Hardware
October 2026
← Topics

Key Zero Is in the Tree

Coinkite, 23 Sep 2026: how to change Coldcard firmware, test it, and install it. A developer guide, not a fix for the August seed-generation bug.

WHAT YOU CAN BUILD
The source includes the development signing private key, key zero. You can change the Python application under shared/, native modules, or the embedded MicroPython, build a DFU, and install it without Coinkite's signature. Mk4 and Mk5 build with MK-Makefile, Q with Q1-Makefile. The factory-fixed bootloader checks the image first.
THE BOOT WARNING
Development firmware shows a warning and a forced delay on every boot, so it cannot pass as factory firmware. Only an image Coinkite signs removes the warning.
THEIR WARNING
Use a blank Coldcard that will never hold real secrets. Custom firmware can read secrets, change the screen, or sign the wrong transaction. Reinstalling official firmware does not make an exposed seed private again.
BRICKS AND FIXES
Keep a hash-checked official DFU before experimenting: a change that stops the device reaching the upgrade menu bricks that unit. For a general fix, Coinkite points at small merged pull requests such as #729, #808, and #766.

Catcard: New Code, Same Install Path

TibaneLabs/catcard, named in Coinkite's post. Coinkite calls it an independent experiment and says the mention is not an endorsement.

WHAT IT IS
Clean-room Rust firmware for Coldcard hardware: no-std, Cortex-M4F, MIT, copyright Karpeles Lab Inc. It installs as a dev-signed image on Mk3, Mk4, Mk5, and Q1, so it goes through the same key-zero path. Its README: runs on real hardware, not ready for funds.
TWO ENTROPY ESTIMATES
Catcard's README says stock firmware derived seeds from software PRNGs instead of the hardware TRNG, and estimates about 22 bits of real entropy on Mk3 and about 32 on Mk4. Coinkite's own backgrounder estimates about 40 bits on Mk2 and Mk3, and about 72 on Mk4, Mk5, and Q, where secure-element entropy is mixed in.
LICENCE
Coldcard's firmware is MIT plus the Commons Clause, which catcard's README says is not open source. That is its second stated reason to start from scratch, under MIT only.
THE SEED
Neither the guide nor catcard repairs a seed generated on affected firmware. Installing fixed firmware only helps new seeds, which is why August's session was about migrating funds.