Coldcard now requires 65 key presses after seed exploit, while exposed funds still must move

fiverr
Bybit


Coinkite, the maker of the Coldcard Bitcoin hardware wallet, released new standard firmware on Aug. 20 that forces users to add physical randomness whenever they generate a seed.

Owners who generate a seed after installing the current fixed release can use the hardened process. Owners still relying on a seed produced by affected firmware must generate another seed and transfer the funds unless that wallet meets the dice-roll exception.

During standard seed creation, every seed combines fresh device entropy with one required human input source: at least 65 key presses made at unpredictable intervals, 50 rolls of a physical six-sided die, or 128 physical coin flips. The requirement reduces reliance on the wallet’s random-number generator alone.

Coldcard’s current security status recommends version 5.6.1 for Mk4 and Mk5 devices and 1.5.1Q for Q devices. The advisory’s exposure list is wider and track-specific. Coinkite’s official migration guidance covers Mk2 and Mk3 firmware 4.0.1 through 4.1.9; Mk4 and Mk5 standard firmware before 5.6.0 and Edge firmware before 6.6.0X; and Q standard firmware before 1.5.0Q and Edge firmware before 6.6.0QX.

coinbase

Block’s independent technical analysis uses a broader Mk2 and Mk3 boundary that includes version 4.0.0. Owners of that release should not treat the vendor boundary as proof of safety.

Related Reading

A flaw in Coldcard seed generation lets attackers recreate private keys from the press of a button

Installing fixed firmware does not change an old seed. Unless the advisory’s dice exception applies, Coinkite’s migration guide tells affected users to generate a genuinely new seed, verify its backup and wallet fingerprint, confirm a receiving address on the device, send a small test transaction, and then transfer every balance tied to the old seed. Cloning or restoring the wallet does not create a new seed.