Coldcard strengthens seed generation with firmware update
Coinkite urged Coldcard users to generate new seed phrases, warning that existing vulnerable seeds remain unsafe despite the security upgrade.
Coinkite, the manufacturer of Coldcard devices, has released a firmware update to enhance seed phrase generation security. The update, version 5.6.1 for Coldcard Mk4 and Mk5, and 1.5.1Q for the Coldcard Q, requires users to generate new seed phrases using user-supplied entropy mixed with device randomness. This is intended to make private keys unpredictable, even if one of the device's entropy sources fails.
Users are advised to upgrade immediately, as existing seed phrases remain vulnerable. The exploit has resulted in confirmed losses of 1,778 Bitcoin, worth approximately $112 million, making it the third-largest cryptocurrency exploit of 2026. The July 31 firmware update had already addressed the seed-generation failure for newly created wallets.
The latest release also includes additional checks for USB data handling, transaction signing, and hardware randomness.
Written by urgent.news from Cointelegraph's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.