NewsCryptoColdcard Issues Major Firmware Upgrade After Seed-Generation Flaw Exposed Customers to Theft

Coldcard Issues Major Firmware Upgrade After Seed-Generation Flaw Exposed Customers to Theft

Author: CryptoNewsNet·

Key Takeaways

  • Firmware 5.6.1 requires users to supply randomness through actions such as pressing keys, rolling dice, or flipping coins when creating a seed.
  • Coldcard says the new seed-generation process reduces reliance on the device’s internal random number generator.
  • The company warns that wallets created with the vulnerable method remain exposed and must be migrated rather than patched in place.
  • The update adds a final PSBT check before signing, designed to catch transaction changes made by a computer after user approval.
  • Coldcard has also restricted USB transfers in encrypted sessions and blocked Delta Mode features that could reveal seed information.
Coldcard Issues Major Firmware Upgrade After Seed-Generation Flaw Exposed Customers to Theft

Coldcard Issues Major Firmware Upgrade After Seed-Generation Flaw Exposed Customers to Theft

Coldcard has deployed a major firmware upgrade after a seed-generation flaw left some customers exposed to theft. The company is urging users of its Mk4, Mk5, and Q devices to install firmware 5.6.1, which changes how the hardware wallets create, protect, and validate wallet data. Coldcard devices are produced by Coinkite and marketed as Bitcoin-only tools for security-focused self-custody, a market in which the trustworthiness of the seed-generation process is the product's core promise.

User-Supplied Randomness Now Required for Seed Creation

A central change concerns seed generation: Coldcard now requires users to contribute their own randomness when creating a seed. Users can press keys, roll dice, or flip coins, and the device combines that input with its hardware entropy and cryptographic protections. The design change speaks to a foundational risk in hardware wallets: a recovery phrase is derived from random entropy, and if that entropy is predictable or compromised, the resulting private keys — and any funds they control — can be recreated by an attacker. Mixing user input into the process reduces dependence on the device's internal random number generator as a single point of trust. The company cautions, however, that the upgrade cannot protect seeds that were originally created through the vulnerable process, so customers holding exposed seeds must migrate their funds rather than rely on the patch alone.

Stronger Checks Around Wallet Operations

Beyond seed generation, the release adds safeguards covering transactions and USB connections. The device now performs a PSBT (partially signed Bitcoin transaction) check immediately before signing, so users receive a warning if a computer changes transaction details after they have approved them. PSBT, standardized in BIP 174, is the format wallets and coordinators use to pass partially signed transactions between parties, and the last-second check targets a scenario in which a compromised computer tampers with a transaction after the user has reviewed it on the device's own screen.

Encrypted sessions now restrict USB transfers to the latest, device-generated results only, and Coldcard has blocked Delta Mode features that could expose sensitive information from the seed. The firmware also improves hardware randomness testing, backup recovery, multisig security, and firmware verification, reducing risks across the stages of wallet use.

Coldcard has additionally created a security status page and is helping customers move funds away from exposed seeds. Authorities continue to investigate the thefts associated with the earlier vulnerability, and the scope of losses and any attribution remain unresolved.