< Back to all clusters
[TECHNOLOGY] · 2 sources

started · updated

Coinkite updates Coldcard firmware following seed generation vulnerability

Coinkite has released critical firmware updates for its Coldcard Bitcoin hardware wallets (Mk4, Mk5, and Q) following a vulnerability in the seed phrase generation process. The issue, which stemmed from a build and linking error that caused the device to use a general-purpose pseudo-random number generator instead of the intended hardware random number generator, has led to significant financial losses. A report by Galaxy Research indicated that over 8,600 addresses were affected, totaling approximately 1,778.84 BTC, valued at roughly $112.7 million.

The new firmware versions—5.6.1 for Mk4/Mk5 and 1.5.1Q for Coldcard Q—require users to provide manual entropy when generating new seeds. This can be done through 65+ irregular keypresses, 50 dice rolls, or 128 coin flips, which are then mixed with the device’s internal hardware random number generators and secure elements.

Coinkite emphasizes that updating the firmware alone does not secure existing seeds created under the vulnerable versions. Users with affected seeds are strongly advised to install the update, generate a completely new seed using the new entropy requirements, and then transfer their funds to the new wallet. Law enforcement agencies are currently investigating the thefts.

Entities

Coinkite · Coldcard · Galaxy Research