Critical Coldcard flaw: what happened, who is affected, and what to do

crcastle1 pts0 comments

Critical Coldcard flaw: what happened, who is affected, and what to do | Wizardsardine

Back to blog list

Coldcard

Security

Self-Custody

Multisig

Published on Sat, Aug 1, 2026 by Kevin Loaec

Critical Coldcard flaw: what happened, who is affected, and what to do

Coldcard devices had an entropy bug since 2021, MK2, MK3, MK4, MK5 and Q wallets are being drained right now. Here is what happened in the code, exactly who is affected, what to do today, and how to build a setup that withstands this kind of flaw.

How to read this VERY LONG blog post:

the first section covers Liana users, and is interesting to read to multisig users too. They cover risks and actions to take.

the rest of the article is the technical analysis of the bugs and risks surrounding the attack, incuding in-depth educational content.

If you don’t care about Liana or Multisig and just want to learn everything we know about the attack, skip the first sections.

This blog post was written by 3 people in parallel. Any first person “I, me, myself” is from Kevin Loaec, and may reflect personal preference and opinion not shared by the rest of the team.

Additional images will be added over time, to add clarity

⚠️ Liana users: if you use Coldcard devices in your setup, such that Coldcard devices are sufficent to spend without other keys (for example, a 2 -of-3 primary with 2 Coldcards, or even just a single sig Coldcard primay path), you need to move your funds to a new setup .

⚠️ Any Coldcard users: If you generated a seed on a Coldcard since 2021 , including models MK2, MK3, MK4, MK5 and Q , you need to move your funds immediately . Wallets are being drained as you read this. Only wallets generated using 50+ fair dice rolls are safe but advanced features of the device are still broken . Wallets from before 2021 are safe.

⚠️ Even if you did not generate your seed on an affected Coldcard, multiple advanced features of the Coldcard devices are broken. Dice rolls do not protect you here.

This article tries to cover as much of the scale of the unfolding situation as possible, including risks that are not yet exploited but imminent (a matter of hours).<br>1000s of bitcoins have already been drained, and this is only the beginning.

Fixed firmware is out, it DOES NOT save your existing seed and wallets. Coinkite shipped emergency hotfixes on 31 July: version 4.2.0 for the Mk3, 5.6.0 for the Mk4 and Mk5, and 1.5.0Q for the Q. The Edge channel, the experimental builds carrying the X and QX suffixes, has been fixed as well. These correct entropy generation for seeds created from now on. They do not repair a seed that was already generated by affected firmware. A firmware update on its own changes nothing for the coins you hold today.

Section 1: Liana, Miniscript and Multisig - you are potentially at risk

If none of your key was generated on a Coldcard, you are safe.<br>If any of your key was generated on a Coldcard, or coming from a mnemonic initially generated on a Coldcard, you may be at risk.

A Liana wallet spends through independent paths, the one thing that decides your risk is whether any single spending path can be satisfied with affected keys alone . A path falls the moment enough of its keys are weak to meet its threshold.<br>A &ldquo;primary path&rdquo; is the non-timelocked spending condition of Liana.

If your primary path can be met with affected Coldcard keys alone, move your funds while following the migration steps below. If only a recovery path can, move quickly but the timelock protects you.

⚠️ Before moving funds, read the WHAT DO I DO AS A LIANA USER? at the end of this section. It&rsquo;s important.

If you use the &ldquo;Simple inheritance&rdquo; setup

One key you use day to day, and a second key usable only after a delay, meant as a fallback or for an heir. Each path is a single key, so there is no threshold to protect you: one affected key breaks that path.

Where your affected Coldcard key sits<br>Risk<br>Action

The primary key<br>immediate risk<br>Move ASAP, following the steps below

Only the recovery key, expired timelock, Segwit wallet<br>immediate risk<br>Move ASAP, following the steps below

Only the recovery key, expired timelock, Taproot wallet<br>Recovery only risk<br>Move quickly, do not use Recovery

Only the recovery key, timelock still active<br>No risk as long as timelock is active<br>Move quickly, keep the timelock active

Neither key is from an affected Coldcard<br>Not affected by this flaw<br>None needed

Because inheritance setups are often left untouched for long stretches, the recovery-key case is not hypothetical: it becomes a risk for dormant, long-untouched wallet. Every time the coins move, the delay resets, which keeps that path shut until you can migrate.

If you use the &ldquo;Expanding multisig&rdquo; setup

Two keys are needed to spend day to day, and any two of three keys (your two everyday keys plus a recovery key) after a delay.

How many of your keys are affected Coldcards<br>Risk<br>Action

Only one key...

coldcard affected risk path move keys

Related Articles