- Coinkite released firmware 5.6.1 for Coldcard Mk4/Mk5 and 1.5.1Q for Coldcard Q, requiring user-supplied entropy for seed generation
- New seeds must include at least 65 keypresses, 50 dice rolls, or 128 coin flips combined with device randomness
- Existing seed phrases remain vulnerable even after upgrading and must be replaced before migrating funds
- Confirmed losses from the Coldcard exploit reached 1,778 BTC (~$112 million), making it the third-largest crypto exploit of 2026
- Coinspect launched Unlukey, a free tool for identifying wallet addresses generated from weak seed phrases
Coinkite announced firmware 5.6.1 for Coldcard Mk4 and Mk5 devices and 1.5.1Q for the Coldcard Q on Thursday, requiring user-supplied entropy mixed with improved device randomness for seed generation. The release mandates that newly generated seeds include at least 65 keypresses with unpredictable timing, 50 rolls of a six-sided die, or 128 coin flips.
That user input is combined with randomness from multiple device sources, including secure elements and the hardware random-number generator. The combined randomness creates the wallet’s seed phrase and keeps private keys unpredictable even if one entropy source fails.
Coinkite urged users to upgrade immediately, emphasizing that existing seed phrases remain vulnerable and must be replaced with new seeds before migrating funds. Confirmed losses from the Coldcard exploit reached 1,778 Bitcoin (BTC), worth about $112 million, according to an Aug. 14 report by Galaxy Research.
This makes the Coldcard hack the third-largest cryptocurrency exploit of 2026, according to data aggregated by DefiLlama. The company’s July 31 firmware update had already fixed the seed-generation failure for newly created wallets.
Thursday’s release follows three weeks of broader security review and adds safeguards around USB data handling, transaction signing, and hardware randomness. Coinkite said the update addresses a theoretical attack involving a compromised computer USB port by re-verifying transactions immediately before signing.
The firmware also introduces additional hardware RNG checks and a boot-time test designed to verify the wallet uses its intended hardware path. Other changes restrict USB downloads to the device’s most recent output and require an encrypted session, while certain Bitcoin signature hash modes that allow transaction outputs to remain modifiable are now blocked by default.
Blockchain security company Coinspect revealed Unlukey, a free public tool for identifying wallet addresses generated from weak seed phrases. The first iteration aims to reproduce known weak seed generation and check whether public addresses belong to the affected dataset, Coinspect said in a Friday X post.
Weak seed phrase generation was a main vulnerability that led to the Coldcard exploit. TRM Labs said that a firmware bug from March 2021 weakened seed randomness on some Coldcard wallets, reducing key strength from 128 bits to 40 bits and making them brute-forceable without physical access.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
