Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Binance Account Rental Scam: How Fraudsters Lure Crypto Users with Promises of Easy Money
    Binance Account Rental Scam: How Fraudsters Lure Crypto Users with Promises of Easy Money
    80% of Major SpaceX Investors Deal With Crypto
    80% of Major SpaceX Investors Deal With Crypto
    SEC Cancels Crypto Meeting Why Rulemaking Just Hit Another Wall
    SEC Cancels Crypto Meeting: Why Rulemaking Just Hit Another Wall
    Internet Computer (ICP) Tops Blockchain Transactions Chart: Here’s What It's Actually Doing
    Internet Computer (ICP) Tops Blockchain Transactions Chart: Here’s What It’s Actually Doing
    Ethereum’s Staking War Why EIP-8361 Has DeFi Leaders Fighting Back
    Ethereum’s Staking War: Why EIP-8361 Has DeFi Leaders Fighting Back
  • Opinion
    OpinionShow More
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
  • Learn
    • Explained
    • How To
    • Insights
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Industry

Coinkite Updates COLDCARD After Seed Flaw Exposed Bitcoin Wallets

Coinkite’s latest firmware adds new entropy requirements and security checks, while users with potentially affected seeds still need to migrate their funds.

Written By Isha Chavda
Edited by Shubham Soni
Published 14 minutes ago·Updated 2 minutes ago
Make The Crypto Times preferred on GoogleGoogle
Coinkite Updates COLDCARD After Seed Flaw Exposed Bitcoin Wallets

Key Highlights

  • Coinkite released firmware 5.6.1 for Mk4/Mk5 and 1.5.1Q for COLDCARD Q following the seed-generation failure disclosed in July.
  • The update adds user-supplied entropy, stronger transaction checks, and tighter controls around USB data and wallet backups.
  • Users with seeds generated on potentially affected firmware from 2021 through July 2026 still need to create new seeds and move their funds.

A Canadian Bitcoin hardware company, Coinkite, has released a firmware update for COLDCARD hardware wallets following a seed-generation failure linked to a series of Bitcoin thefts.

According to the company’s August 20 security update, the release goes beyond addressing the original randomness issue. It introduces changes to seed creation, transaction signing, USB handling, firmware validation, wallet backups, and other security functions.

🚨 New COLDCARD firmware is available: 5.6.1 for Mk4/Mk5 and 1.5.1Q for Q.

This release follows three weeks of sustained review since our July 31 hotfix. We continue to acknowledge the customers who suffered severe financial losses from the seed-generation attack.

Every newly… pic.twitter.com/zmrEwh58eI

— COLDCARD (@COLDCARDwallet) August 20, 2026

The release follows several weeks of technical review involving Coinkite, security researchers, and blockchain analysts who examined the circumstances surrounding the thefts.

Seed generation gets new requirements

The original incident involved a randomness problem that could result in predictable wallet seeds. Because seeds are used to derive private keys, attackers could potentially reconstruct affected wallets without obtaining the physical COLDCARD devices.

Earlier reports estimated losses at around $88 million, while later investigations placed the broader amount associated with the theft at roughly $112 million.

The latest firmware changes how new seeds are generated. Users must now provide at least one form of physical or user-generated entropy, including:

  • 65 key presses with unpredictable timing
  • 50 physical dice rolls
  • 128 physical coin flips

The device combines this input with internal entropy from SE1, SE2, and its hardware TRNG. Coinkite has also replaced its previous backup pseudorandom generator, Yasmarang, with SHA-256 Hash_DRBG. For the separate Dice Rolls Only option, the firmware requires 50 rolls for a 12-word seed or 99 rolls for a 24-word seed.

Updating firmware is not enough for old seeds

The new release does not make previously generated seeds safe. Coinkite said users whose seeds may have been generated on affected firmware between 2021 and July 2026 should create a new seed using fixed firmware and move their funds.

This is separate from installing the latest software. Since the original problem occurred during seed creation, updating the device afterward cannot change the security of a seed that was already generated.

The July 31 firmware fixed the seed-generation failure for newly created wallets. The August 20 release provides additional changes and security checks for users completing the migration.

COLDCARD adds transaction verification

The firmware also introduces another check before a transaction is signed.

COLDCARD now re-verifies a staged PSBT immediately before signing. If a connected computer modifies the transaction after it has been reviewed on the device, signing is stopped, and the device displays “Transaction modified.”

The update also blocks SIGHASH_SINGLE and SIGHASH_SINGLE|ANYONECANPAY by default because certain outputs can remain modifiable under those signing modes.

Advanced users can change the setting to issue a warning instead.

USB and wallet backup controls tightened

Several changes target the way COLDCARD handles data exchanged with connected devices. USB downloads are now limited to the latest result produced by the device and require an encrypted session. New uploads, transactions, or sessions can invalidate previous downloads.

The firmware also adds additional checks around wallet backups, multisig enrollment, PSBT uploads, and wallet restoration. For passphrase wallets, backup behavior has also been changed so that the active wallet is captured rather than simply preserving the underlying parent seed.

Delta mode and hardware RNG receive changes

The update restricts several seed-related functions while the device is operating in Delta Mode, including Seed XOR, Key Teleport, CCC Key C import, and BIP-85.

Coinkite has also added checks around the hardware random-number generator. The firmware now checks for specific RNG error states, output readiness, and zero-word conditions, with the device stopping when certain faults are detected.

A boot-time check has also been added to verify that the RNG function reaches the intended hardware read path.

Coinkite stressed that these tests are designed to identify specific failure conditions and do not independently prove the quality of every random output.

Investigation into the Bitcoin theft continues

The firmware release comes while the investigation into the stolen Bitcoin remains ongoing.

Earlier reporting linked Block’s engineering team and Galaxy Research to efforts to analyze the stolen funds and provide information to law enforcement.

1/ During our investigation of the Coldcard drain yesterday, we identified an unusual pattern in the sweeps. That pattern led us to a hypothesis that has since been confirmed: the operator used a paid account at a well-known blockchain-services provider to query the source… https://t.co/l5McyhhcNn

— Clay Garrett (@clay_garrett) July 31, 2026

Coinkite said authorities are continuing to investigate the thefts and work to identify those responsible. The company also credited external researchers who identified additional issues during the review, including problems involving staged PSBT transactions and Seed XOR.

COLDCARD incident adds to Bitcoin custody debate

The incident has also renewed discussion over the risks and responsibilities of Bitcoin self-custody.

Bitcoin analyst Willy Woo previously argued that users should continue to prioritize controlling their own private keys as institutional products and spot Bitcoin ETFs expand access to Bitcoin through custodians.

The COLDCARD case highlights a different risk within self-custody: users can control their keys directly while still depending on the security of the hardware and software used to generate and protect them. 

In this case, physical access to the device was not required for the affected wallets to be compromised because the weakness occurred during seed generation.

What affected COLDCARD users should do

COLDCARD users should install the appropriate firmware and verify that the device reports 5.6.1 for Mk4/Mk5 or 1.5.1Q for Q.

For users whose seeds may have been generated during the affected period, however, the more important step is to create a new seed and migrate funds.

Coinkite has also launched a new COLDCARD Security Status page containing firmware information, migration guidance, and updates related to the incident.

The latest release strengthens several parts of the device’s security architecture, but it does not change the central migration requirement for potentially affected wallets: an old seed cannot be secured retroactively by installing new firmware.

Also Read: HTX Revamps Withdrawal System as Wallet Scrutiny Grows

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

TAGGED:Bitcoin (BTC)Crypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Latest News

Stablecoins Could Become AI’s Default Payment Rail, Coinbase CEO Says
Stablecoins Could Become AI’s Default Payment Rail, Coinbase CEO Says
Digital Chamber CEO Discusses CLARITY Act After White House Meeting
Digital Chamber CEO Discusses CLARITY Act After White House Meeting
HTX Revamps Withdrawal System as Wallet Scrutiny Grows
HTX Revamps Withdrawal System as Wallet Scrutiny Grows
CFTC Readies Backup Crypto Rules as CLARITY Act Stalls
CFTC Readies Backup Crypto Rules as CLARITY Act Stalls
COIN, CRCL, ABTC, BMNR, NAKA Rise as Crypto Market Rebounds
COIN, CRCL, ABTC, BMNR, NAKA Rise as Crypto Market Rebounds

Find Us on Socials

You may also like

Ripple CEO Recalls $150M SEC Battle at CFTC Innovation Meeting

Ripple CEO Recalls $150M SEC Battle at CFTC Innovation Meeting

Bitcoin Advances Past $72K as Short Sellers Face Heavy Liquidations

Bitcoin Advances Past $72K as Short Sellers Face Heavy Liquidations

Grayscale Flags Zcash Privacy Use as AI Expands Financial Data

Grayscale Flags Zcash Privacy Use as AI Expands Financial Data

Securitize Links SECZ Shares to Solana’s Onchain Credit Markets

Securitize Links SECZ Shares to Solana’s Onchain Credit Markets

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Videos
Glossary

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information