COLDCARD drama just leveled up — this isn't just a hotfix anymore, it's a full security overhaul.

Coinkite dropped firmware 5.6.1 (Mk4/Mk5) + 1.5.1Q (Q) on Aug 20. Here's what changed:

🔴 USER ENTROPY NOW MANDATORY
You can't generate a new seed using device RNG alone anymore. Pick one:
- 65+ unpredictable keypresses
- 50 dice rolls
- 128 coin flips
Device still mixes STM32 hardware RNG + 2 Secure Element sources, but now YOU must add your own randomness. This is a massive policy shift — dice entropy used to be optional for power users, now it's baseline.

🔴 NEW VULN PATCHED: USB PSBT TAMPERING
Turns out there was a separate attack vector nobody talked about publicly before: after you review a PSBT on-screen but before signing, a malicious USB host could swap the transaction. New firmware now re-validates the PSBT right before signing. If it detects any change post-review, signing aborts. This is NOT the weak RNG issue — it's a different attack surface.

🔴 OLD SEEDS STILL UNSAFE
Upgrading firmware does NOT magically fix wallets generated with weak entropy. If your seed was created before the patch, you MUST regenerate + migrate funds.

Coinkite ran a 3-week deep audit covering RNG, PSBT handling, USB data flow, firmware update verification, Delta Mode, and backup processes. They publicly thanked external researchers + Karma-X for audit work. New Security Status page is live for tracking fixes and migration guides.

📊 INCIDENT STATUS (No new changes):
- Galaxy's last confirmed tally: 1,778.84 $BTC stolen
- ~1,531 $BTC still sitting in attacker wallets
- ~246 $BTC moved, 65% into CoinJoin
- No new attack waves confirmed after Aug 6
- No arrests, no official attribution, no exchange seizures yet
- Mk3 still ~40-bit entropy, Mk4/Mk5/Q ~72-bit (no new independent reproduction to change this)

Bottom line: Coinkite is no longer trusting its own hardware RNG alone for new seeds. That's the real headline. If you're still using an old COLDCARD seed generated before this mess, stop procrastinating and migrate.