-wrap{padding:28px 20px}.cc-hero{min-height:620px}.cc-hero:after{background:linear-gradient(0deg,#080a0d 0%,rgba(3,4,6,.88) 65%,rgba(3,4,6,.35) 100%)}.cc-hero-content{padding:34px 20px}.cc-hero h2{font-size:40px}.cc-stat-grid{grid-template-columns:1fr 1fr}.cc-stat{padding:17px;min-height:125px}.cc-stat b{font-size:22px}.cc-section-head{grid-template-columns:1fr;gap:6px}.cc-section-no{padding:0}.cc-steps li{padding:68px 18px 20px}.cc-steps li:before{top:18px;left:18px}.cc-buttons{flex-direction:column}.cc-button{width:100%}.cc-source-line{align-items:flex-start;flex-direction:column}}
@media(max-width:620px){.cc-table-wrap{overflow:visible;border:0;background:transparent}.cc-security-brief table{display:block;min-width:0}.cc-security-brief thead{position:absolute;width:1px;height:1px;padding:0;margin:-1px;overflow:hidden;clip:rect(0,0,0,0);white-space:nowrap;border:0}.cc-security-brief tbody,.cc-security-brief tr,.cc-security-brief td{display:block;width:100%}.cc-security-brief tr{background:#0f141a;border:1px solid #2d3642;border-radius:16px;margin:0 0 12px;padding:7px 16px}.cc-security-brief td{display:grid;grid-template-columns:minmax(92px,.85fr) 1.4fr;gap:13px;padding:11px 0;border-bottom:1px solid #252d38}.cc-security-brief td:before{content:attr(data-label);color:#8794a3;font:800 9px/1.45 ui-monospace,SFMono-Regular,Menlo,monospace;letter-spacing:.07em;text-transform:uppercase}.cc-security-brief td:last-child{border-bottom:0}.cc-status{margin-top:5px}}
</style>
<article class="cc-security-brief">
<header class="cc-hero">
<img fetchpriority="high" src="https://www.cryptocloaks.com/wp-content/uploads/2026/08/coldcard-entropy-bug-security-advisory-2026.jpg" alt="Coldcard Mk5 signing device used in CryptoCloaks' Coldcard entropy security advisory" width="1200" height="675" loading="eager" decoding="async"></p>
<div class="cc-hero-content">
<div class="cc-kicker"><span class="cc-pulse" aria-hidden="true"></span>Security Incident Brief // Updated August 5, 2026</div>
<h2>The Coldcard trust failure is bigger than a firmware update.</h2>
<p class="cc-deck">Affected Coldcard firmware generated some wallet secrets from dramatically less entropy than owners were promised. Fixed firmware protects future generation, but it cannot strengthen an existing weak seed.</p>
<div class="cc-chip-row"><span class="cc-chip">Severity: Critical</span><span class="cc-chip">Active exploitation reported by Block</span><span class="cc-chip">Migration required for affected seeds</span></div>
</div>
</header>
<section class="cc-verdict">
<div class="cc-wrap cc-verdict-grid">
<div class="cc-verdict-label">CryptoCloaks<br />Editorial Position</div>
<div>
<h2>CryptoCloaks does not recommend using Coldcard for Bitcoin custody.</h2>
<p>Our recommendation is to stop relying on Coldcard as your long-term primary signing platform, migrate any affected seed, and generate your replacement through a different, independently trusted key-generation workflow. An owner may still need the existing device temporarily to authorize a careful migration. Do not destroy it or its backup before the move is verified.</p>
<p class="cc-disclosure"><strong>This is CryptoCloaks&#8217; recommendation.</strong> It is stronger than Coinkite&#8217;s official guidance, which says fixed firmware corrects future seed generation. We are making a trust and risk-management judgment; we are not claiming that every updated Coldcard or every seed ever imported into one is mathematically compromised.</p>
</div>
</div>
</section>
<div class="cc-wrap">
<div class="cc-source-line"><span><strong>Evidence standard:</strong> Primary-source claims only, with opinion clearly labeled</span></p>
<div class="cc-source-badges"><span class="cc-source-badge">Coinkite advisory</span><span class="cc-source-badge">Coinkite technical report</span><span class="cc-source-badge">Block Engineering</span><span class="cc-source-badge">Coldcard firmware notes</span></div>
</div>
<div class="cc-stat-grid" aria-label="Incident summary">
<div class="cc-stat alert"><b>~40 bits</b><span>Coinkite&#8217;s preliminary effective-search-space estimate for affected Mk2/Mk3 seeds.</span></div>
<div class="cc-stat alert"><b>~72 bits</b><span>Coinkite&#8217;s preliminary estimate for affected Mk4, Mk5, and Q seeds.</span></div>
<div class="cc-stat"><b>50 rolls</b><span>Minimum fair, independent, private D6 rolls for Coinkite&#8217;s stated exception.</span></div>
<div class="cc-stat good"><b>New seed</b><span>Required after fixed firmware. Updating alone does not repair the old seed.</span></div>
</div>
<div class="cc-callout danger"><span class="cc-callout-label">Immediate warning</span></p>
<p>If a funded seed was generated on affected firmware without at least 50 fair, independent, private dice rolls, follow the migration guidance now. A strong, unique BIP-39 passphrase may reduce immediate exposure, but Coinkite says it does not repair the affected seed and passphrase users should also migrate as soon as practical.</p>
</div>
<div class="cc-action-grid" aria-label="Immediate actions">
<div class="cc-action"><span class="cc-action-num">01</span></p>
<h3>Stop depositing</h3>
<p>Do not send new funds to a wallet controlled by a potentially affected seed.</p>
</div>
<div class="cc-action"><span class="cc-action-num">02</span></p>
<h3>Verify the seed&#8217;s origin</h3>
<p>Identify the model, release track, and firmware that generated it. Today&#8217;s firmware version is not enough.</p>
</div>
<div class="cc-action"><span class="cc-action-num">03</span></p>
<h3>Migrate calmly</h3>
<p>Generate a new seed through a trusted process, verify backups and addresses, send a test, then move the balance.</p>
</div>
</div>
<nav class="cc-toc" aria-label="Table of contents">
<div class="cc-toc-title">Inside this security brief</div>
<ol>
<li><a href="#verified-facts">Verified facts versus our recommendation</a></li>
<li><a href="#what-happened">What happened inside Coldcard</a></li>
<li><a href="#affected">Affected models and firmware</a></li>
<li><a href="#risk">How serious the risk is</a></li>
<li><a href="#action">What owners should do now</a></li>
<li><a href="#dice-passphrase">Dice and passphrase exceptions</a></li>
<li><a href="#technical">The technical failure</a></li>
<li><a href="#broader-scope">Functions beyond seed generation</a></li>
<li><a href="#why-no-recommendation">Why we do not recommend Coldcard</a></li>
<li><a href="#faq">Accuracy-first FAQ</a></li>
<li><a href="#sources">Primary sources</a></li>
</ol>
</nav>
</div>
<section class="cc-section" id="verified-facts">
<div class="cc-wrap">
<div class="cc-section-head">
<div class="cc-section-no">01 // SCOPE</div>
<h2>What is verified, and what is our judgment?</h2>
</div>
<p class="cc-lede">The most important accuracy rule is not to turn a serious, confirmed RNG failure into claims the evidence does not support.</p>
<div class="cc-action-grid">
<div class="cc-action"><span class="cc-callout-label">Verified fact</span></p>
<h3>Affected seeds may be searchable offline</h3>
<p>The wrong PRNG implementation reached wallet secret generation. Coinkite estimates materially reduced effective search spaces.</p>
</div>
<div class="cc-action"><span class="cc-callout-label">Verified fact</span></p>
<h3>New firmware cannot heal an old seed</h3>
<p>The fixes change future random generation. Funds on an affected seed must be moved to a newly generated seed unless Coinkite&#8217;s dice exception applies.</p>
</div>
<div class="cc-action"><span class="cc-callout-label">Our recommendation</span></p>
<h3>Do not choose Coldcard for new primary custody</h3>
<p>This is CryptoCloaks&#8217; assessment of vendor trust, review quality, and key-generation risk after the disclosure.</p>
</div>
</div>
<div class="cc-callout fact"><span class="cc-callout-label">Important boundary</span></p>
<p>This incident is not evidence that an attacker can remotely control every Coldcard. A seed securely generated somewhere else and later imported into a Coldcard was not created by this faulty RNG path. TAPSIGNER, OPENDIME, and SATSCARD use different codebases and Coinkite says they are not affected by this bug.</p>
</div>
</div>
</section>
<section class="cc-section" id="what-happened">
<div class="cc-wrap">
<div class="cc-section-head">
<div class="cc-section-no">02 // FAILURE</div>
<h2>What happened inside Coldcard?</h2>
</div>
<p class="cc-lede">During a 2021 cryptographic-library migration, Coldcard wallet generation changed from its board-specific hardware RNG path to <code>ngu.random.bytes()</code>. That call resolved to MicroPython&#8217;s deterministic Yasmarang fallback instead of the intended hardware random-number generator.</p>
<p>The hardware RNG code was still present in the firmware binary, but the wallet-generation path did not reach it. The fallback exposed the same function shape, so the build completed. Code review confirmed that the intended implementation existed; it did not prove which implementation the seed-generation call actually used.</p>
<p>The result was not merely &#8220;bad-looking randomness.&#8221; A deterministic generator can produce output that appears statistically uniform while still selecting from a candidate family far smaller than the expected 128-bit or 256-bit security target. An attacker can generate candidates offline and use public wallet material, such as an address or extended public key, to test them.</p>
<div class="cc-quote">
<p>&#8220;We are publishing this advisory early, because active exploitation is under way.&#8221;</p>
<p><cite>Block Engineering, while also stating it had not completed full empirical testing for every exploit scenario</cite></div>
<p>Block says its investigation followed theft reports and concluded that active exploitation was underway. Block also explicitly says its report reflects its current understanding and that it had not performed full empirical testing to confirm every exploit path. CryptoCloaks has not independently verified individual theft claims. We therefore present Block&#8217;s statement as Block&#8217;s conclusion, not as independent proof of each reported loss.</p>
</div>
</section>
<section class="cc-section" id="affected">
<div class="cc-wrap">
<div class="cc-section-head">
<div class="cc-section-no">03 // EXPOSURE</div>
<h2>Which Coldcard models and firmware are affected?</h2>
</div>
<p class="cc-lede">The version that generated the seed is what matters. Installing safe firmware today does not change how an existing seed was created.</p>
<div class="cc-table-wrap">
<table>
<thead>
<tr>
<th>Model / track</th>
<th>Affected seed-generation firmware</th>
<th>Fixed before replacement generation</th>
<th>Coinkite estimate</th>
</tr>
</thead>
<tbody>
<tr>
<td data-label="Model / track"><strong>Mk2 / Mk3</strong><br /><span class="cc-status">Affected range</span></td>
<td data-label="Affected firmware">4.0.1 through 4.1.9 inclusive</td>
<td data-label="Fixed release"><span class="cc-fix">4.2.0 or later</span></td>
<td data-label="Estimate">About 40 bits</td>
</tr>
<tr>
<td data-label="Model / track"><strong>Mk4 / Mk5 standard</strong><br /><span class="cc-status">Affected before fix</span></td>
<td data-label="Affected firmware">Before 5.6.0</td>
<td data-label="Fixed release"><span class="cc-fix">5.6.0 or later</span></td>
<td data-label="Estimate">About 72 bits</td>
</tr>
<tr>
<td data-label="Model / track"><strong>Q standard</strong><br /><span class="cc-status">Affected before fix</span></td>
<td data-label="Affected firmware">Before 1.5.0Q</td>
<td data-label="Fixed release"><span class="cc-fix">1.5.0Q or later</span></td>
<td data-label="Estimate">About 72 bits</td>
</tr>
<tr>
<td data-label="Model / track"><strong>Mk4 / Mk5 Edge</strong><br /><span class="cc-status">Separate track</span></td>
<td data-label="Affected firmware">Before 6.6.0X</td>
<td data-label="Fixed release"><span class="cc-fix">6.6.0X or later</span></td>
<td data-label="Estimate">About 72 bits</td>
</tr>
<tr>
<td data-label="Model / track"><strong>Q Edge</strong><br /><span class="cc-status">Separate track</span></td>
<td data-label="Affected firmware">Before 6.6.0QX</td>
<td data-label="Fixed release"><span class="cc-fix">6.6.0QX or later</span></td>
<td data-label="Estimate">About 72 bits</td>
</tr>
</tbody>
</table>
</div>
<div class="cc-callout warning"><span class="cc-callout-label">Version discrepancy handled explicitly</span></p>
<p>Block&#8217;s technical timeline labels the Mk2/Mk3 range as 4.0.0 through 4.1.9. Coinkite&#8217;s owner-facing advisory and technical backgrounder list 4.0.1 through 4.1.9 and say the vulnerable wallet-generation path entered production in March 2021. Our decision table follows Coinkite&#8217;s current owner guidance. If you cannot prove how your seed was generated, do not gamble on the boundary; migrate.</p>
</div>
<p>Standard and Edge are different release tracks. A numerically higher older Edge version is not automatically fixed. Use the fixed release for the model and track you actually run.</p>
</div>
</section>
<section class="cc-section" id="risk">
<div class="cc-wrap">
<div class="cc-section-head">
<div class="cc-section-no">04 // SEVERITY</div>
<h2>How serious is the Coldcard entropy risk?</h2>
</div>
<p class="cc-lede">Coinkite&#8217;s current estimates are approximately 40 bits for affected Mk2/Mk3 generation and approximately 72 bits for affected Mk4/Mk5/Q generation. Both are below the intended security target.</p>
<p>These are preliminary effective-search-space estimates under stated attack assumptions, not promises that every wallet takes the same amount of work to recover. Practical attack cost depends on what can be constrained about device identity, boot timing, prior PRNG calls, derivation paths, passphrases, and public wallet information.</p>
<p>Block&#8217;s independent analysis describes deterministic fallback behavior on Mk2/Mk3 and a later-model reseed that retained only four bytes, or 32 bits, from secure-element-derived material. Coinkite says the later secure-element input materially improved Mk4, Mk5, and Q compared with Mk2/Mk3, but still did not meet the intended security level.</p>
<div class="cc-callout danger"><span class="cc-callout-label">Decision standard</span></p>
<p>You do not need to predict an attacker&#8217;s budget before acting. If an affected seed controls funds and the documented dice exception does not apply, treat the seed as exposed enough to require migration.</p>
</div>
</div>
</section>
<section class="cc-section" id="action">
<div class="cc-wrap">
<div class="cc-section-head">
<div class="cc-section-no">05 // RESPONSE</div>
<h2>What should Coldcard owners do now?</h2>
</div>
<div class="cc-callout warning"><span class="cc-callout-label">Do not panic-migrate</span></p>
<p>A rushed transfer can create a more immediate loss than the issue you are addressing. Verify firmware, backups, wallet fingerprints, and receive addresses on trusted hardware. Send a small test before moving the full balance.</p>
</div>
<ol class="cc-steps">
<li><strong>Stop sending new funds to the potentially affected wallet.</strong> Preserve the existing device and backup long enough to authorize and verify the migration.</li>
<li><strong>Determine the seed&#8217;s origin.</strong> Record the model, standard or Edge track, and firmware version that generated it. If the history is uncertain, treat that uncertainty as risk.</li>
<li><strong>Read the current primary guidance.</strong> Use Coinkite&#8217;s security advisory and technical backgrounder, not screenshots or early summaries.</li>
<li><strong>Prepare a different trusted generation workflow.</strong> CryptoCloaks recommends not using Coldcard to generate the replacement. If you instead follow Coinkite&#8217;s path, install and verify the fixed release before creating anything new.</li>
<li><strong>Create a completely new seed.</strong> Never &#8220;upgrade&#8221; by reusing the affected words. Do not type seed words or private dice rolls into a website, chat, cloud note, or ordinary networked computer.</li>
<li><strong>Back up and reproduce the new wallet.</strong> Verify the wallet fingerprint and a receive address. Keep any BIP-39 passphrase separate from the seed words.</li>
<li><strong>Send a small test transaction.</strong> Confirm receipt and prove that you can reproduce the same wallet before transferring the remainder.</li>
<li><strong>Move the remaining funds and retire the old seed.</strong> Keep the old backup until every expected balance has arrived and confirmed. Then prevent the compromised or suspect seed from receiving funds again.</li>
</ol>
<p>Mk2/Mk3 owners who have only one device should follow Coinkite&#8217;s dedicated one-device sequence rather than improvising. CryptoCloaks&#8217; stronger platform recommendation does not change the need to preserve access long enough to move funds safely.</p>
</div>
</section>
<section class="cc-section" id="dice-passphrase">
<div class="cc-wrap">
<div class="cc-section-head">
<div class="cc-section-no">06 // EXCEPTIONS</div>
<h2>Dice rolls and passphrases: what actually changes the risk?</h2>
</div>
<h3>At least 50 fair, independent, private D6 rolls</h3>
<p>Coinkite says the bug did not erase independent entropy added through Coldcard&#8217;s dice-roll seed flow. Its current guidance states that 50 to 98 fair, independent, private D6 rolls contribute at least 128 bits of entropy, while 99 or more contribute approximately 256 bits.</p>
<ul>
<li><strong>50 or more qualifying rolls:</strong> Coinkite does not consider the resulting final seed at risk from this RNG issue alone.</li>
<li><strong>Fewer than 50, uncertain count, predictable rolls, recorded rolls, or exposed rolls:</strong> migrate.</li>
<li><strong>The exception applies to the final seed words displayed after the rolls were added.</strong> It does not apply if you later used a different seed.</li>
</ul>
<div class="cc-callout danger"><span class="cc-callout-label">Dice are secret key material</span></p>
<p>Do not photograph rolls, save them digitally, paste them into an online calculator, or enter real rolls on a normal networked computer.</p>
</div>
<h3>A strong BIP-39 passphrase is a separate barrier, not a repair</h3>
<p>A strong, unique, secret BIP-39 passphrase can make immediate candidate testing harder because an attacker must also discover the passphrase wallet. A short, common, patterned, quoted, reused, exposed, or uncertain passphrase should not be treated as protection. The Coldcard PIN is not a BIP-39 passphrase.</p>
<p>Coinkite still recommends that passphrase users migrate as soon as practical. Every passphrase, including a typo, creates a valid but different wallet, so compare the wallet fingerprint before moving funds.</p>
</div>
</section>
<section class="cc-section" id="technical">
<div class="cc-wrap">
<div class="cc-section-head">
<div class="cc-section-no">07 // ROOT CAUSE</div>
<h2>How did the wrong random-number generator ship?</h2>
</div>
<p>Coldcard moved elliptic-curve operations to Bitcoin Core&#8217;s <code>libsecp256k1</code> through the embedded libNgU library. During that migration, seed generation changed from <code>ckcc.rng_bytes()</code> to <code>ngu.random.bytes()</code>.</p>
<p>The board configuration defined <code>MICROPY_HW_ENABLE_RNG</code> as zero because Coldcard supplied a separate hardware-RNG wrapper. LibNgU checked whether the macro was defined, not whether its value was nonzero. MicroPython used the zero value to compile its deterministic fallback. Compatible function signatures allowed the wrong implementation to satisfy the build.</p>
<p>On affected Mk2/Mk3 firmware, the fallback was seeded mainly from device and timing state. On Mk4, Q, and Mk5, secure-element values were mixed into the software generator, but Block&#8217;s analysis says only four digest bytes reached the reseed function.</p>
<p>Coinkite says the hotfix removes the fallback PRNG object and adds a link/build-time symbol check so the build fails unless the board-specific RNG implementation supplies the expected symbol and the upstream fallback supplies none.</p>
</div>
</section>
<section class="cc-section" id="broader-scope">
<div class="cc-wrap">
<div class="cc-section-head">
<div class="cc-section-no">08 // OTHER USES</div>
<h2>The RNG stream was used beyond ordinary BIP-39 seed generation.</h2>
</div>
<p>Block&#8217;s report says the same <code>ngu.random</code> construction fed additional functions, including random paper-wallet keys, random Seed XOR masks, some cloning and encrypted-transfer keys, generated Secure Notes passwords, and other temporary key material.</p>
<p>That does not mean every feature has the same impact or that every use reveals the main wallet. Consequences depend on whether public material allows candidate private values to be tested and what an attacker captured. A vulnerable paper-wallet key, for example, could threaten that standalone paper wallet without necessarily exposing the device&#8217;s primary seed.</p>
<div class="cc-callout fact"><span class="cc-callout-label">Advanced-feature users</span></p>
<p>If you used Coldcard-generated paper wallets, random Seed XOR masks, cloning transfers, or generated Secure Notes passwords on affected firmware, read Block&#8217;s complete technical report and monitor Coinkite&#8217;s updates. Do not infer the impact from the BIP-39 table alone.</p>
</div>
</div>
</section>
<section class="cc-section" id="why-no-recommendation">
<div class="cc-wrap">
<div class="cc-section-head">
<div class="cc-section-no">09 // TRUST</div>
<h2>Why CryptoCloaks does not recommend Coldcard.</h2>
</div>
<p class="cc-lede">A hardware wallet is a trust decision about key generation, implementation review, release engineering, and incident response. The specific hotfix matters, but so does the failure mode that reached production.</p>
<ul>
<li>The intended secure RNG implementation existed in the firmware, yet the critical wallet-generation path reached a deterministic fallback.</li>
<li>The integration survived builds and review because symbol presence was mistaken for proof of runtime binding.</li>
<li>The affected path remained in released firmware across multiple product generations and release tracks.</li>
<li>The same random stream was used by functions beyond standard seed generation.</li>
<li>Coinkite&#8217;s own estimates say some affected seeds delivered far less search resistance than users expected.</li>
</ul>
<p>Coinkite has published fixes, owner guidance, and a technical backgrounder. Those actions matter and should be judged on their merits. Our conclusion is still that we are not comfortable recommending Coldcard for new or primary custody. That is a vendor-trust conclusion, not a claim that the fixed firmware is secretly proven broken.</p>
<div class="cc-cta">
<h2>Choose a different signing workflow, then verify it yourself.</h2>
<p>CryptoCloaks recommends a stateless, air-gapped signing workflow with independently generated entropy and reproducible wallet fingerprints. Our SeedSigner+ product is a case and electronics kit and <strong>requires a Raspberry Pi Zero</strong>; it is not a complete ready-to-sign device by itself. No hardware or kit removes the need to verify the build, seed process, backup, fingerprint, and receive address.</p>
<div class="cc-buttons"><a class="cc-button primary" href="https://www.cryptocloaks.com/product/seedsigner-plus-bitcoin-signing-device/">See the SeedSigner+ case and electronics kit</a><a class="cc-button secondary" href="https://www.cryptocloaks.com/2026/05/best-bitcoin-seed-backup-for-real-people/">Build a safer backup plan</a></div>
<p class="cc-fineprint">CryptoCloaks sells the linked kit and physical backup tools. That commercial relationship is disclosed because it can affect our incentives. The technical claims above remain linked to primary sources.</p>
</div>
</div>
</section>
<section class="cc-section cc-faq" id="faq">
<div class="cc-wrap">
<div class="cc-section-head">
<div class="cc-section-no">10 // FAQ</div>
<h2>Accuracy-first Coldcard entropy FAQ</h2>
</div>
<details>
<summary>Was every Coldcard remotely hacked?</summary>
<p>No. The confirmed issue is an RNG integration failure that can make some generated secrets searchable offline. It is not evidence that an attacker remotely controls every Coldcard.</p>
</details>
<details>
<summary>Should I keep using Coldcard after installing fixed firmware?</summary>
<p>Coinkite says fixed firmware corrects future generation. CryptoCloaks does not recommend using Coldcard for Bitcoin custody. That is our trust judgment, not proof that every corrected device remains cryptographically vulnerable.</p>
</details>
<details>
<summary>Does new firmware fix my existing seed?</summary>
<p>No. Firmware cannot retroactively add entropy to a seed that already exists. Affected owners need a completely new seed and a verified fund migration unless Coinkite&#8217;s independent dice-entropy exception applies.</p>
</details>
<details>
<summary>Does the Coldcard PIN protect an affected seed?</summary>
<p>No. The device PIN controls access to the hardware. It is not a BIP-39 passphrase and does not add an independent secret to offline candidate testing against public wallet data.</p>
</details>
<details>
<summary>I used a BIP-39 passphrase. Am I safe?</summary>
<p>A strong, unique, secret passphrase adds a separate barrier and may reduce immediate exposure. Weak or uncertain passphrases should not be trusted. Coinkite still recommends migrating because the passphrase does not repair the affected seed.</p>
</details>
<details>
<summary>I entered at least 50 dice rolls. Do I need to migrate?</summary>
<p>Coinkite says at least 50 fair, independent, private D6 rolls in the original seed-creation flow contribute at least 128 bits and the final seed is not considered at risk from this RNG issue alone. If the count, fairness, privacy, or final seed is uncertain, migrate.</p>
</details>
<details>
<summary>What if my seed was generated somewhere else and imported?</summary>
<p>This bug concerns entropy produced by the affected Coldcard firmware path. A seed securely generated elsewhere was not weakened merely by being imported. Its safety still depends on its original generation, handling, passphrase, and backups.</p>
</details>
<details>
<summary>Should I destroy my Coldcard and old backup now?</summary>
<p>No. Preserve the device and old backup until the new wallet is verified and the complete expected balance has arrived. Destroying the only usable authorization path before migration finishes can cause permanent loss.</p>
</details>
</div>
</section>
<section class="cc-section" id="sources">
<div class="cc-wrap">
<div class="cc-section-head">
<div class="cc-section-no">11 // SOURCES</div>
<h2>Primary and independent technical sources</h2>
</div>
<ul class="cc-sources">
<li><a href="https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/" rel="noopener" target="_blank">Coinkite: Coldcard Security Advisory</a></li>
<li><a href="https://blog.coinkite.com/entropy-technical-backgrounder/" rel="noopener" target="_blank">Coinkite: Technical Deep Dive into the Entropy Issue</a></li>
<li><a href="https://coldcard.com/docs/upgrade/" rel="noopener" target="_blank">Coldcard: Current firmware and upgrade instructions</a></li>
<li><a href="https://coldcard.com/docs/verifying-dice-roll-math/" rel="noopener" target="_blank">Coldcard: Verifying dice-roll math</a></li>
<li><a href="https://coldcard.com/docs/passphrase/" rel="noopener" target="_blank">Coldcard: BIP-39 passphrase documentation</a></li>
<li><a href="https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware" rel="noopener" target="_blank">Block Engineering: Predictable RNG Fallback and 32-Bit Reseed in Coldcard Firmware</a></li>
</ul>
<p class="cc-security-note">SECURITY NOTE // CryptoCloaks will never ask for your seed words, passphrase, dice rolls, xprv, private keys, or wallet backup. No legitimate migration help requires sending those secrets to us.</p>
</div>
</section>
</article>
<p>The post <a rel="nofollow" href="https://www.cryptocloaks.com/2026/08/coldcard-entropy-bug-security-advisory-2026/">Coldcard Entropy Bug: Why CryptoCloaks Does Not Recommend Coldcard</a> appeared first on <a rel="nofollow" href="https://www.cryptocloaks.com">CryptoCloaks</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.cryptocloaks.com/2026/08/coldcard-entropy-bug-security-advisory-2026/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">65262</post-id>	</item>
	</channel>
</rss>
