Key Safety · Coldcard seed warning

Does this warning affect your wallet?

Check whether seeds created by affected Coldcard firmware could provide enough keys to spend your wallet. No seed words, addresses, xpubs, or passphrases are requested.

Check my wallet ↓Usually takes about three minutes
Runs entirely in this tab No secrets requested Updated 5 Aug 2026 Independent · not Coinkite
Why receiving-only wallets can still be exposed

Your Coldcard created seed words that derive private keys. If an attacker can recreate enough of those keys, they can satisfy the wallet’s spending rule—even if your device has never sent a transaction.

Check your wallet.

Choose the wallet type, then check how each key’s seed words were created.

Keep all secret material off this page.  Use only device families, creation-time firmware categories, dice counts, and broad passphrase strength. Never enter seed words, wallet identifiers, addresses, setup files, or passphrases.

Which wallet holds the Bitcoin?

A signer means one set of seed words in the wallet’s spending rule.

2-of-2 multisig · both keys required
1 key required · 1 signer total

One affected seed is sufficient to spend this wallet.

Check each key

Use the device and firmware that first created the seed words.

Your result

This answers the Coldcard advisory only.

Ready when you are

Answer the key questions to see your result.

No conclusion has been drawn from the empty form.

Compare the current wallet with two alternatives

Option A comes from the incident check above. Options B and C are editable replacement plans.

Choose the simplest fresh-key setup you can confidently recover. A clean singlesig can be safer than a badly operated multisig.

View updated tradeoffs ↓

Compare the tradeoffs

What mattersA · Current walletB · Alternative oneC · Alternative two

Loss tolerance assumes the remaining backups work. Rehearse recovery before funding.

Theoretical random-key probabilities and technical model
Optional model controls

Set the attacker assumptions

Based on one RTX 4090 benchmark. Larger presets assume ideal linear scaling. Hardware changes attack time and time-window chance where derivable; it cannot change the probability of one random guess.

Real coordination, hardware, and energy costs are not included.
Changes time-window probability when the source supports one; otherwise it changes only the amount of work available.

There are two different questions, so there are two different units. “One-guess success chance” is a probability: can one randomly chosen set of private keys spend from the wallet? “Attack work” is a count of candidate seeds or elliptic-curve calculations. Time is that work count divided by calculations per second.

12 words · 2128 valid BIP39 mnemonics 24 words · 2256 valid BIP39 mnemonics Checksum bits detect errors · they add 0 secret bits

Word count changes the mnemonic-enumeration route. It does not change the 256-bit private-key space or the roughly 2128-operation public-key attack. The page compares elapsed time across those different units and reports the faster applicable route.

1-of-1 · 1 success per 2256 random private-key sets 2-of-3 · ≈1 success per 2510 random private-key sets 3-of-5 · ≈1 success per 2765 random private-key sets

For independent uniform keys, P = Σj=k…n C(n,j)pj(1−p)n−j, where p=2−256. The combinatorial term matters: 2-of-3 has three valid pairs, while 3-of-5 has ten valid triples.

One required key · ≈2128 elliptic-curve calculations Two required keys · ≈2128 elliptic-curve calculations Three required keys · ≈2129 elliptic-curve calculations

Those public-key figures are close because the standard attack against sound Bitcoin keys can reuse some work: two required keys cost about 1.5× the one-key calculation count and three cost about 1.875×. Multisig’s practical benefit is different: separately created keys prevent one seed failure from satisfying the spending rule.

Time uses T = work ÷ measured-model rate. For a uniform search space, the chance within time t is min(rate × t ÷ 2b, 1). Block’s deterministic/average-trial findings are attack-work statements, so the page refuses to turn them into a made-up probability. Coinkite’s preliminary estimates are shown separately: about 40 effective bits for Mk2/Mk3 and 72 for Mk4/Q/Mk5.

An LLM is not a cryptographic engine. The audited local model assigns it no reduction in sound entropy, hash, or curve work. The displayed “LLM-assisted” weak-seed time is a clearly labeled 10× scanner stress case plus a separate judged 3–123.5-hour tool-preparation range—not a measured universal speedup.

Affected firmware and the dice exception

Mk2/Mk3 versions 4.0.1–4.1.9 are affected. Mk4/Mk5 are fixed in standard 5.6.0+ or Edge 6.6.0X+; Q is fixed in standard 1.5.0Q+ or Edge 6.6.0QX+. Coinkite says at least 50 fair, independent, private rolls clear this RNG issue alone. Read the advisory ↗

Why same-vendor multisig may fail together

Multiple seeds created by the same affected generator belong to a shared weak class. Enumerating that class can expose more than one signer, so adding same-line cosigners does not create independent protection against the defect.

Method, limits, and sources

The model asks whether affected or unresolved keys can satisfy the spending rule, then keeps Block’s attack-work findings separate from Coinkite’s preliminary effective-search estimates. Time is conditional on selectable hardware assumptions; it is not a prediction that a theft will occur. Unknown seed origins receive no invented strength. The model does not assess malware, coercion, backup theft, inheritance, or every unknown firmware defect.