bitcoin-hardware-coldcard

v2026.09.24

Coldcard hardware wallets (Coinkite): Mk4, Mk5, Q. Bitcoin-only firmware, airgap support via SD card / NFC / QR, BIP85, MuSig2 (Edge firmware), Trick PINs, and the July 2026 seed-entropy advisory. USE WHEN: integrating with Coldcard, supporting Mk4 / Mk5 / Q, designing airgap signing flows, assessing whether a seed was generated by affected firmware.

GitHub
Install command
npx skhub add claude-dev-suite/bitcoin-hardware-coldcard
Markdown
SKILL.md

Coldcard (Coinkite)

Bitcoin-only hardware wallet. Industry favorite for airgapped signing. Models: Mk4, Mk5, Q.

Security advisory: weak seed generation (2021-2026)

Critical. Any seed generated on a COLDCARD between March 2021 and July 2026 must be treated as compromised.

Coinkite published an advisory on 30 July 2026 (expanded 1 August 2026) plus a technical backgrounder. In the March 2021 libNgU migration, seed generation moved from ckcc.rng_bytes() to ngu.random.bytes(). MICROPY_HW_ENABLE_RNG was set to 0 to disable the software path, but the preprocessor guard tested whether the macro was defined rather than its value, so rng_get() linked to MicroPython's Yasmarang software PRNG instead of the hardware TRNG. The TRNG never failed at runtime; the build linked the wrong symbol, and both implementations had the same signature so nothing complained.

Effective search space, against a design target of 128 bits:

ModelsAffected firmwareEffective entropy
Mk2 / Mk34.0.1 - 4.1.9~40 bits
Mk4 / Mk5Standard < 5.6.0, Edge < 6.6.0X~72 bits
QStandard < 1.5.0Q, Edge < 6.6.0QX~72 bits

Mk4/Mk5/Q fare better only because SE1/SE2 entropy was still mixed into the PRNG state. TAPSIGNER, OPENDIME and SATSCARD use different codebases and are unaffected.

Fixed firmware:

LineFixed atLatest as of 15 September 2026
Mk2 / Mk3 Standard4.2.04.2.0 (final release for Mk2/Mk3)
Mk4 / Mk5 Standard5.6.05.6.2 (2026-09-03)
Q Standard1.5.0Q1.5.2Q (2026-09-03)
Mk4 / Mk5 Edge6.6.0X6.6.1X (2026-08-31)
Q Edge6.6.0QX6.6.1QX (2026-08-31)

Updating firmware does not fix an existing seed. From the technical backgrounder: "Updating the firmware does not repair a seed that was generated by affected firmware. A new seed must be generated and the funds migrated to the new wallet."

Exemptions and mitigations:

  • A seed mixed with >= 50 fair, independent, private dice rolls is not at risk from this bug alone (99+ rolls is ~256 bits of dice entropy).
  • A strong, unique, secret BIP-39 passphrase is an independent barrier, but Coinkite still says to migrate to a newly generated seed as soon as practical.

Migration: upgrade firmware first, generate a new seed on the fixed build, verify the backup, test with a small transaction, then move the remaining funds. Regenerate every secret derived on-device during the affected window, not just the master seed - BIP85 sub-seeds and duress/decoy wallets included.

Exploitation started 30 July 2026, the day of the advisory. As of TRM Labs' report of 5 August 2026, Galaxy Research's running tally stood at roughly 1,816 BTC (~USD 116 million) drained from more than 5,200 addresses across four waves. TRM calls that preliminary - funds were still moving and a fourth wave was still in the mempool at the time of writing. It is also cumulative, so the lower numbers in earlier press coverage are snapshots of the first waves.

Models

ModelYearNotes
Mk42022USB-C + microSD + NFC, no battery
Mk520261.54" Gorilla Glass, new keypad, bottom USB-C, NFC
Q2024Color touchscreen, USB-C, microSD, NFC, full keyboard, battery

The Mk5 is a March 2026 refresh of the Mk4 and shares its firmware builds: Coinkite ships a single Standard download covering "Mk4/Mk5" (as of September 2026).

Airgap support

Multiple transport options:

  • microSD card: write PSBT to card, sign on device, write back.
  • NFC: tap-to-transfer.
  • QR codes (Q only): scan + display.
  • USB: direct (less airgap).

Bitcoin-only firmware

Coldcard intentionally supports ONLY Bitcoin. No altcoins. Smaller attack surface, simpler mental model.

Trick PINs

Defense against coercion:

  • Set up multiple PINs.
  • "Real" PIN unlocks main wallet.
  • "Duress" PIN unlocks decoy wallet (real-looking but with different seed).
  • "Login countdown" — N attempts before wallet wipe.

BIP85

Native support for deriving sub-seeds via BIP85. UI lets you generate:

  • BIP39 mnemonic (any word count).
  • HEX bytes.
  • WIF private key.
  • xprv.

MuSig2 (Edge firmware)

MuSig2 signing shipped in Edge 6.5.0X / 6.5.0QX (24 March 2026) for Mk4/Mk5 and Q - "Ability to sign MuSig2 UTXOs", alongside BIP-322 proof of reserves for Miniscript and MuSig2 UTXOs. Key-path aggregation means the spend is indistinguishable on-chain from a single-signer Taproot spend.

Edge is Coinkite's faster-moving preview branch; the download page warns it is "Targeting developers and experimenters, the Edge version tracks the latest changes to Bitcoin" (as of September 2026). It also carries Taproot/Tapscript, BSMS (BIP-129), Miniscript and BIP-388 wallet policies. Standard firmware (5.6.x / 1.5.xQ as of September 2026) does not include MuSig2.

Later Edge releases hardened it: distinct nonces for different aggregate-key derivations of the same participant set, session handling for PSBTs with foreign MuSig2 inputs or differing witness UTXO data, preserving incomplete sessions while waiting for cosigner public nonces, no PSBT corruption when one participant signs multiple rounds via Key Teleport, and a 32-participant cap.

Cross-tool support has started: HWI 3.2.0 (10 February 2026) added PSBT MuSig2 fields.

Backup

  • Standard 24-word seed. Generate it only on fixed firmware (see the security advisory above), and mix in >= 50 private dice rolls if you want entropy that does not rest on the device alone.
  • "Tarot card" backup grids for resilient recovery.
  • BIP85-derived sub-seeds.
  • Encrypted backups to microSD with a separate backup password.
  • 5.6.2 / 1.5.2Q (September 2026) add View TRNG Words: shows the full 256-bit device-generated input as 24 BIP39 words before dice rolls or key presses are mixed in, so the mixing can be verified independently.

API

ckcc-protocol Python:

from ckcc_protocol.client import ColdcardDevice
dev = ColdcardDevice()
pk = dev.get_xpub("m/84'/0'/0'")
dev.sign_psbt(psbt_bytes)

Connection

  • USB-C.
  • microSD (airgap).
  • NFC (Mk4, Mk5, Q).
  • Q only: QR code.

Third-party: HWI, Sparrow, Specter, Electrum.

Common issues

  • microSD format must be FAT32 (max 32 GB).
  • USB driver issues on some Linux distros.
  • NFC on iPhone limited to read-only — use Android for tap-to-sign.

See also

Discovery
Tags

No tags published for this skill.

Version
Latest version metadata

Version

v2026.09.24

Published

Sep 24, 2026

Category

Uncategorized

License

MIT

Source path

skills/bitcoin/hardware/coldcard

Default branch

main

Latest commit

9496306

Tree SHA

fe4e2f1