Coldcard strengthens seed generation with firmware update
Coinkite has released firmware updates for Coldcard hardware wallets, requiring user-supplied entropy to strengthen seed phrase generation after an exploit led to $112 million in Bitcoin losses. Users must generate new seed phrases to secure their funds.
Intelligence analysis by Gemini 2.5 Flash

Coldcard's manufacturer, Coinkite, rolled out firmware 5.6.1 for Mk4/Mk5 and 1.5.1Q for Coldcard Q, enhancing seed phrase generation by combining user input with device randomness. This update addresses a vulnerability that caused a significant Bitcoin exploit, but users are urged to replace existing, potentially compromised seed phrases immediately.
Imagine your secret code for your digital money is like a super-long, random password. Coldcard, a special device that keeps your money safe, had a tiny glitch that sometimes made these passwords not quite random enough, like picking a password that's too easy to guess. Now, they've fixed it with a new update that makes you help create the password by pressing buttons or rolling dice, making it super strong and unique. But if you already have an old, weaker password, you still need to make a brand new, stronger one to keep your money safe!
Analysis
Coinkite's Firmware 5.6.1
Coinkite, the manufacturer behind Coldcard hardware wallets, has introduced a significant security upgrade with the release of firmware 5.6.1 for its Mk4 and Mk5 devices, alongside version 1.5.1Q for the Coldcard Q. This update is a direct response to a vulnerability in the seed phrase generation process that previously exposed users to exploits.
The core enhancement of this firmware lies in its new requirement for newly generated seeds to incorporate user-supplied entropy. This can be achieved through a minimum of 65 unpredictable keypresses, 50 rolls of a six-sided die, or 128 coin flips. This user input is then combined with multiple internal device randomness sources, including secure elements and a hardware random-number generator (RNG), to create a more robust and unpredictable seed phrase.
1,778 Bitcoin Loss
The urgency of this firmware update is underscored by the substantial financial impact of the prior vulnerability. According to an August 14 report by Galaxy Research, confirmed losses from the Coldcard exploit reached a staggering 1,778 Bitcoin (BTC), which was valued at approximately $112 million at the time. This incident marks the third-largest cryptocurrency exploit of 2026, as aggregated by DefiLlama data.
The root cause of these losses was identified as a firmware bug from March 2021, which weakened seed randomness on some Coldcard wallets. TRM Labs reported that this bug reduced key strength from 128 bits to a mere 40 bits, making these seeds susceptible to brute-force attacks without requiring physical access to the device. The new firmware aims to prevent such vulnerabilities from recurring by significantly bolstering the entropy used in seed generation.
Coinspect's Unlukey Tool
In parallel with Coinkite's efforts, other blockchain security firms are also developing tools to help users identify and mitigate risks from weak seed generation. Coinspect, a blockchain security company, has launched 'Unlukey,' a free public tool designed to detect wallet addresses that may have been generated from compromised or weak seed phrases.
This initial iteration of Unlukey focuses on reproducing known weak seed generation patterns. It then checks whether public wallet addresses belong to the dataset of addresses potentially affected by these vulnerabilities. The availability of such tools is critical for users who may have generated seeds prior to the firmware update, providing a means to assess their exposure and take necessary precautions, such as migrating funds to newly generated, secure wallets.
Key points
- Coinkite released firmware 5.6.1 for Coldcard Mk4/Mk5 and 1.5.1Q for Coldcard Q to strengthen seed phrase generation.
- The update requires user-supplied entropy (e.g., 65 keypresses, 50 die rolls) combined with device randomness for new seeds.
- Existing seed phrases remain vulnerable even after the upgrade and must be replaced with new ones.
- The Coldcard exploit led to confirmed losses of 1,778 Bitcoin, valued at approximately $112 million, making it the third-largest crypto exploit of 2026.
- Blockchain security company Coinspect launched 'Unlukey,' a free tool to identify wallet addresses generated from weak seed phrases.
Users who promptly upgrade their Coldcard devices and generate new seed phrases will benefit from significantly enhanced security, mitigating the risks associated with previously weak randomness. The mandatory user-supplied entropy combined with improved device randomness establishes a higher standard for hardware wallet protection, fostering greater trust in the Coldcard ecosystem.
Despite the critical firmware update, a substantial risk persists for users who fail to generate new seed phrases, leaving their existing funds vulnerable to the identified weakness. The necessity for active user participation means that many may not fully secure their assets, potentially leading to further losses if they continue to rely on compromised seeds.



