Key facts
- Coinkite released firmware 5.6.1 for Coldcard Mk4/Mk5 and 1.5.1Q for Coldcard Q.
- New seed generation now requires user-supplied entropy and improved device randomness.
- Existing seed phrases are considered vulnerable even after the update and must be replaced.
- The update includes safeguards for USB data handling and transaction signing.
- A tool called Unlukey has been released to detect wallets with weak seed phrases.
Coinkite has released a significant security upgrade for its Coldcard hardware wallets, aiming to bolster seed phrase generation by incorporating user-supplied entropy alongside improved device randomness. The new firmware, version 5.6.1 for Mk4 and Mk5 devices and 1.5.1Q for the Coldcard Q, mandates actions like at least 65 keypresses, 50 die rolls, or 128 coin flips from the user, which is then combined with randomness from the device's secure elements and hardware random-number generator.
Despite the enhanced security for newly generated seeds, Coinkite strongly advised users to upgrade their devices immediately and, crucially, to generate entirely new seed phrases. The company emphasized that existing seed phrases, even on upgraded devices, remain vulnerable due to a past firmware bug that weakened randomness, potentially reducing key strength significantly. Confirmed losses from a previous Coldcard exploit have reached 1,778 Bitcoin, valued at approximately $112 million, making it the third-largest crypto exploit of 2026.
The latest update also introduces additional security measures, including safeguards for USB data handling and transaction signing. These aim to protect against theoretical attacks via compromised computer USB ports by re-verifying transactions before signing. Furthermore, the firmware blocks certain Bitcoin signature hash modes by default that could allow transaction outputs to be modified.
In parallel, blockchain security firm Coinspect has launched a free public tool called Unlukey, designed to identify wallet addresses generated from weak seed phrases, addressing a vulnerability that was a primary cause of the Coldcard exploit. TRM Labs previously identified a March 2021 firmware bug that reduced seed randomness on some Coldcard wallets, making them susceptible to brute-force attacks.