It seems that the details were already posted all over the place over Twitter and Telegram, so here is an explanation of it:
In Coldcard, there are two implementations of getting bytes from the HWRNG, in cckt and libngu.
The path in libngu is used for generating seeds. This one calls the MicroPython API to get random values.
The MicroPython API uses the HWRNG if enabled. The problem was that Coinkite disabled the HWRNG for MicroPython.
This should not have been an issue, as libngu had a check to see if the HW RNG is enabled. However, this used ifndef, which explicitly checked *if the HW RNG enable was not configured*. It did not check if the HW RNG enable was turned off explicitly, which is what Coinkite did.
This led to their code using the flawed software MicroPython RNG, which was solely based on the device boot time and a very weak manufacturing identifier.
This means that there are not a lot of different seeds. In Mk4/Mk5, this issue still exists. The only difference is that 32 actually random bits (which is tiny) have been mixed into the RNG.
By overly complicating their codebase, in what can only be described as “attempted security through complexity”, they have put all user funds at risk.
Regarding the implications:
- If you generated using dice or wordlist or another method that included non-Coldcard entropy, you are fine.
- If you generated on a non-Coldcard device, you are fine.
- If not, your funds are at risk. A passphrase will help slow it down but the main seed is still compromised.
Multisigs: You are affected *privacy wise* if one of your members is a Coldcard-generated seed. You are only at risk if the majority of your members are CC.
Secure element RNGs: These are fine. You need a proper one though from Infineon/NXP/ST, and not the crappy IoT ones.
Also beware the HWW firmware can still butcher the resulting numbers.
Login to reply
Replies (73)
Out of curiosity what do you mean by people with 1 key in a multisig generated with standard CC, not dice,are affected in terms of privacy?
In a multisig, only one xpub of a member is required to track *spends*.
(Compared to all of them for unspent outputs, which is why you MUST back it up to restore your wallet)
This is because the individual pubkeys derived from each member xpub are revealed on chain, and you could just check using one xpub.
Someone can bruteforce all possible seeds’ multisig xpubs to track individual wallets.
what about mk3 where seed was generated with firmware prior to v4.0.0? according to grok, seed was generated using hardware trng prior to v4.0.0.
So do you believe they're lying when they say K4, K5 and Q are unaffected or does it look like legitimate ignorance? I understand I'm asking an opinion on a fact post but these two premises conflict.
It is quoting Coinkite’s security disclosure. Do not trust AI solely on web data
Rotate your keys anyway.
Good info 👍👍
I’m not sure. Could be both, knowing NVK.
They did make an attempt to make the Mk4/5/Q RNG more secure. But this attempt is much weaker than thought.
URGENT 🚨 READ for all ColdCard users
View quoted note →
Urgent update for ColdCard users 🚨
View quoted note →
what about the Q ?
But why 32 bits, coldcard use both secure elements to do RNG, where does the 32 bits come from?
Commiserations to all the plebs, like me who stayed humble, who mixed and held and followed best practice only to scramble into a mass consolidated UTXO dox nightmare. When chain surveillance conspiracy?
Trading crypto doesn't have to be a guessing game.
Partner with Riley Greyson, a certified professional with a proven track record in market forecasting. Whether you're new or experienced, her simple strategy helps you trade smarter and capture real profits.
📲 Message her with "Join" right now to begin trading (
) @Riley Greyson

WhatsApp.com
Riley D Greyson
Business Account
If this is correct, any LLM would've caught that bug years ago. I don't get it.
View quoted note →
it seems at some point in their firmware it bypassed the SE RNG and fell back to some python RNG library or something like that.
Interpretation it’s safer to temporarily move your funds to a new backed up wallet created by a trezor, ledger or exchange like unchained or river.
If you are not sure what this means and you’ve been relying on coldcard something like nunchuck is also a good option but always be careful and methodical - rushing is a bigger risk.
So mk4 is still a risk just slightly less so?
This is interesting. So my mk3 that got drained was 1 of 3 in a multi vendor multi Sig. utxo that got drained last night was from that multi sig. I was able to salvage remaining unrelated sats in the wallet..
It compresses the two secure elements’ RNGs into 32 bits, and uses that as a seed for a insecure software PRNG that is mixed into the seed
Same thing
correct
By any chance, was that address reused?
Thank you for explaining everything to us NVK. Oh wait he’s gone off the fucking grid!!
Nope
Moved utxo from the vault then sent a portion of that utxo to a new address. the sats that went into the change address are what got drained
I have a seed that was likely generated by a ColdCard device prior to the Mk3. Does the Mk1 or Mk2 have this same entropy derp issue?
Likely yes.
oh boy, they really fucked it up.
And it went unnoticed for 4 years!
So is a 2-3 multisig with 2 CC newer devices at risk if no passphrases?
Why the fuck were they using micro python
View quoted note →
So you lost funds from the multisig or only from the single cc?
I can't thank myself enough for getting started. Despite the economic situation, I'm so happy to see €78,000 in returns from a €15,000 short-term investment with pjtradinghub. His videos are top-notch and highly educational, giving you real insights to achieve your goals and come out from debt! For a guide to a professional trader, I highly recommend everyone check out his Telegram 👉 "pjtradinghub"
Your entropy is still reduced, but the number of possible combinations is increased.
IOW, you all suffer from the fact the pool of private keys is (MUCH) more limited. But to move funds you'd need the right combination of three of them. (2 xprvs and all three xpubs).
You are safer, but if I were in your shoes I'd CAREFULLY move the coins. A Bip 39 passphrase helps quite a bit but is one more way to complicate and therefore shoot self in foot. 😁 whatever you do take care to do it well.
Not really. The effort to attack 1 wallet or 1000 or a multisig or 1000 multisig is the same.
It doesn’t matter if they are Q or MK5 devices?
I cede to your knowledge.
But don't you need to guess a combination of keys rather than just one?
I do not know the numberspace the borked rng drops down to, but wouldn't you need at least two xprvs (harder) and all three xpubs (not hard)?
I am surprised that you just mentioned Paul here. I met this man at a conference in 2021, and we have been working together ever since
I’ve been exploring different perspectives in the crypto space, and I’ve come across Paul Jon's content a few times. What stands out to me is his focus on risk management and staying patient rather than chasing quick profits. I don’t think there’s a single ‘perfect’ approach to trading, but it’s useful to learn from different viewpoints and then build your own strategy over time. Some of his ideas seem practical, especially for people who are still trying to understand market behavior. At the end of the day, everyone has to test what works for them and stay consistent. The market is always changing, so having a balanced mindset and being open to learning is probably more important than following any one method blindly. Just sharing my thoughts based on what I’ve seen so far.”
Where to find him
Telegram 👇
"Pjtradinghub"


my UTXOs are definitely doxxed now lol
Even if you did not consolidate, all your xpubs are out in the open
thoughts on Samsung secure elements?
Just my single sig and only one of the utxo
Multi sig which is multi vendor is not impacted
Only from the single sig cc
How do we know there will be no such vulnerabilities found in other wallets?
I bet 90% of people use single sig.
What’s a secure solution today? Only multisigs, or single sig (not Coldcard-generated) and passphrase could work?
"This should not have been an issue, as libngu had a check to see if the HW RNG is enabled. However, this used ifndef, which explicitly checked *if the HW RNG enable was not configured*. It did not check if the HW RNG enable was turned off explicitly, which is what Coinkite did."
This is incompetence.
The really impressive part is that NOBODY realised this in the last 5-6 years.
Ai.... It can now be a projects worst enemy and best friend.
This is the shove I need to move from dice & passphrase single sig to multivendor multisig dice + passphrase for each. Gonna setup a canary deposit on each multisig key as well & actively monitor for a compromised key.

for clarity sake should the following instead read... Multisigs: You are only at risk if the majority of your members are CC (AND that majority consists of Coldcard-generated seeds) ??
Why does this feel like fear harvesting? It start to feel like this particular when they’re saying multisig are of concern.
Let me explain: the possibility for a signal MK3.
With the MK3 That’s approximately 1.0995 \times 10^{12} (about 1.1 trillion).
Possible seeds. There could be for example 1.2 million wallets with funds.
The goal is to find funds.
In a multisig. You need all three keys to rebuild the wallet to generate a public address with funds.
Even with a finding two of the three keys, that was used to build a multisig that number is.
1 trillion × 1 trillion = 1,000,000,000,000,000,000,000,000
That’s 1 septillion (or 10^{24}).
Breakdown:
• 1 trillion = 10^{12}
• 10^{12} \times 10^{12} = 10^{24}
That is not how multisig recovery works, and a single UTXO spend can be used to recover the entire multisig
Really sorry man
Help me understand how a single UTXO could be used to rebuild a wallet.
yup, and maybe hubris
Sucks but could have been a lot worse for me. Need to switch the key in my multi sig setup also
Yea, you’re pwn’d
Users are also fine if you generated pre 2021 right?
Well, the guy was a graphic designer in a former life, not an engineer, iirc.
At this point, any single single wallet from any hardware wallet should be skeptical. We actually don’t have any idea where truth is right now. AI could find vulnerabilities in any hardware wallet so multi is gonna be the only way to go.
Single seed generated offline from good entropy (like dice rolls) is still a viable defense against offline signing device vulneraabilities.
Trading crypto doesn't have to be a guessing game.
Partner with Riley Greyson, a certified professional with a proven track record in market forecasting. Whether you're new or experienced, her simple strategy helps you trade smarter and capture real profits.
📲 Message her with "Join" right now to begin trading (
) @Riley Greyson

WhatsApp.com
Riley D Greyson
Business Account
Yeah seems a change was made in firmware version 4.0.0 - March 17, 2021 which changed the way RNG was generated and wallets generated before that should be fine, not sure I’d want to risk it and wait until the full report from coinkite comes out though


Block Engineering Blog
Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware
How a disabled hardware-RNG path and 32-bit reseed constrain entropy in affected COLDCARD firmware and expose generated secrets.
GitHub
firmware/releases/History-Mk3.md at master · Coldcard/firmware
❄️ Firmware and simulator for Coldcard Hardware Wallet - Coldcard/firmware
Trading crypto doesn't have to be a guessing game.
Partner with Riley Greyson, a certified professional with a proven track record in market forecasting. Whether you're new or experienced, her simple strategy helps you trade smarter and capture real profits.
📲 Message her with "Join" right now to begin trading (
) @Riley Greyson


WhatsApp.com
Riley D Greyson
Business Account

What a pain in the ass that’s gonna be
Certainly not a fun experience haha
You are correct the public keys are exposed in a transaction, where you send bitcoin like a purchase, and you are also returned the bitcoin back to the same wallet. This exposes the public. I learned something today.
I can't thank myself enough for getting started. Despite the economic situation, I'm so happy to see €78,000 in returns from a €15,000 short-term investment with pjtradinghub. His videos are top-notch and highly educational, giving you real insights to achieve your goals and come out from debt! For a guide to a professional trader, I highly recommend everyone check out his Telegram 👉 "pjtradinghub"


People 'verify' source code far less than people actually believe. The audience of people who actually can are less than people think too. The entropy code was likely read by many people, many times. It means most did not actually understand what was written. Larger projects pay for AppSec teams to do assurance testing / 'audits' because just having visible source code isn't equal to an audit.
Suspected and known malware get a more documented, deep analysis by security firms compared to most open source projects.
My open letter actually has a lot of this info also. I think we have the same understanding of the problem. 👀 Mk4 5 and q still only around 70 bits of entropy.
The obscurity of this issue specifically is almost the level of Jia Tan inserting a dot to break the sandboxing enable defined in CMakeLists.txt in xz.
Whats a “proper one”? I have a Letstrust with an SLB-9670 from Infineon. It was dead cheap and I got it for LUKS automated unlock.
```
-shell:~]# cat /proc/sys/kernel/random/entropy_avail
256
[nix-shell:~]# cat /dev/hwrng | rngtest -c 1000
rngtest 6.17
Copyright (c) 2004 by Henrique de Moraes Holschuh
This is free software; see the source for copying conditions. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
rngtest: starting FIPS tests...
rngtest: bits received from input: 20000032
rngtest: FIPS 140-2 successes: 1000
rngtest: FIPS 140-2 failures: 0
rngtest: FIPS 140-2(2001-10-10) Monobit: 0
rngtest: FIPS 140-2(2001-10-10) Poker: 0
rngtest: FIPS 140-2(2001-10-10) Runs: 0
rngtest: FIPS 140-2(2001-10-10) Long run: 0
rngtest: FIPS 140-2(2001-10-10) Continuous run: 0
rngtest: input channel speed: (min=13174.996; avg=1464176.220; max=0.000)bits/s
rngtest: FIPS tests speed: (min=127.157; avg=141.413; max=144.496)Mibits/s
rngtest: Program run time: 15331486 microseconds
```
I am a bit annoyed personally with Infineon, especially since they like to cheap out on their crypto it seems. See EUCLEAK (32-bit masking instead of full masking) and RoCA (weird “cheaper” prime generation algorithm)
Most commercial SEs also feed TRNG bytes through whitening and processing
I would say the random numbers generated by it, when mixed with the OS pool, are sufficiently good