Bullish
Coldcard Expands Seed Phrase Vulnerability to Mk4, Mk5, and Q Devices
2026-07-31 21:48:18
Coldcard reveals seed phrase generation flaw affects Mk3, Mk4, Mk5, and Q models. Users urged to update firmware before creating new seeds or moving assets.
Woofun AI reports that hardware wallet manufacturer Coldcard has issued a security update expanding the scope of a seed phrase generation vulnerability. The risk now encompasses Mk3 versions 4.0.1 to 4.1.9, Mk4/Mk5 versions prior to 5.6.0, and Q versions before 1.5.0Q, contradicting earlier assurances that newer devices were unaffected. A patched version, Mk3 4.2.0, is available, with users advised to update firmware before generating new seeds or transferring funds.
WOOFUN AI
Impact Assessment · Quick Read
The expansion of this vulnerability to newer device models undermines previous security assurances, potentially eroding user trust in Coldcard's hardware wallets. Affected users must prioritize firmware updates to mitigate risks associated with compromised seed phrases. This incident highlights the critical importance of rigorous security audits in self-custody solutions, as flaws in key generation can expose significant capital.
Generated by WOOFUN AI · For reference only, not investment advice
Comments
No comments yet.