Skip to content Skip to sidebar Skip to footer
Prefer Koin Bülteni on Google Add as source

Coldcard Firmware Patch Not Enough: Renew Your Seeds After Losses Surpassing $114 Million

Following a vulnerability that led to over $114 million in bitcoin thefts, Coldcard has released new firmware, stating that seeds generated between 2021 and July 2026 must be renewed and funds moved to a new wallet.

As reported by CoinDesk, Canadian developer Coinkite, the creator of Coldcard, has released version 5.6.1 for Mk4 and Mk5 devices and 1.5.1Q for the Q model. The update addresses the randomness vulnerability responsible for losses exceeding $114 million.

The most critical point is that the update does not secure existing wallets. Users with seeds generated on the affected firmware between 2021 and July 2026 must create a new seed and move their bitcoins to the new wallet. Firmware should only be installed from Coinkite’s official download page.

Coldcard users must renew seeds

Physical entropy is used for generating new seeds. Users can press 65 keys at random intervals, roll a six-sided die 50 times, or perform 128 coin flips. These methods leverage unpredictable physical outcomes rather than leaving randomness to software.

An AI-powered review revealed other issues alongside the initial bug, including transaction confirmation, data handling over USB, and firmware update verification. Coinkite has replaced the Yasmarang-based backup random number generator with a SHA-256 based structure, which Bitcoin also uses. Transactions are re-checked just before signing, and insecure modes that could be altered after signing are blocked by default.

Tüm gelişmelerden ve paylaşımlardan haberdar olmak için Telegram kanalımıza katılın!