Key Highlights
- Coinkite released firmware 5.6.1 for Mk4/Mk5 and 1.5.1Q for COLDCARD Q following the seed-generation failure disclosed in July.
- The update adds user-supplied entropy, stronger transaction checks, and tighter controls around USB data and wallet backups.
- Users with seeds generated on potentially affected firmware from 2021 through July 2026 still need to create new seeds and move their funds.
A Canadian Bitcoin hardware company, Coinkite, has released a firmware update for COLDCARD hardware wallets following a seed-generation failure linked to a series of Bitcoin thefts.
According to the company’s August 20 security update, the release goes beyond addressing the original randomness issue. It introduces changes to seed creation, transaction signing, USB handling, firmware validation, wallet backups, and other security functions.
The release follows several weeks of technical review involving Coinkite, security researchers, and blockchain analysts who examined the circumstances surrounding the thefts.
Seed generation gets new requirements
The original incident involved a randomness problem that could result in predictable wallet seeds. Because seeds are used to derive private keys, attackers could potentially reconstruct affected wallets without obtaining the physical COLDCARD devices.
Earlier reports estimated losses at around $88 million, while later investigations placed the broader amount associated with the theft at roughly $112 million.
The latest firmware changes how new seeds are generated. Users must now provide at least one form of physical or user-generated entropy, including:
- 65 key presses with unpredictable timing
- 50 physical dice rolls
- 128 physical coin flips
The device combines this input with internal entropy from SE1, SE2, and its hardware TRNG. Coinkite has also replaced its previous backup pseudorandom generator, Yasmarang, with SHA-256 Hash_DRBG. For the separate Dice Rolls Only option, the firmware requires 50 rolls for a 12-word seed or 99 rolls for a 24-word seed.
Updating firmware is not enough for old seeds
The new release does not make previously generated seeds safe. Coinkite said users whose seeds may have been generated on affected firmware between 2021 and July 2026 should create a new seed using fixed firmware and move their funds.
This is separate from installing the latest software. Since the original problem occurred during seed creation, updating the device afterward cannot change the security of a seed that was already generated.
The July 31 firmware fixed the seed-generation failure for newly created wallets. The August 20 release provides additional changes and security checks for users completing the migration.
COLDCARD adds transaction verification
The firmware also introduces another check before a transaction is signed.
COLDCARD now re-verifies a staged PSBT immediately before signing. If a connected computer modifies the transaction after it has been reviewed on the device, signing is stopped, and the device displays “Transaction modified.”
The update also blocks SIGHASH_SINGLE and SIGHASH_SINGLE|ANYONECANPAY by default because certain outputs can remain modifiable under those signing modes.
Advanced users can change the setting to issue a warning instead.
USB and wallet backup controls tightened
Several changes target the way COLDCARD handles data exchanged with connected devices. USB downloads are now limited to the latest result produced by the device and require an encrypted session. New uploads, transactions, or sessions can invalidate previous downloads.
The firmware also adds additional checks around wallet backups, multisig enrollment, PSBT uploads, and wallet restoration. For passphrase wallets, backup behavior has also been changed so that the active wallet is captured rather than simply preserving the underlying parent seed.
Delta mode and hardware RNG receive changes
The update restricts several seed-related functions while the device is operating in Delta Mode, including Seed XOR, Key Teleport, CCC Key C import, and BIP-85.
Coinkite has also added checks around the hardware random-number generator. The firmware now checks for specific RNG error states, output readiness, and zero-word conditions, with the device stopping when certain faults are detected.
A boot-time check has also been added to verify that the RNG function reaches the intended hardware read path.
Coinkite stressed that these tests are designed to identify specific failure conditions and do not independently prove the quality of every random output.
Investigation into the Bitcoin theft continues
The firmware release comes while the investigation into the stolen Bitcoin remains ongoing.
Earlier reporting linked Block’s engineering team and Galaxy Research to efforts to analyze the stolen funds and provide information to law enforcement.
Coinkite said authorities are continuing to investigate the thefts and work to identify those responsible. The company also credited external researchers who identified additional issues during the review, including problems involving staged PSBT transactions and Seed XOR.
COLDCARD incident adds to Bitcoin custody debate
The incident has also renewed discussion over the risks and responsibilities of Bitcoin self-custody.
Bitcoin analyst Willy Woo previously argued that users should continue to prioritize controlling their own private keys as institutional products and spot Bitcoin ETFs expand access to Bitcoin through custodians.
The COLDCARD case highlights a different risk within self-custody: users can control their keys directly while still depending on the security of the hardware and software used to generate and protect them.
In this case, physical access to the device was not required for the affected wallets to be compromised because the weakness occurred during seed generation.
What affected COLDCARD users should do
COLDCARD users should install the appropriate firmware and verify that the device reports 5.6.1 for Mk4/Mk5 or 1.5.1Q for Q.
For users whose seeds may have been generated during the affected period, however, the more important step is to create a new seed and migrate funds.
Coinkite has also launched a new COLDCARD Security Status page containing firmware information, migration guidance, and updates related to the incident.
The latest release strengthens several parts of the device’s security architecture, but it does not change the central migration requirement for potentially affected wallets: an old seed cannot be secured retroactively by installing new firmware.
Also Read: HTX Revamps Withdrawal System as Wallet Scrutiny Grows
