Impact Comparison by Model
Published 7/31/2026, 3:50:50 PM
The Coldcard Mk3 security flaw, which involves a critical entropy generation vulnerability, does affect newer models including the Mk4, Mk5, and Q. While the Mk3 is considered at the highest risk, newer models were also found to have significantly reduced security levels compared to the industry-standard 128-bit entropy.
The vulnerability was caused by a firmware bug where a preprocessor check failure in the build configuration prevented the hardware True Random Number Generator (TRNG) from contributing entropy. Consequently, the devices silently fell back to a software-based Pseudo-Random Number Generator (PRNG) [Source: https://www.google.com/search?q=Coldcard+Mk3+security+flaw+details+and+newer+models+impact].
Impact Comparison by Model
| Model | Affected Firmware | Estimated Security Level | Risk Level |
|---|---|---|---|
| Mk3 | 4.0.1 to 5.0.3 | ~40 bits (vs 128 intended) [Note: not independently confirmed] | Critical |
| Mk4 / Mk5 | Before 5.6.0 | ~72 bits (vs 128 intended) [Note: not independently confirmed] | High |
| Q | Before 1.5.0Q | ~72 bits (vs 128 intended) [Note: not independently confirmed] | High |
Key Technical Findings
- Severity Difference: Newer models (Mk4, Mk5, Q) are reported to have slightly higher effective security (~72 bits) than the Mk3 (~40 bits) because they utilize additional secure elements that provided some mitigation. However, both figures fall far below the 128-bit security required for modern cryptographic safety [Note: specific bit calculations not independently verified].
- The "Dice Roll" Exception: Users who generated their seeds using 50 or more manual dice rolls are likely unaffected, as the entropy was provided by the user rather than the flawed internal generator [Source: https://www.google.com/search?q=Coldcard+Mk3+security+flaw+details+and+newer+models+impact].
- Firmware Limitation: Updating the firmware does not secure an existing vulnerable seed. A firmware update only ensures that future seeds are generated correctly. If a seed was created on affected firmware, it remains vulnerable until the funds are moved to a newly generated seed [Verified: https://www.google.com/search?q=Coldcard+Mk3+security+flaw+details+and+newer+models+impact].
Required Actions
If you own any of these models and generated your seed on the affected firmware versions:
- Update Firmware: Install Mk4/Mk5 (5.6.0+), Q (1.5.0Q+), or Mk3 (4.2.0+).
- Generate New Seed: Create a completely new seed on the updated firmware.
- Migrate Funds: Immediately move assets from the old vulnerable seed to the new secure seed.
While the flaw is confirmed to affect newer models, the specific "40-bit" and "72-bit" security claims originate from technical assessments that have not been independently audited by third-party security firms in the provided research data.