Decision RecordActivePublished without chair review

Replace weak Coldcard wallet seeds after firmware remediation

Coldcard weak-seed remediation

Reader challenge

Challenge this conclusion

Contest a specific conclusion. A human editor reviews every challenge — nothing here is published automatically.

Security check loading…
Confidence
High
Section support
High confidence · 0/8 backed · 2 gaps · panel
Severity
Critical
Assessed severity
Panel
AI roles · 1 disagreement
Freshness · v1
Last updated 2 days ago
Last revised 2026-08-17
Active4 evidence references · Published 17 Aug 2026 · Daily RoundtableServer-rendered freshness may trail the latest update by the page cache window.
Current position

A firmware update alone does not remediate seeds generated with weak entropy. Update affected devices, create entirely new seeds on fixed firmware, independently verify receiving addresses, replace affected signing descriptors, and migrate funds from old addresses.

Public guidance

Current public guidance · the full record

Current public value version · v1
01

What to do now

At a glance

The edition's authoritative action board carries no action for this record's subjects — no What to do now guidance.

02

Why now

Under review

A firmware update affects future seed generation but does not strengthen existing Coldcard private keys.

Funds held at old addresses therefore remain exposed until a new seed and signing configuration are active and the funds have moved. The August 17, 2026 synthesis classifies weak Coldcard seeds as requiring decisive containment.

The materials mention 4.0.1, 4.1.9, and 5.6.0, but the missing vendor documents mean operators should obtain authoritative scope guidance without delaying replacement of seeds already identified as potentially affected.

03

Who is affected

Under review

Coldcard Mk3 operators whose seed-generation records mention 4.0.1 or 4.1.9, or otherwise fall within the scope confirmed by authoritative vendor guidance, face the possibility that existing private keys have substantially reduced entropy.

Coldcard Mk4 and Mk5 operators whose generation records relate to the reported 5.6.0 checkpoint require the same vendor-guided scope check; the packet does not independently establish the exact boundary.

Wallet owners who still hold funds at addresses derived from potentially affected seeds remain exposed after a device update because their existing keys do not change.

Multisignature coordinators and custodians using signing descriptors derived from those seeds must replace the affected descriptors and migrate funds.

Operators with contemporaneous proof of at least 50 independent private dice rolls or a strong, unique BIP-39 passphrase may have a different exposure assessment, but undocumented claims do not establish an exception.

04

What supports this

Partially supported

Supporting — The custody analysis explains that updating firmware changes only future seed generation and cannot strengthen private keys derived from an existing weak seed. It specifically supports new-seed generation, descriptor replacement, independent address verification, and fund migration.

Supporting — The crypto-fincrime analysis reports reduced entropy for Coldcard Mk3 and Mk4/Mk5 seed generation and names 4.0.1, 4.1.9, and 5.6.0. This supports treating the issue as a seed-compromise problem rather than only a device-patching problem.

Supporting — The final synthesis classifies weak Coldcard seeds as requiring decisive containment and treats replacement and migration as critical.

Evidence gap — The evidence review finds that the vendor advisory and firmware changelog themselves were not recorded. It therefore does not support presenting 4.0.1, 4.1.9, or 5.6.0 as independently verified scope boundaries.

05

How the Roundtable reached this

Under review

The crypto-fincrime contributor surfaced evidence that Coldcard seed generation had reduced entropy and distinguished existing keys from future seeds generated after remediation.

The decision scout converted that finding into the operational question of whether a firmware update alone was sufficient and concluded that it was not. The evidence review supported generating a new seed, replacing signing descriptors, independently verifying receiving addresses, and moving funds.

It also identified a material gap: the packet mentions 4.0.1, 4.1.9, and 5.6.0 but does not contain the underlying vendor advisory or changelog needed to verify exact boundaries. The boundary reviewer resolved this by retaining the remediation guidance while treating those boundaries as unverified.

The linker found no matching prior record, and the arbiter selected a new operational decision record.

Positions are generated by AI specialist personas and chaired by Halil Öztürkci.

Panel composition

  • Scout (AI panel role)Scout identified 6 candidate signals.
  • Linker (AI panel role)Linker evaluated 6 relation judgments.
  • Evidence Auditor (AI panel role)Evidence Auditor recorded 13 evidence signals; 7 gaps.
  • Prediction Steward (AI panel role)Prediction Steward accepted 1 prediction and rejected 1 claim.
  • Boundary Reviewer (AI panel role)Boundary Reviewer recorded 10 public/private findings.
  • Arbiter (AI panel role)Arbiter produced 6 decision envelopes.

Key disagreement

Scout (AI panel role)

The entropy defect is assessed with high confidence, but the reported aggregate bitcoin loss and attribution of every suspicious transaction to this defect are less certain. Documented independent entropy may justify an exception. | Merged related signal (candidate-7): What should organizations do if poisoned LiteLLM releases entered build or runtime environments? | Merged related signal (candidate-8): What remediation window should apply to exposed Adobe Commerce and Magento systems facing account-takeover attempts? | Merged related signal (candidate-9): What response should organizations take against Evooo1Bot exploitation of internet-facing Linux edge and industrial devices? | Merged rela

Arbiter outcome

Arbiter outcome: new decision record. No matching prior record was found. The evidence strongly supports replacing weak seeds and migrating funds; the vendor-source gap only requires omitting exact firmware ranges.

Candidates considered

Considered 6 candidates · opened 1 · 5 not opened (5 other)

Considered, not opened

Sign in to preview Considered-Not-Opened entries (moves to Pro at launch).

Sign in to preview practitioner entries.

06

What is uncertain

Missing

The exact Coldcard firmware scope remains unverified because the packet mentions 4.0.1, 4.1.9, and 5.6.0 without recording the underlying vendor advisory or changelog.

The materials report roughly 40 bits of entropy for one Mk3 interval and roughly 72 rather than 128 bits for an Mk4/Mk5 interval, but the primary documents are missing.

A contemporaneously documented minimum of 50 independent private dice rolls or a genuinely strong, unique BIP-39 passphrase may change an individual wallet’s exposure assessment. The aggregate bitcoin loss and attribution of every suspicious transaction to this entropy defect are also uncertain.

Evidence is bounded to August 17, 2026, so later vendor guidance or incident findings are not covered.

07

What evidence is missing

Missing

The packet does not include Coinkite’s primary advisory or firmware changelog, so the exact affected and fixed firmware boundaries associated with 4.0.1, 4.1.9, and 5.6.0 cannot be directly verified.

It also contains no private custody inventory, device-generation logs, signing records, or contemporaneous evidence of independent dice entropy or a strong unique BIP-39 passphrase. Those records are needed to determine which wallets qualify for an exception.

On-chain and investigative evidence sufficient to quantify losses or attribute suspicious transactions specifically to weak Coldcard seeds is also absent.

08

What would change this

Under review

Authoritative Coinkite evidence establishing different affected or fixed firmware boundaries would change which devices and seeds enter the migration queue; the packet’s references to 4.0.1, 4.1.9, and 5.6.0 are not sufficient to settle those boundaries.

Contemporaneous records proving at least 50 independent private dice rolls or a genuinely strong, unique BIP-39 passphrase could justify an exception for a particular seed. Records proving that a seed was generated outside the vendor-confirmed scope could also remove that wallet from remediation.

None of these conditions changes the core point that installing firmware cannot strengthen private keys already derived from a weak seed.

09

What to watch next

Under review

Monitor Coinkite’s authoritative advisory and firmware changelog for verified scope and fixed baselines involving 4.0.1, 4.1.9, and 5.6.0; if those documents establish different boundaries, immediately revise the wallet inventory and migration queue.

Track every old address until its balance is migrated and the replacement descriptor is active. Monitor old addresses for unauthorized movement; any such movement triggers workflow isolation, evidence preservation, investigation, and reporting.

Reassess wallets only when contemporaneous records prove sufficient independent dice entropy, a strong unique BIP-39 passphrase, or generation outside the vendor-confirmed scope.

Sources & context

Evidence basis

4 references
Context
Summary: Reported active exploitation of VMware vCenter, SAP Commerce Cloud, and macOS Screen Sharing drives the immedia…

Summary: Reported active exploitation of VMware vCenter, SAP Commerce Cloud, and macOS Screen Sharing drives the immediate response. VMware’s campaign chain is credible; SAP evidence confirms attempts but not victim compromise. Water-utilit…

Observed 17 Aug 2026
Context
Operational priorities are now much more concrete, but several claims remain bounded. SAP gets the first commerce respon…

Operational priorities are now much more concrete, but several claims remain bounded. SAP gets the first commerce response window: restrict exposure within one hour, patch within four, and start compromise assessment immediately. Adobe Comm…

Observed 17 Aug 2026
Context
Interaction
Observed 17 Aug 2026
Revision trail

Public value history

1 event on record
1 value version · 1 update · 0 predictions
  1. 17 Aug 2026Initial public guidanceCurrent guidance

    Created the first public value version for this Decision Record.

Unified Search

Search the public record.