Newsroom

Coinkite Issues Coldcard Firmware Update to Fortify Seed Generation After $112 Million Exploit

21 August, 2026   /   News   /  AI   /   Tags:  firmware, seed, coldcard, randomness, seeds

Coinkite Issues Coldcard Firmware Update to Fortify Seed Generation After $112 Million Exploit

New firmware for Coldcard Mk4, Mk5 and Q requires user entropy mixed with device randomness, while existing seeds stay exposed and must be replaced before fund transfers

Coinkite has released firmware version 5.6.1 for Coldcard Mk4 and Mk5 devices along with version 1.5.1Q for the Coldcard Q. The update overhauls seed-phrase creation by mandating user-supplied entropy combined with multiple onboard randomness sources, aiming to keep private keys unpredictable even if one source underperforms.

The company directed all Coldcard users to install the new firmware at once. It stressed that the upgrade alone does not protect seeds generated under earlier vulnerable conditions. Any seed that may have been created on affected firmware between 2021 and July 2026 must be replaced with a fresh seed produced on the updated software before funds are moved.

Mandatory User Entropy for New Seeds

Every newly generated seed now requires one of three user inputs: at least 65 key presses with unpredictable timing, 50 rolls of a physical six-sided die, or 128 coin flips. The same rule applies to Temporary Seeds and CCC Key C. Firmware then mixes this input with fresh entropy drawn from the device’s secure elements and its hardware random-number generator.

The process combines 32 bytes from an improved backup generator, 32 fresh bytes from one secure element and 8 from another, applies double SHA-256, and incorporates versioned identifiers for the chosen method. A separate advanced option allows pure dice rolls that exclude all hardware randomness, requiring 50 rolls for a 12-word seed or 99 for a 24-word seed. Holding a key no longer registers as repeated rolls.

These measures follow a July 31 hotfix that already corrected the seed-generation failure for wallets created after that date. The latest release comes after three weeks of extended review that examined the full system, not only the random-number path.

Broader Transaction and Hardware Protections

Beyond seed generation, the firmware adds several layers of defense. Coldcard now re-verifies a staged transaction immediately before signing. If a connected host alters the data after the user reviews it on the device, signing halts and the wallet displays a modification warning. This closes a theoretical risk that could arise if a computer’s USB port were compromised while the device remained connected.

Signature-hash modes that leave later outputs modifiable are blocked by default. USB downloads are restricted to the most recent result produced by the device, must occur inside an encrypted session, and are invalidated by subsequent uploads or new sessions. Firmware also performs additional hardware random-number checks at runtime and a boot-time test confirming that the intended hardware randomness path is active. If the boot check fails, the device stops before normal operation begins.

Further changes harden Delta Mode, tighten backup and clone behavior so that the currently active wallet—including any passphrase or temporary seed—is captured, and improve various input-validation and multisig checks.

Context of the Exploit and Ongoing Recovery

The update arrives against the backdrop of a major Coldcard exploit. Confirmed losses have reached 1,778 Bitcoin, valued at approximately $112 million according to an August 14 assessment. The incident ranks as the third-largest cryptocurrency exploit of 2026.

Investigators and researchers have linked the thefts to a firmware defect dating to March 2021 that reduced seed randomness strength from 128 bits to 40 bits on some devices, rendering certain keys susceptible to brute-force attacks without physical access. Law-enforcement authorities continue to investigate the thefts while Coinkite assists and monitors developments.

Coinkite has launched a public security-status page that lists fixed-release details, migration guidance and independent-validation notes. Support channels remain open for users completing migrations, though response times may be longer because of elevated volume.

Detection Tools Appear

Separately, blockchain security firm Coinspect released Unlukey, a free public tool designed to identify wallet addresses that may have been generated from weak seed phrases. The initial version attempts to reproduce known weak-generation patterns and checks whether given public addresses belong to the affected set.

Users are advised to download firmware exclusively from the official Coldcard site, verify its cryptographic signatures, install it via the MicroSD procedure, and confirm the reported version after restart. Those whose seeds fall under the earlier advisory must still complete a full seed migration; the firmware upgrade is a necessary but not sufficient step.

Associated cryptocurrencies
Disclaimer
This article was generated by AI using information from multiple industry sources. It has not been reviewed or verified by a human editor and may contain inaccuracies, omissions, or misinformation. Readers are encouraged to independently verify any information before making decisions based on its content.
This article is for informational purposes only and does not constitute financial, legal, or investment advice. Cryptocurrency and related investments involve substantial risk, and past performance does not guarantee future results.