Coldcard has pushed two security updates and warned some users they must recreate wallets and move any Bitcoin stored on affected seed phrases. What’s new - Coldcard released firmware 5.6.1 for Mk4/Mk5 devices and 1.5.1Q for Coldcard Q after a three-week review following a July 31 emergency hotfix. - The review covered the earlier seed-generation failure plus signing, device-connection, firmware-installation and random-number checks. - Coldcard acknowledges customers who suffered losses from the vulnerability and tightened the seed-creation process to require private user entropy. Who is affected - Seeds created on specific older firmware versions are vulnerable; not every Coldcard seed is impacted. - Affected ranges: - Mk2/Mk3 seeds created on firmware 4.0.1 through 4.1.9 - Mk4/Mk5 seeds created before standard 5.6.0 (or Edge 6.6.0X) - Coldcard Q seeds created before standard 1.5.0Q (or Edge 6.6.0QX) - Mk1 devices and other Coinkite products (TAPSIGNER, OPENDIME, SATSCARD) use different software and are not covered by this disclosure. What changed to make seed creation safer - Every new seed must now include at least one source of user-supplied randomness, combined with the device’s STM32 true random-number generator and two secure elements (SE1 and SE2). Options for user entropy: - At least 65 key presses with unpredictable timing, or - 50 private rolls of a fair six-sided die, or - 128 physical coin flips. - User inputs must remain private; anyone who records them could help reconstruct the seed. - The update only affects seeds generated after installing the firmware—it cannot add randomness to previously created seeds. What affected users must do 1. Update the device firmware and verify the digital signature of the update before installing. 2. Create and verify an entirely new seed using the updated entropy process. 3. Transfer funds from the old wallet to addresses controlled by the new seed. Confirm the receiving address on-device, perform a small test transfer, then move the balance. 4. Keep the old backup offline until the migration is confirmed, but do not continue using it for receiving funds. Notes and exceptions - Coldcard said wallets where owners added at least 50 fair, independent, private dice rolls before the final seed words were generated already supplied ~128 bits of entropy and are not subject to forced migration. If users cannot prove they did this, they should migrate. - Adding a BIP-39 passphrase provides an extra barrier to attackers but does not repair a weak underlying seed—Coldcard advises replacing the recovery phrase even if a passphrase was used. Technical origin and impact - The flaw dates to a March 2021 firmware change that could cause devices to fall back to a deterministic MicroPython routine for seed generation instead of using the STM32 hardware TRNG. - Block’s review estimated effective entropy at roughly 40 bits for older Mk2/Mk3 devices and about 72 bits for vulnerable Mk4/Mk5/Q devices—well below the intended 128 bits—making some seeds searchable offline. - Researchers attribute four suspected attack waves to the flaw, with an estimated ~1,816 BTC taken from more than 5,200 addresses (loss estimates vary as investigations continue). - Blockchain analytics firm Galaxy Research shared suspected attacker addresses with exchanges and US law enforcement; as of early August, about 90% of Bitcoin moved during confirmed attack waves remained in identified destination wallets. Other firmware improvements - Staged verification of partially signed Bitcoin transactions (PSBTs) immediately before signing. - Changed default SIGHASH handling to alter what parts of a transaction a signature covers. - Hardening of USB boundaries and firmware-update checks, improved isolation in Delta Mode, fixes for backup behavior, and additional checks around RNG initialization and faults. Why this matters - The incident underscores the critical role of true randomness in seed generation and the risk of weak seeds: attackers who can derive likely seeds can compute addresses and drain funds without physical access, PINs, or network attacks. - Some users responded by moving funds to exchanges or other custodians; this shifts counterparty risk to third parties and has coincided with elevated exchange inflows. Bottom line If your Coldcard seed was created on a firmware listed as vulnerable, update your device now, generate a new seed using the updated entropy process, and migrate your Bitcoin following Coldcard’s recommended verification steps. Verify firmware signatures before installing updates, and keep migration backups until you confirm success. Read more AI-generated news on: undefined/news