Bullish

Coldcard Expands Seed Phrase Vulnerability to Mk4, Mk5, and Q Devices

2026-07-31 21:48:18

Coldcard reveals seed phrase generation flaw affects Mk3, Mk4, Mk5, and Q models. Users urged to update firmware before creating new seeds or moving assets.

Woofun AI reports that hardware wallet manufacturer Coldcard has issued a security update expanding the scope of a seed phrase generation vulnerability. The risk now encompasses Mk3 versions 4.0.1 to 4.1.9, Mk4/Mk5 versions prior to 5.6.0, and Q versions before 1.5.0Q, contradicting earlier assurances that newer devices were unaffected. A patched version, Mk3 4.2.0, is available, with users advised to update firmware before generating new seeds or transferring funds.

WOOFUN AI

Impact Assessment · Quick Read

The expansion of this vulnerability to newer device models undermines previous security assurances, potentially eroding user trust in Coldcard's hardware wallets. Affected users must prioritize firmware updates to mitigate risks associated with compromised seed phrases. This incident highlights the critical importance of rigorous security audits in self-custody solutions, as flaws in key generation can expose significant capital.
Generated by WOOFUN AI · For reference only, not investment advice

Comments

Me
Replying to @User
0/800

No comments yet.

Notifications

Sign in to view messages
View all messagesManage subscriptions