Coldcard Releases Firmware 5.6.1, Urges Affected Users to Move Their Bitcoin
Key Takeaways
- •Coldcard released firmware 5.6.1 in response to a specific security issue rather than as routine maintenance.
- •The warning centers on the older Coldcard Mk3 model and applies to a subset of affected users.
- •Coldcard told affected users to move their Bitcoin because a firmware update cannot repair the randomness used in an existing seed.
- •The company advises users to install firmware only through its official upgrade documentation and verify updates through official channels.
- •The incident highlights the importance of firmware trust and device integrity for Bitcoin self-custody users.

Coldcard has released firmware 5.6.1 and is urging affected users to move their Bitcoin, tying the update to a specific security issue rather than a routine maintenance release. The rollout is paired with a direct warning to device owners.
What Coldcard changed in firmware 5.6.1
The release is framed as a risk-mitigation step rather than a standard changelog update. Coldcard is a Bitcoin-only hardware wallet line built by Coinkite, and the Mk3 at the center of the warning is an older model in that series, context that helps explain why the advisory is directed at a subset of devices rather than every owner. Coinkite published guidance connecting the update to a seed-generation issue in its Mk3 seed generation warning.
Users can apply the update through the official Coldcard upgrade documentation, which walks through the firmware installation process for the hardware wallet. Coldcard devices cryptographically verify the signature on firmware before installing it, which is one reason updates should be sourced only from the vendor's official channels.
Which users are affected, and why Coldcard says to move Bitcoin
The company has told affected users to move their Bitcoin, signaling that it identified a subset of holders facing elevated risk rather than issuing a blanket advisory to all owners. The guidance mirrors earlier reporting on how Coldcard warned Mk3 users to move funds during a drain investigation that tracked roughly 594 BTC.
The instruction to relocate funds reflects the reasoning that affected devices may not be able to guarantee the integrity of keys already generated on them. A firmware patch cannot retroactively change the randomness that went into a seed at the moment it was created, so the remediation centers on moving funds to a wallet generated fresh on an updated, unaffected device rather than on the update alone. Reporting on the active wallet exploit noted that Coldcard urged users to move Bitcoin while the situation remained ongoing.
What this means for Bitcoin self-custody users
For self-custody holders, the episode underscores why firmware trust and device integrity are central to keeping keys safe, since a compromised generation process can undermine an otherwise secure setup. Analysis of the incident by TRM Labs, which described the case as the largest hardware wallet exploit of 2026 with losses it put at roughly $116 million, provided a detailed account of the incident.
When a hardware wallet vendor issues a warning to move funds, the practical response is to treat the advisory as time-sensitive and to verify guidance against the vendor's official channels before acting. Coldcard maintains an official security status page for users tracking the situation as it develops.
The broader takeaway is a reminder that operational caution matters for Bitcoin storage: readers weighing their own approach can look at how figures like David Schwartz have structured cold storage plans to manage similar custody risk.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.