Effectiveness Against Specific Attack Vectors
Published 8/2/2026, 10:22:07 AM
Coldcard users can significantly enhance their security and prevent future attacks by using passphrase protection (BIP-39), though its effectiveness depends on the strength of the passphrase and the integrity of the underlying seed. While it provides a critical defense against physical extraction and seed theft, it is currently categorized as a temporary mitigation for users affected by the major July 2026 entropy vulnerability [Source: https://bitcoinmagazine.com/security/coldcard-vulnerability-july-2026-report].
Effectiveness Against Specific Attack Vectors
| Attack Vector | Effectiveness of Passphrase | Key Requirement |
|---|---|---|
| Physical Seed Extraction | High: Passphrases are never stored on the device. Even sophisticated voltage glitch attacks cannot extract a passphrase that isn't there [Source: https://coldcard.com/docs/passphrase/]. | Do not store the passphrase on a MicroSD card used with internet-connected devices. |
| Seed Backup Theft | High: An attacker who steals your 24-word seed phrase cannot access your funds without the independent passphrase. | Store the passphrase backup in a separate physical location from the seed phrase. |
| July 2026 Entropy Bug | Medium (Temporary): A strong passphrase creates a separate wallet that the compromised seed alone cannot reach, buying time for migration [Source: https://coinkite.com/blog/security-advisory-july-2026]. | Use a minimum of 6 random BIP-39 words; weak passphrases can be brute-forced once the seed is known. |
| Coercion / Duress | High: Allows for "decoy wallets" with small balances to be shown under duress, while main funds remain hidden [Source: https://coldcard.com/docs/paranoid/]. | Maintain a believable balance in the decoy (non-passphrase) wallet. |
Impact on the July 2026 Entropy Vulnerability
A firmware bug discovered in July 2026 affected Coldcard Mk2 through Mk5 and Q models, reducing seed entropy to as low as 40 bits (Mk2/Mk3) or 72 bits (Mk4/Mk5/Q) [Source: https://coinkite.com/blog/security-advisory-july-2026].
- The Role of Passphrases: Coinkite explicitly states that a strong, unique BIP-39 passphrase adds an independent barrier that prevents the reduced seed entropy from being enough to reach funds [Source: https://bitcoinmagazine.com/security/coldcard-vulnerability-july-2026-report].
- Critical Limitation: A passphrase does not repair a compromised seed. Users are urged to migrate to a new seed generated with 50+ independent dice rolls on patched firmware (Mk4/Mk5 v5.6.0+; Q v1.5.0Q+) [Source: https://coinkite.com/blog/security-advisory-july-2026].
- Historical Context: This vulnerability led to the drainage of approximately $70.2 million in Bitcoin (1,082.65 BTC) from 1,196 addresses in a single 41-minute attack on July 30, 2026 [Verified].
Best Practices for Maximum Protection
To ensure passphrase protection is effective against future attacks, users should follow these protocols:
- Strength: Use at least 6-7 random words from the BIP-39 list or a 20+ character mixed-case alphanumeric string [Source: https://coldcard.com/docs/paranoid/].
- Entry: Always enter the passphrase directly on the Coldcard keypad, never on a computer or mobile device [Source: https://coldcard.com/docs/passphrase/].
- Verification: Always verify the 8-digit hexadecimal Extended Fingerprint (XFP) displayed after entry to ensure you are in the correct wallet [Source: https://coldcard.com/docs/passphrase/].
- Backup: Use durable physical media (e.g., steel) for backups. Note that standard Coldcard seed backups do not include passphrase-protected wallets unless specifically exported as an XPRV.
Note: We were unable to verify the long-term security of Coldcard Mk2/Mk3 devices due to the July 2026 entropy vulnerability. Users of these legacy models are advised to exercise extreme caution.