Market desk Bitcoin Ethereum Altcoins DeFi Stablecoins Markets & Trading

Coldcard Updates Firmware After Seed Exploit, Requiring New Physical Randomness Steps

Coinkite has released new firmware for Coldcard Bitcoin hardware wallets following a seed exploit, forcing users to incorporate physical randomness for newly generated seeds while existing exposed seeds require migration.
2 weeks ago 36 views
Coldcard Updates Firmware After Seed Exploit, Requiring New Physical Randomness Steps

Coinkite, the maker of the Coldcard Bitcoin hardware wallet, released new standard firmware on Aug. 20 that requires users to add physical randomness when generating new seeds. The update follows a seed exploit and applies to version 5.6.1 for Mk4 and Mk5 devices, and version 1.5.1Q for Q devices.

Under the updated process, standard seed creation combines device entropy with at least one required human input source: 65 key presses made at unpredictable intervals, 50 rolls of a physical six-sided die, or 128 physical coin flips. This requirement reduces reliance on the hardware wallet's random-number generator alone. Coinkite also maintains an advanced Dice Rolls Only mode, which excludes hardware randomness and requires 50 rolls for a 12-word seed or 99 rolls for a 24-word seed.

Installing the fixed firmware does not repair seeds created on affected releases. Coinkite's official migration guidance advises affected users to generate a genuinely new seed, verify its backup and wallet fingerprint, confirm a receiving address on the device, send a small test transaction, and transfer all balances tied to the old seed. Simply cloning or restoring the wallet does not create a new seed.

An exception applies if the user previously added at least 50 fair, independent, and private physical die rolls through the affected workflow and never recorded or exposed the sequence. Users with fewer rolls or uncertainty regarding those conditions are instructed to migrate.

Coinkite's exposure list covers multiple versions, including Mk2 and Mk3 firmware 4.0.1 through 4.1.9; Mk4 and Mk5 standard firmware before 5.6.0 and Edge firmware before 6.6.0X; and Q standard firmware before 1.5.0Q and Edge firmware before 6.6.0QX. Block's independent technical analysis uses a broader Mk2 and Mk3 boundary that includes version 4.0.0. Block traced the original defect to code that could route requests to a deterministic MicroPython fallback because a feature flag defined as zero was treated as present.

In addition to seed creation updates, the new firmware packages updates for signing and data paths. These include binding USB review to a staged PSBT checksum, rechecking transaction bytes before signing, blocking SIGHASH_SINGLE modes by default, restricting USB downloads to the current encrypted-session result, and validating firmware file length. Coinkite noted that some customers suffered severe losses and that law enforcement is investigating, though the company has not published a verified victim count or loss total.

Market snapshot

Top cryptocurrency prices

Explore all prices
Market prices will appear after the next scheduled refresh.