An update is not enough. Coinkite has released new firmware for its Coldcard hardware wallets, just weeks after revealing a weakness in seed generation that allowed the theft of over $114 million in bitcoins. Versions 5.6.1 for the Coldcard Mk4 and Mk5 and 1.5.1Q for the Q model add several protections. However, users who created their wallets on vulnerable firmware must generate a new seed and transfer their funds.
The initial flaw stemmed from an integration error dating back to March 2021. When creating a seed, the firmware used the Yasmarang software generator from MicroPython instead of the hardware generator intended by Coinkite. The key generated thus had a lower level of randomness than expected, which could allow an attacker to recover it.
A first fix, released at the end of July, had corrected the generation of new seeds. The current versions further strengthen the system by requiring a source of entropy provided by the user. The user must perform at least 65 key presses at unpredictable intervals, 50 rolls of a physical die, or 128 coin flips.
The backup software generator Yasmarang is also replaced by a mechanism based on SHA-256. The firmware now combines several internal sources of randomness with the physical entropy input by the user.
Other changes concern transaction signing and USB exchanges. The Coldcard notably checks the transaction data a second time just before signing to detect any potential modification between its display and validation. Signature modes that might leave some elements modifiable are also disabled by default.
Coinkite claims to have used several artificial intelligence models to examine its entire firmware. This review has identified additional anomalies in transaction approval, USB data management, backups, and update validation.
These flaws are distinct from the initial random generation error, which has already been corrected by the versions released at the end of July. Their discovery shows the usefulness of AI in quickly scanning a large codebase, but does not guarantee the absence of vulnerabilities. Coldcard's security page also specifies that the independent checks conducted so far remain targeted and do not represent a complete audit of all firmware.
Most importantly, no software can make a seed potentially guessed or already known to an attacker secret. Wallets created with the affected versions between 2021 and July 2026 must therefore be abandoned, except for specifically documented exceptions for certain seeds strengthened by sufficient independent die rolls.
The procedure involves installing the corrected firmware, creating a new seed, verifying its backup, and then transferring bitcoins to the new addresses. In this case, the update secures future keys; only migration protects the funds associated with the old ones. The Coldcard teams are doing everything to move on -- and that is commendable -- but the incident will remain in everyone's memory for a long time.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.





























