Coldcard strengthens seed generation with firmware update
Coldcard strengthens seed generation with a new Coinkite firmware update that forces user-supplied entropy into every new wallet seed. Users must still create fresh seed phrases and move funds, because older vulnerable seeds stay unsafe even after upgrading. Confirmed losses tied to the Coldcard exploit reached 1,778 BTC, about $112 million.
Key Takeaways
- Coinkite shipped firmware 5.6.1 for Coldcard Mk4 and Mk5 and 1.5.1Q for Coldcard Q to harden how new seeds are created.
- New seeds must mix user entropy—at least 65 unpredictable keypresses, 50 dice rolls, or 128 coin flips—with device randomness from secure elements and the hardware RNG.
- Upgrading alone does not fix old seeds; Coinkite says vulnerable phrases must be replaced before funds are migrated.
- The release also tightens USB handling, transaction signing checks, and hardware RNG verification after a broader security review.
- Galaxy Research put confirmed Coldcard-exploit losses at 1,778 BTC, about $112 million, ranking it among 2026's largest crypto hacks.
What did Coinkite change in the Coldcard update?
According to Cointelegraph, Coinkite announced the firmware in a Thursday blog post after three weeks of wider security review. A July 31 update had already fixed seed-generation failure for newly created wallets. Thursday's build goes further by requiring every newly generated seed to include user-supplied entropy mixed with improved device randomness.
That combined randomness feeds the wallet's seed phrase so private keys stay unpredictable even if one device entropy source fails. The same policy is meant to keep keys strong when hardware RNG paths degrade. For more hardware-wallet and crypto security coverage, see our Fintech & Crypto Alerts hub.
Why must Coldcard users generate new seed phrases?
Coinkite urged users to upgrade immediately, but stressed that existing vulnerable seeds remain unsafe after the security upgrade. Firmware cannot repair randomness that was missing when an older seed was created. Users who may hold affected phrases are told to generate new seeds on fixed firmware and migrate funds before relying on the wallet again.
TRM Labs said a March 2021 firmware bug weakened seed randomness on some Coldcard wallets, cutting key strength from 128 bits to 40 bits and making them brute-forceable without physical access. Weak seed generation was a core factor in the Coldcard exploit, Cointelegraph reported.
What other safeguards arrived with the firmware?
Beyond seed rules, the update adds safeguards around USB data handling, transaction signing, and hardware randomness. Coinkite said it addresses a theoretical attack via a compromised computer USB port by re-verifying transactions immediately before signing. The firmware also adds hardware RNG checks and a boot-time test to confirm the wallet uses its intended hardware path.
Other changes limit USB downloads to the device's most recent output and require an encrypted session. Certain Bitcoin signature hash modes that leave transaction outputs modifiable are blocked by default. Separately, blockchain security firm Coinspect launched Unlukey, a free tool to flag addresses tied to weak seed phrases by reproducing known weak generation patterns.