Key Safety · Coldcard seed warning
Does this warning affect your wallet?
Check whether seeds created by affected Coldcard firmware could provide enough keys to spend your wallet. No seed words, addresses, xpubs, or passphrases are requested.
Your Coldcard created seed words that derive private keys. If an attacker can recreate enough of those keys, they can satisfy the wallet’s spending rule—even if your device has never sent a transaction.
Check your wallet.
Choose the wallet type, then check how each key’s seed words were created.
Keep all secret material off this page. Use only device families, creation-time firmware categories, dice counts, and broad passphrase strength. Never enter seed words, wallet identifiers, addresses, setup files, or passphrases.
Which wallet holds the Bitcoin?
A signer means one set of seed words in the wallet’s spending rule.
2-of-2 multisig · both keys required
One affected seed is sufficient to spend this wallet.
Check each key
Use the device and firmware that first created the seed words.
Your result
This answers the Coldcard advisory only.
Answer the key questions to see your result.
No conclusion has been drawn from the empty form.
Show migration checklist
Compare the current wallet with two alternatives
Option A comes from the incident check above. Options B and C are editable replacement plans.
Choose the simplest fresh-key setup you can confidently recover. A clean singlesig can be safer than a badly operated multisig.
View updated tradeoffs ↓Compare the tradeoffs
| What matters | A · Current wallet | B · Alternative one | C · Alternative two |
|---|
Loss tolerance assumes the remaining backups work. Rehearse recovery before funding.
Theoretical random-key probabilities and technical model
Set the attacker assumptions
Based on one RTX 4090 benchmark. Larger presets assume ideal linear scaling. Hardware changes attack time and time-window chance where derivable; it cannot change the probability of one random guess.
There are two different questions, so there are two different units. “One-guess success chance” is a probability: can one randomly chosen set of private keys spend from the wallet? “Attack work” is a count of candidate seeds or elliptic-curve calculations. Time is that work count divided by calculations per second.
Word count changes the mnemonic-enumeration route. It does not change the 256-bit private-key space or the roughly 2128-operation public-key attack. The page compares elapsed time across those different units and reports the faster applicable route.
For independent uniform keys, P = Σj=k…n C(n,j)pj(1−p)n−j, where p=2−256. The combinatorial term matters: 2-of-3 has three valid pairs, while 3-of-5 has ten valid triples.
Those public-key figures are close because the standard attack against sound Bitcoin keys can reuse some work: two required keys cost about 1.5× the one-key calculation count and three cost about 1.875×. Multisig’s practical benefit is different: separately created keys prevent one seed failure from satisfying the spending rule.
Time uses T = work ÷ measured-model rate. For a uniform search space, the chance within time t is min(rate × t ÷ 2b, 1). Block’s deterministic/average-trial findings are attack-work statements, so the page refuses to turn them into a made-up probability. Coinkite’s preliminary estimates are shown separately: about 40 effective bits for Mk2/Mk3 and 72 for Mk4/Q/Mk5.
An LLM is not a cryptographic engine. The audited local model assigns it no reduction in sound entropy, hash, or curve work. The displayed “LLM-assisted” weak-seed time is a clearly labeled 10× scanner stress case plus a separate judged 3–123.5-hour tool-preparation range—not a measured universal speedup.
Affected firmware and the dice exception
Mk2/Mk3 versions 4.0.1–4.1.9 are affected. Mk4/Mk5 are fixed in standard 5.6.0+ or Edge 6.6.0X+; Q is fixed in standard 1.5.0Q+ or Edge 6.6.0QX+. Coinkite says at least 50 fair, independent, private rolls clear this RNG issue alone. Read the advisory ↗
Why same-vendor multisig may fail together
Multiple seeds created by the same affected generator belong to a shared weak class. Enumerating that class can expose more than one signer, so adding same-line cosigners does not create independent protection against the defect.
Method, limits, and sources
The model asks whether affected or unresolved keys can satisfy the spending rule, then keeps Block’s attack-work findings separate from Coinkite’s preliminary effective-search estimates. Time is conditional on selectable hardware assumptions; it is not a prediction that a theft will occur. Unknown seed origins receive no invented strength. The model does not assess malware, coercion, backup theft, inheritance, or every unknown firmware defect.