- Coinkite released firmware 5.6.1 and 1.5.1Q after a seed-generation flaw enabled approximately $130 million in Bitcoin thefts from Coldcard wallets.
- The update now requires users to add physical randomness through key presses, dice rolls, or coin flips when generating new wallet seeds.
- A three-week security review also patched vulnerabilities involving transaction signing, USB data handling, and wallet backups.
Coinkite has released a critical firmware update for its Coldcard hardware wallets after a seed-generation flaw allowed attackers to steal approximately $130 million in Bitcoin from affected devices, according to a blog post on Thursday. The vulnerability, which dated back to 2021, reduced wallet seed entropy from 128 bits to roughly 40 bits, making private keys easier for attackers to guess without physical access to the device.
Coinkite urged Coldcard Mk4, Mk5, and Q users to upgrade to firmware 5.6.1 or 1.5.1Q following a three-week review that involved outside security researchers and AI models. Attackers began draining wallets in July, with Galaxy Research tracking approximately $112 million stolen across 4,585 addresses by mid-August.
The company suggested attackers may have used AI to examine older versions of its open-source firmware and uncover the flaw. The updated firmware now requires users to add randomness when generating a wallet seed using at least 65 key presses, 50 dice rolls, or 128 coin flips, which the device combines with its own randomness.
Coinkite also replaced its Yasmarang backup pseudo-random number generator with SHA-256 Hash_DRBG and added checks to catch hardware random number generator failures. The hardware wallet now checks a partially signed Bitcoin transaction immediately before signing, stopping the process if the transaction has changed.
Ledger CTO Charles Guillemet told Decrypt: “We’re treating this as a serious reminder of how the whole security model of a hardware wallet lives or dies on randomness.” Users who generated seeds on affected versions between 2021 and July 2026 must create a new seed using updated firmware and move their Bitcoin.
The company said law enforcement authorities continue investigating the thefts and that it remains committed to supporting affected customers.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
