Coldcard has pushed two security-focused firmware updates and warned that some users must generate new wallets and move their Bitcoin to stay safe. What changed - Coldcard released firmware 5.6.1 for Mk4/Mk5 and 1.5.1Q for Coldcard Q after a three-week security review following an emergency July 31 hotfix. - The review re-examined the earlier seed-generation bug and also audited transaction signing, device connections, firmware installation, and random-number handling. - Coldcard publicly acknowledged customers who lost funds to the seed-generation attack. Why some users need to migrate - The updated firmware changes how new seed phrases are created: every newly generated seed now requires at least one source of user-provided entropy (private input from the owner). - Acceptable user entropy options: - At least 65 key presses with unpredictable timing - 50 private rolls of a fair six-sided die - 128 physical coin flips - The device mixes that user input with fresh data from the STM32 true random-number generator and two secure elements (SE1 and SE2). Using multiple entropy sources reduces dependence on any single component. Important: this only affects seeds generated before the fix - The firmware cannot add entropy retroactively. If a seed was generated under an affected firmware version, it remains vulnerable even after updating the device. - Affected users must: 1. Install the new firmware and verify its digital signature. 2. Create and verify an entirely new seed on the device (using the required user entropy). 3. Transfer Bitcoin from the old wallet to addresses controlled by the new wallet (confirm the receiving address on-device and do a small test transfer first). 4. Keep the old backup offline until the migration is confirmed, but do not continue to use the old seed to receive funds. - Importing the old seed into updated Coldcard firmware, another hardware wallet, or a software wallet does not fix the underlying weakness. Which seeds are affected - Mk2 and Mk3: seeds generated on firmware versions 4.0.1 through 4.1.9. - Mk4 and Mk5: seeds generated before standard firmware 5.6.0 or Edge firmware 6.6.0X. - Coldcard Q: seeds created before standard 1.5.0Q or Edge 6.6.0QX. - Mk1 devices are outside the regression. Other Coinkite products (TAPSIGNER, OPENDIME, SATSCARD) run different software and are not affected. Exceptions and mitigations - Coldcard previously noted an exception for users who added at least 50 private, fair dice rolls before finalizing their seed; those rolls provide ~128 bits of independent randomness. If you don’t remember the rolls, used fewer than 50, or exposed them, you should migrate. - A BIP-39 passphrase adds a protective layer but does not repair a weak seed itself; owners with affected seeds were told to replace the recovery phrase even if they used a strong passphrase. Other firmware changes - Staged verification of partially signed Bitcoin transactions (PSBTs) immediately before signing. - Default SIGHASH behavior changed (affects which parts of a transaction a signature covers). - Stronger isolation around USB connections and firmware updates, improved Delta Mode isolation, fixes for backups involving the active wallet, and extra checks for RNG initialization and faults. - Coldcard instructs users to verify firmware signatures before installing updates. Root cause and impact - The regression traces back to a March 2021 firmware change that could fall back to a deterministic MicroPython routine instead of using the STM32 hardware TRNG when creating seeds. - Block’s security review estimated effective entropy around 40 bits for older Mk2/Mk3 devices and about 72 bits for vulnerable Mk4/Mk5/Q devices — well under the intended ~128 bits. That reduction made seeds feasible to search offline. - Researchers have linked the flaw to suspected attacker waves that drained roughly 1,816 BTC from more than 5,200 addresses, though estimates have varied as teams verified victim reports. - The incident drove some Bitcoin holders to move funds to exchanges; OKX reported record inflows following the attacks. Galaxy Research shared suspected attacker addresses with exchanges, investigators, and US federal law enforcement, and said about 90% of the Bitcoin taken during confirmed waves remained unmoved in identified destination wallets. What users should do now - If your seed was created on an affected firmware version, update Coldcard, verify the firmware signature, create a fresh seed using the new entropy requirements, verify the on-device receiving address, then move your funds (start with a small test transfer). - Keep the old backup but do not rely on it to receive funds. - If unsure whether your seed is affected, check Coldcard’s published affected-version ranges or consult support/documentation before making decisions. Bottom line: Coldcard’s fixes strengthen seed creation and transaction checks, but for anyone with an affected seed the only secure remedy is to generate a new wallet (with user entropy) and move the Bitcoin off the old recovery phrase. Read more AI-generated news on: undefined/news
