Coldcard Overhauls Wallet Security After Bitcoin Hack
Coldcard maker Coinkite has released a broad security update for its Bitcoin hardware wallets after reports connected a seed-generation flaw to more than $100 million in thefts. The company is urging Mk4, Mk5 and Q users to upgrade to firmware 5.6.1 or 1.5.1Q.
The vulnerability affected seed generation in certain firmware released between 2021 and July 2026, potentially producing seeds with insufficient randomness. Attackers could reconstruct vulnerable private keys without gaining physical access to the hardware devices.
New Seeds Require User-Generated Randomness
Coldcard’s updated seed-generation process now requires users to contribute their own randomness alongside entropy generated by the device. Users must provide at least 65 key presses with unpredictable timing, 50 rolls of a physical six-sided die or 128 coin flips.
The company also replaced its Yasmarang backup pseudo-random number generator with SHA-256 Hash_DRBG and added checks designed to detect failures in the hardware random number generator. These changes followed a three-week security review covering areas beyond the original seed-generation flaw. Coinkite said:
“Their work put this firmware under intense, sustained scrutiny and made this release stronger.”
Update Adds Transaction and USB Protections
The new firmware also changes how Coldcard handles transaction signing, USB data, firmware validation, Delta Mode and wallet backups. Coldcard now rechecks a partially signed Bitcoin transaction immediately before signing and stops the process if the transaction has changed since the user reviewed it.
USB downloads are now limited to results generated during the current encrypted session. Coinkite also added additional checks around firmware updates and tightened access to seed-related functions when using Delta Mode.
Existing Vulnerable Seeds Still Require Migration
Installing the latest firmware does not repair a seed that was generated using affected software. Coinkite says users whose seeds may have been created on vulnerable firmware between 2021 and July 2026 must generate a new seed using fixed firmware and transfer their Bitcoin.
The investigation into the thefts remains ongoing. Coinkite said law enforcement authorities are working to identify those responsible while the company continues assisting affected customers with wallet migration.