Key facts
- Coldcard maker Coinkite released new firmware (5.6.1 for Mk4/Mk5, 1.5.1Q for Q) to address a seed generation flaw.
- The flaw, present since 2021, reduced wallet seed randomness, making private keys easier to guess.
- Over $130 million in Bitcoin has been stolen from affected Coldcard wallets.
- New seed generation now requires user-added randomness (key presses, dice rolls, coin flips) combined with device randomness.
- Users with seeds generated on affected versions must create new seeds and move their Bitcoin.
- The update also includes fixes for transaction signing, USB connections, and wallet backups.
Coinkite, the maker of Coldcard Bitcoin hardware wallets, has released a significant firmware update following a seed generation flaw that led to the theft of approximately $130 million in Bitcoin. The vulnerability, present since 2021, reduced the randomness of generated wallet seeds, making them easier for attackers to guess.
The new firmware, version 5.6.1 for Mk4 and Mk5 devices and 1.5.1Q for the Coldcard Q, aims to enhance security by requiring users to contribute their own randomness through actions like key presses, dice rolls, or coin flips. This user-supplied entropy is then combined with the device's internal randomness.
Despite the improvements for new seed generation, Coinkite strongly advises users who generated seeds on affected versions to create entirely new seed phrases and migrate their funds. The company noted that existing seeds, even on upgraded devices, remain vulnerable. The exploit has resulted in the loss of over 1,778 BTC, valued at approximately $112 million at the time of tracking by Galaxy Research.
Beyond seed generation, the firmware update also addresses theoretical issues related to transaction signing, USB data handling, firmware validation, Delta Mode, and wallet backups. Coinkite stated that law enforcement agencies are investigating the thefts.
