Decision RecordActivePublished without chair review
CRT-2026-024117 Aug 2026AFTERNOON EDITIONDaily Roundtable
Replace weak Coldcard wallet seeds after firmware remediation
A firmware update alone does not remediate seeds generated with weak entropy. Update affected devices, create entirely new seeds on fixed firmware, independently verify receiving addresses, replace affected signing descriptors, and migrate funds from old addresses.
Current public guidance · the full record
What to do now
At a glanceThe edition's authoritative action board carries no action for this record's subjects — no What to do now guidance.
Why now
Under reviewA firmware update affects future seed generation but does not strengthen existing Coldcard private keys.
Funds held at old addresses therefore remain exposed until a new seed and signing configuration are active and the funds have moved. The August 17, 2026 synthesis classifies weak Coldcard seeds as requiring decisive containment.
The materials mention 4.0.1, 4.1.9, and 5.6.0, but the missing vendor documents mean operators should obtain authoritative scope guidance without delaying replacement of seeds already identified as potentially affected.
Who is affected
Under reviewColdcard Mk3 operators whose seed-generation records mention 4.0.1 or 4.1.9, or otherwise fall within the scope confirmed by authoritative vendor guidance, face the possibility that existing private keys have substantially reduced entropy.
Coldcard Mk4 and Mk5 operators whose generation records relate to the reported 5.6.0 checkpoint require the same vendor-guided scope check; the packet does not independently establish the exact boundary.
Wallet owners who still hold funds at addresses derived from potentially affected seeds remain exposed after a device update because their existing keys do not change.
Multisignature coordinators and custodians using signing descriptors derived from those seeds must replace the affected descriptors and migrate funds.
Operators with contemporaneous proof of at least 50 independent private dice rolls or a strong, unique BIP-39 passphrase may have a different exposure assessment, but undocumented claims do not establish an exception.
What supports this
Partially supportedSupporting — The custody analysis explains that updating firmware changes only future seed generation and cannot strengthen private keys derived from an existing weak seed. It specifically supports new-seed generation, descriptor replacement, independent address verification, and fund migration.
Supporting — The crypto-fincrime analysis reports reduced entropy for Coldcard Mk3 and Mk4/Mk5 seed generation and names 4.0.1, 4.1.9, and 5.6.0. This supports treating the issue as a seed-compromise problem rather than only a device-patching problem.
Supporting — The final synthesis classifies weak Coldcard seeds as requiring decisive containment and treats replacement and migration as critical.
Evidence gap — The evidence review finds that the vendor advisory and firmware changelog themselves were not recorded. It therefore does not support presenting 4.0.1, 4.1.9, or 5.6.0 as independently verified scope boundaries.
How the Roundtable reached this
Under reviewThe crypto-fincrime contributor surfaced evidence that Coldcard seed generation had reduced entropy and distinguished existing keys from future seeds generated after remediation.
The decision scout converted that finding into the operational question of whether a firmware update alone was sufficient and concluded that it was not. The evidence review supported generating a new seed, replacing signing descriptors, independently verifying receiving addresses, and moving funds.
It also identified a material gap: the packet mentions 4.0.1, 4.1.9, and 5.6.0 but does not contain the underlying vendor advisory or changelog needed to verify exact boundaries. The boundary reviewer resolved this by retaining the remediation guidance while treating those boundaries as unverified.
The linker found no matching prior record, and the arbiter selected a new operational decision record.
Positions are generated by AI specialist personas and chaired by Halil Öztürkci.
Panel composition
- Scout (AI panel role)Scout identified 6 candidate signals.
- Linker (AI panel role)Linker evaluated 6 relation judgments.
- Evidence Auditor (AI panel role)Evidence Auditor recorded 13 evidence signals; 7 gaps.
- Prediction Steward (AI panel role)Prediction Steward accepted 1 prediction and rejected 1 claim.
- Boundary Reviewer (AI panel role)Boundary Reviewer recorded 10 public/private findings.
- Arbiter (AI panel role)Arbiter produced 6 decision envelopes.
Key disagreement
Scout (AI panel role)
The entropy defect is assessed with high confidence, but the reported aggregate bitcoin loss and attribution of every suspicious transaction to this defect are less certain. Documented independent entropy may justify an exception. | Merged related signal (candidate-7): What should organizations do if poisoned LiteLLM releases entered build or runtime environments? | Merged related signal (candidate-8): What remediation window should apply to exposed Adobe Commerce and Magento systems facing account-takeover attempts? | Merged related signal (candidate-9): What response should organizations take against Evooo1Bot exploitation of internet-facing Linux edge and industrial devices? | Merged rela
Arbiter outcome
Arbiter outcome: new decision record. No matching prior record was found. The evidence strongly supports replacing weak seeds and migrating funds; the vendor-source gap only requires omitting exact firmware ranges.
Candidates considered
Considered 6 candidates · opened 1 · 5 not opened (5 other)
Considered, not opened
Sign in to preview Considered-Not-Opened entries (moves to Pro at launch).
Sign in to preview practitioner entries.
What is uncertain
MissingThe exact Coldcard firmware scope remains unverified because the packet mentions 4.0.1, 4.1.9, and 5.6.0 without recording the underlying vendor advisory or changelog.
The materials report roughly 40 bits of entropy for one Mk3 interval and roughly 72 rather than 128 bits for an Mk4/Mk5 interval, but the primary documents are missing.
A contemporaneously documented minimum of 50 independent private dice rolls or a genuinely strong, unique BIP-39 passphrase may change an individual wallet’s exposure assessment. The aggregate bitcoin loss and attribution of every suspicious transaction to this entropy defect are also uncertain.
Evidence is bounded to August 17, 2026, so later vendor guidance or incident findings are not covered.
What evidence is missing
MissingThe packet does not include Coinkite’s primary advisory or firmware changelog, so the exact affected and fixed firmware boundaries associated with 4.0.1, 4.1.9, and 5.6.0 cannot be directly verified.
It also contains no private custody inventory, device-generation logs, signing records, or contemporaneous evidence of independent dice entropy or a strong unique BIP-39 passphrase. Those records are needed to determine which wallets qualify for an exception.
On-chain and investigative evidence sufficient to quantify losses or attribute suspicious transactions specifically to weak Coldcard seeds is also absent.
What would change this
Under reviewAuthoritative Coinkite evidence establishing different affected or fixed firmware boundaries would change which devices and seeds enter the migration queue; the packet’s references to 4.0.1, 4.1.9, and 5.6.0 are not sufficient to settle those boundaries.
Contemporaneous records proving at least 50 independent private dice rolls or a genuinely strong, unique BIP-39 passphrase could justify an exception for a particular seed. Records proving that a seed was generated outside the vendor-confirmed scope could also remove that wallet from remediation.
None of these conditions changes the core point that installing firmware cannot strengthen private keys already derived from a weak seed.
What to watch next
Under reviewMonitor Coinkite’s authoritative advisory and firmware changelog for verified scope and fixed baselines involving 4.0.1, 4.1.9, and 5.6.0; if those documents establish different boundaries, immediately revise the wallet inventory and migration queue.
Track every old address until its balance is migrated and the replacement descriptor is active. Monitor old addresses for unauthorized movement; any such movement triggers workflow isolation, evidence preservation, investigation, and reporting.
Reassess wallets only when contemporaneous records prove sufficient independent dice entropy, a strong unique BIP-39 passphrase, or generation outside the vendor-confirmed scope.
Evidence basis
Summary: Reported active exploitation of VMware vCenter, SAP Commerce Cloud, and macOS Screen Sharing drives the immediate response. VMware’s campaign chain is credible; SAP evidence confirms attempts but not victim compromise. Water-utilit…
Operational priorities are now much more concrete, but several claims remain bounded. SAP gets the first commerce response window: restrict exposure within one hour, patch within four, and start compromise assessment immediately. Adobe Comm…
Public value history
- 17 Aug 2026Initial public guidanceCurrent guidance
Created the first public value version for this Decision Record.
Source RoundtableAfternoon roundtableConvened 17 Aug 2026Methodology
How the panel reaches a Public Decision Record.