NewsCryptoColdcard Releases Security Update, but Affected Seeds Still Need Replacing

Coldcard Releases Security Update, but Affected Seeds Still Need Replacing

Author: Coindoo·

Key Takeaways

  • The issue involved weak recovery seed generation, not remote compromise of all Coldcard devices.
  • Coldcard’s current standard releases are Mk4/Mk5 firmware 5.6.1 and Coldcard Q firmware 1.5.1Q.
  • Users with affected seeds need to create a replacement seed and move their Bitcoin to addresses derived from the new wallet.
  • Coldcard says at least 50 fair, independent and private dice rolls during seed creation can exempt a user from this specific RNG risk.
  • The company warns that fake support and fraudulent migration help may appear after the security alert.
Coldcard Releases Security Update, but Affected Seeds Still Need Replacing

Firmware fix follows seed-generation defect linked to reported Bitcoin thefts

Coinkite, the manufacturer of Coldcard hardware wallets, has released new firmware after a seed-generation defect was connected to reported Bitcoin thefts. The incident did not involve an attacker remotely unlocking every Coldcard device; it involved the way certain recovery seeds were created. The current standard releases are Mk4/Mk5 firmware 5.6.1 and Coldcard Q firmware 1.5.1Q.

Why a device update is not enough

During a 2021 code migration, seed generation reached a software pseudo-random-number generator instead of Coldcard's intended hardware random-number generator, leaving some seeds with insufficient randomness. Coldcard estimates that affected Mk2 and Mk3 seeds may have had an effective search space of about 40 bits, while later Mk4, Mk5 and Q models received extra entropy from secure elements, raising the preliminary estimate to around 72 bits. Neither met the company's 128-bit target.

A firmware download can change the process used for the next seed, but it cannot change private keys that have already been derived from a weak one. For an affected holder, the remedy therefore has three parts: verify the firmware, make a replacement seed, and move the balance to a receiving address derived from it. Skipping the last step leaves the Bitcoin under the same old keys, which is why this is a wallet-replacement issue rather than a simple software maintenance step.

Check the version that created the seed

Coldcard's security-status page separates device models and release tracks. Standard and Edge firmware use different version numbers, so holders should check the track they were using rather than compare the numbers alone.

Coldcard offers one important exception. According to the company, a user who added at least 50 fair, independent and private dice rolls when creating the seed supplied enough additional entropy to avoid this particular RNG risk. The dice sequence must not have been stored, photographed or otherwise exposed.

A strong, unique BIP-39 passphrase also makes it harder to use an affected seed, but it does not correct the underlying flaw. Coldcard still recommends migration as soon as practical for passphrase wallets unless the documented dice condition applies. Anyone who cannot clearly establish that their setup met the exception should follow the migration guidance rather than rely on memory.

What 5.6.1 and 1.5.1Q change

The current standard releases add controls beyond the original RNG hotfix. New seed generation now combines fresh device entropy with a required user contribution: at least 65 key presses with unpredictable timing, 50 physical six-sided-die rolls, or 128 physical coin flips.

Coinkite says AI-assisted review also identified issues involving transaction approval, USB handling and firmware validation. Its security page lists targeted work by outside reviewers, including a real-device RNG test, source reviews and reproducible-build work. The stated scope matters: these checks validate the listed mechanisms, not every possible condition across every firmware binary.

How to replace an affected seed safely

Coldcard's migration guidance is deliberately cautious. Moving Bitcoin under pressure can create a new problem if a user sends to the wrong address, loses the replacement backup, or installs a counterfeit firmware file. The recommended steps:

  • Open Coldcard's website directly. Download the correct release for the device and release track, then verify the SHA-256 hash and the signed signatures.txt file.
  • Generate a completely new seed. Do not reuse the old words or transfer Bitcoin to another address derived from the same seed.
  • Back up the replacement wallet offline. Record the seed carefully. If using a passphrase, store it separately from the seed words and note the wallet fingerprint.
  • Restart and check the wallet. Confirm the fingerprint and receiving address on the Coldcard screen before sending funds.
  • Send a small test transaction. Confirm its arrival and recovery details before moving the remaining balance.
  • Keep the old backup until the migration is complete. It may be needed to access the old wallet or document a theft report.

Coinkite's technical backgrounder provides the model-specific migration instructions. It also warns that a passphrase creates a different wallet every time it is entered; a typo can lead to a valid but empty wallet. That is why confirming the wallet fingerprint matters before depositing the full balance.

Expect fake migration help

Security incidents create a ready-made pretext for phishing. A fake support account can offer an "RNG checker," a recovery tool, or a temporary address for moving Bitcoin. None of those services need the recovery phrase, PIN or private key to help a holder verify a public transaction.

Use a saved Coldcard address or type the official domain directly, and do not install firmware from a message, ad or social-media reply. The same principle applies to any genuine security alert: as Coindoo reported in its coverage of MiCA-related migration scams, a real announcement can be copied to direct users toward a fake support channel.

If an unauthorized transaction is still unconfirmed and marked replaceable, there may be a narrow chance to supersede it with a higher-fee transaction to a secure wallet. That process is technical and time-sensitive. Coindoo's guide on stopping eligible pending Coldcard transfers explains the conditions; holders who are unsure should seek help from a trusted Bitcoin security professional rather than improvise with the remaining balance.

A key replacement, not a routine update

Coldcard's new releases address the published seed-generation defect and add several controls around setup, signing and firmware handling. For a seed created on the affected versions without the qualifying dice protection, the remaining task is straightforward in principle: establish a verified replacement wallet and move the Bitcoin under its new keys before relying on the old backup again.

Source review: The technical cause, affected versions, current release recommendations, seed-creation requirements, migration steps and validation scope are based on Coldcard's security-status page and Coinkite's technical backgrounder. Coldcard says its advisory does not establish the cause of any individual reported loss; this article therefore does not present reported theft totals as a conclusion confirmed by the firmware update.