PROOFOFCUSTODY
Scores
Incidents
Learn
About
Get the Report
PROOFOFCUSTODY

The independent scoring system for Bitcoin custody. Every platform scored and ranked.

$1B+ in assets under custody expertise

No spam. Unsubscribe anytime.

PLATFORM SCORES
All ScoresCompareMethodologyIndependence StandardDataCustody Assessment
LEARN
Bitcoin 101Custody GuidesCustody InsuranceIs Your Setup Safe?Custody TimelineIncidentsFAQQuiz
COMPANY
AboutAuthorsEditorial IndependenceChangelogCorrections
RESOURCES
PodcastPressReport
CONNECT
Twitter / XLinkedInYouTubehello@proofofcustody.io
2026 Proof of Custody. Published by Onramp Bitcoin. Editorial Independence.PrivacyTermsproofofcustody.io
Incident status

Am I affected by the Coldcard entropy failure?

Work through these six questions in order. Answer them about the wallet holding most of your bitcoin, then repeat for any others. If an answer is genuinely unknown, treat it as exposed rather than safe until you can establish it.

By Steve L, Editorial Lead·Reviewed by Proof of Custody Editorial
Published Jul 31, 2026·Last updated Aug 4, 2026
No legitimate party will ever ask for your seed phrase. Never type it into a website, form, chat, or phone call, including anything that claims to check exposure for you. This page asks you to look at your own records, never to enter them anywhere.
01

Was the seed generated on a Coldcard?

What matters is where the seed phrase was created, not which wallet holds it today. A seed created on a Coldcard and later imported elsewhere carries its origin with it.

No, it came from another brand, from my own dice, or from a custody providerNot implicated

This specific defect does not apply to you. The architecture questions further down still do.

Yes, or I am not certainNeeds checking

Continue to step 2.

02

Which model, and which firmware was running when you created the seed?

Exposure follows the firmware version at the moment of seed generation, not the purchase date and not the current firmware. If you cannot establish which firmware created the seed, treat it as unknown rather than safe.

Mk2 or Mk3 on firmware v4.0.1 through v4.1.9Treat as exposed

Both primary sources place this range at risk. Coinkite estimates about 40 bits of effective entropy against an intended 128. Fixed in 4.2.0 or later, but that fix does not repair an existing seed. Continue to step 3, then plan a migration.

Mk4 or Mk5 before firmware 5.6.0 (or Edge 6.6.0X)Treat as exposed

Coinkite's advisory, updated August 1, confirms these are affected at about 72 bits of entropy. Earlier coverage said these models were safe; that guidance is superseded. Continue to step 3.

Q before firmware 1.5.0Q (or Edge 6.6.0QX)Treat as exposed

Affected on the same basis as Mk4 and Mk5. Continue to step 3.

Mk1, or Mk2 / Mk3 before v4.0.1Not implicated

The affected range begins at v4.0.1 (March 2021), so earlier firmware sits outside this regression. That is not a statement that the device is free of every possible issue.

03

Did you use a dedicated dice-entropy path when creating the seed?

Coinkite's advisory states that funds are at risk if the seed was created without at least 50 independent, private dice rolls. Fifty fair rolls of a six-sided die contribute at least 128 bits of entropy on their own, which is why that path is treated differently. Adding a handful of rolls inside the normal new-wallet flow is not equivalent.

Yes, at least 50 independent private dice rollsReduced risk, not zero

Your entropy came from the dice rather than the device generator, which materially reduces exposure. Continue to step 4.

No, or I added a few rolls to the standard setup flowTreat as exposed

Treat the seed as generated by the device. Continue to step 4.

04

Is the wallet protected by a strong BIP39 passphrase?

A passphrase is an additional secret that produces a different wallet from the same seed words. An attacker who reconstructs the seed still needs it.

Yes, long, random, and uniqueReduced risk, not zero

Your bitcoin is now only as protected as that passphrase. Real risk reduction, not elimination. Plan a migration on your own timeline rather than in a panic.

No, or it is short, memorable, or reused elsewhereTreat as exposed

Treat the wallet as exposed and continue to step 5.

05

Is this a multisig wallet, and where did the other keys come from?

This is where the most consequential misreadings happen, in both directions. Multisig protects you when the keys are genuinely independent of one another.

Single signatureTreat as exposed

If the steps above put you at risk, there is nothing else standing between the reconstructed seed and your bitcoin. This is the highest-priority configuration to migrate.

Multisig, but enough affected devices to reach the spending thresholdTreat as exposed

Those keys are not independent. They share one firmware and one entropy path, so the quorum can be reached by the same root cause. Rotate the affected keys out.

Multisig where affected devices alone cannot reach the thresholdReduced risk, not zero

The threshold still holds, and this is exactly what genuine vendor diversity is for. Rotate the affected keys out in an unhurried, verified process.

06

Has this seed ever been exported, imported, or reused anywhere else?

The weakness lives in the seed itself, not in the device currently holding it.

Yes, it has been imported into another wallet or used for another chainTreat as exposed

Every wallet derived from that seed is exposed, on every chain. Migrate all of them, not only the bitcoin.

No, it has only ever existed on the original deviceNeeds checking

Your exposure is whatever the steps above established.

If you need to migrate

The greatest risk to an exposed holder is usually not the attacker. It is a rushed transfer made at midnight by someone frightened, to an address they did not verify, into a setup they have not tested. Slow down enough to be deliberate.

Generate new keys on a process unaffected by this defect, verify the receiving addresses on the device screen rather than a computer, send a small test amount first, confirm it arrives, then move the balance. Treat the old seed as permanently burned even if a later analysis clears your model.

On where to move: a different hardware vendor, a dedicated dice-generated seed, multi-vendor multisig, collaborative custody, and institutional custody are all legitimate destinations, and the right one depends on how much operational burden you want to carry. Temporarily parking funds at a reputable exchange while you build a proper setup is a defensible choice and is safer than a botched self-custody migration, provided it is temporary and you understand the counterparty trade.

The question worth answering before you choose is not which brand to buy. It is how many independent things would have to fail in the new setup, and who maintains that independence over the next twenty years. We work through that in Is your custody setup actually safe? and score arrangements against it in the Custody Independence Standard.

What to move toAssess your custody setupCompare platform scores
Frequently asked questions
How do I know which firmware created my seed?+

Check your own records: the purchase date, any firmware update history you kept, and when you first set the device up. If you cannot establish which firmware was running at seed generation, treat the seed as exposed rather than safe. The cost of migrating unnecessarily is far lower than the cost of being wrong.

Should I move my bitcoin to an exchange right now?+

Temporarily parking funds at a reputable exchange while you build a proper setup is defensible and is safer than a rushed self-custody migration you have not tested. Understand that you are taking on counterparty risk while they sit there, and treat it as a staging step rather than a destination.

Can I keep using my Coldcard after updating the firmware?+

Updating firmware does not repair a seed that was already created on an affected version. If your seed is exposed, you need a new seed, not new firmware. Whether to keep using the hardware afterwards is a separate decision about the vendor and your own comfort.