What to know:
- Coinkite urges Coldcard users to replace old seed phrases after the new security update.
- New seeds now require entropy from keypresses, dice rolls, or coin flips for protection.
- Total losses linked to the Coldcard exploit reached 1,778 BTC, worth about $112 million.

Coinkite has issued a new Coldcard firmware update to improve seed phrase security. However, the company warned that earlier vulnerable seeds remain unsafe and must be replaced by affected users.
Coinkite announced firmware 5.6.1 for Coldcard Mk4 and Mk5 in a Thursday blog post. It also released version 1.5.1Q for Coldcard Q.
The Coldcard firmware update requires user entropy when generating a seed phrase. Owners must provide it through keypresses, dice rolls, or coin flips.
Also Read: MANTRA Chain Stops Transactions Amid Investigation Into Network Incident
What Must Users Do After the Coldcard Firmware Update?
Users can make at least 65 keypresses with unpredictable timing. Alternatively, they can roll a six-sided die 50 times or flip a coin 128 times.
The device mixes this input with randomness from secure elements and its hardware random-number generator. This keeps private keys unpredictable if one entropy source fails.
Coinkite urged owners to install the Coldcard firmware update immediately. It protects future seeds but cannot repair phrases already generated by the earlier flawed process.
Affected users must generate fresh credentials on updated devices before transferring Bitcoin. Using a vulnerable phrase may leave the linked wallet exposed.
Galaxy Research said confirmed losses reached 1,778 Bitcoin (BTC) by Aug. 14. Its report valued assets from the Coldcard exploit at $112 million.
DefiLlama ranked the incident as the third-largest cryptocurrency exploit of 2026. The seed weakness made affected wallets brute-forceable without physical access to the devices.
How Does Coldcard Improve Wallet Security?
Coinkite fixed the seed-generation failure for new wallets in its July 31 release. The Coldcard firmware update followed three weeks of security reviews.
The review produced safeguards for USB data handling, transaction signing, and hardware randomness. The changes cover risks beyond the original seed-generation failure.
The device now verifies transaction details again immediately before signing. Coinkite said this addresses a theoretical attack involving a compromised computer USB port.
This version comes with random number generator tests and one test that runs once the wallet powers up. This helps confirm that the intended hardware path is being used.
With the Coldcard firmware update, all USB downloads will be limited to the device’s most current output. All transfers have to use encrypted sessions.
The software disables certain Bitcoin signature-hash types. These modes make the transaction outputs susceptible to changes while being signed.
Why Are Some Coldcard Wallets Brute-Forceable?
Firms that specialize in security are developing a tool to identify wallets that become vulnerable through weak seed generation processes. For instance, Coinspect released Unlukey, a free public tool.
Coinspect said that the tool simulates the weak seed generation techniques. It then identifies whether the public wallet addresses belong to that dataset.
TRM Labs linked this vulnerability to a bug found in the March 2021 firmware. This bug reduces the entropy in certain Coldcard wallets from 128 bits to 40 bits.
This made the keys susceptible to brute force attacks. TRM Labs revealed that the attack does not require physical access to the device.
Also Read: Upbit Listings Send ETHGas Higher as GWEI Leads Four New Token Additions





Be the first to comment