Coldcard Firmware Update Tackles Seed Generation Flaws
Coinkite has released a crucial firmware update for its Coldcard devices to strengthen seed phrase generation and address existing security vulnerabilities. The latest firmware, version 5.6.1 for Coldcard Mk4 and Mk5 devices and 1.5.1Q for the Coldcard Q, requires user-supplied entropy through at least 65 keypresses with unpredictable timing, 50 rolls of a six-sided die or 128 coin flips to be combined with randomness from multiple device sources.
The update aims to prevent seed phrase duplication and keep private keys unpredictable even if one of the device's entropy sources fails. Coinkite emphasizes that existing seed phrases remain vulnerable and must be replaced with new seeds before migrating funds.
Confirming losses from the Coldcard exploit reached 1,778 BTC (worth around $112 million) as reported by Galaxy Research on August 14. This makes it the third-largest cryptocurrency exploit of 2026, according to DefiLlama's data aggregation.