
Coinkite has released a major security upgrade for its Coldcard hardware wallets aimed at strengthening seed-phrase generation by forcing users to contribute unpredictable entropy. The change is designed to ensure private keys remain hard to predict even if one of the device’s randomness sources underperforms.
In a Thursday blog post, Coinkite announced firmware 5.6.1 for the Coldcard Mk4 and Mk5, and 1.5.1Q for the Coldcard Q. The company said affected users must upgrade immediately and—critically—replace any existing seed phrases before moving funds.
Key takeaways
- Coinkite’s new firmware changes how Coldcard generates seed phrases by mixing user-supplied entropy with multiple device randomness sources.
- For newly generated wallets, the firmware requires user input via at least 65 keypresses with unpredictable timing (or equivalent die/coin-rolling actions).
- Even after upgrading, previously generated seed phrases remain vulnerable and must be replaced with new seeds before migrating funds, Coinkite says.
- The update also adds safeguards around USB handling, transaction verification timing, hardware RNG checks, and boot-time integrity testing.
- Separately, Coinspect launched Unlukey, a free tool intended to help detect wallet addresses potentially linked to weak-seed generation.
Seed phrases now rely on more user unpredictability
At the center of Coinkite’s update is a shift in seed generation. According to the company, newly generated seeds must incorporate user-supplied entropy through interactive actions, including at least 65 keypresses with intentionally unpredictable timing. Coinkite also describes alternative entropy contribution methods: 50 rolls of a six-sided die or 128 coin flips.
That input is then combined with randomness from several parts of the device, including secure elements and the wallet’s hardware random-number generator (RNG). Coinkite frames the redesign as defense-in-depth: by requiring user entropy and mixing it with internal sources, the resulting private keys should remain unpredictable even if one device entropy source fails or is otherwise compromised.
Importantly, Coinkite’s guidance is not limited to upgrading. The company warns that existing seed phrases do not become safe just because the firmware is updated; users must generate new seeds and replace the wallet’s backing recovery phrase before migrating funds.
Coinkite adds transaction and USB safeguards
The new firmware follows an earlier July 31 update that Coinkite says already corrected the seed-generation failure for newly created wallets. In its Thursday announcement, Coinkite describes the latest release as the result of additional security review over the subsequent weeks, expanding protections beyond seed generation.
One element targets how transactions are processed when a Coldcard is connected to a potentially compromised computer. Coinkite says the firmware re-verifies transactions immediately before signing—an approach intended to counter a theoretical attack involving a compromised USB port. In other words, the device aims to confirm that what it signs is still what it expects, right up to the moment it produces a signature.
Coinkite also describes new hardware RNG checks and a boot-time test designed to confirm the wallet is using the intended hardware pathway. Beyond randomness integrity, the update restricts USB downloads to the device’s most recent output and requires an encrypted session, reducing opportunities for manipulated data to be fed to the wallet during the workflow.
Finally, the firmware blocks certain Bitcoin signature hash modes by default—specifically those that could allow transaction outputs to remain modifiable under the affected conditions Coinkite references.
Impact from the Coldcard exploit remains significant
While Coinkite focuses on preventing additional exposure, the ongoing consequences of the Coldcard exploit continue to shape the security landscape. Galaxy Research reported that confirmed losses associated with the exploit reached 1,778 Bitcoin, worth about $112 million, in an Aug. 14 report. Galaxy’s assessment is linked to a broader figure compilation, and DefiLlama data aggregated in the same context ranks the Coldcard hack as the third-largest cryptocurrency exploit of 2026.
These figures underline why seed-generation hardening and secure transaction flows matter to users: even hardware-wallet protections can be undermined if randomness used for key material is weak or if signing operations can be influenced through connectivity or timing issues.
Weak-seed detection tools enter the ecosystem
Alongside firmware fixes, at least one blockchain security firm is working on software approaches to identify potential victims of weak seed generation. Coinspect revealed Unlukey, a free public tool for identifying wallet addresses that may have been generated from weak seed phrases.
In a Friday X post, Coinspect said the first iteration of Unlukey focuses on reproducing known weak seed generation patterns and checking whether public addresses appear in the affected dataset. While this does not automatically prove that any given address belongs to an exposed wallet, the tool is positioned as a way to narrow down exposure for individuals and analysts who are investigating risks related to the Coldcard incident.
Context on the underlying weakness comes from TRM Labs, which said in an analysis that a firmware bug from March 2021 weakened seed randomness on some Coldcard wallets. TRM Labs reported that the issue reduced key strength from 128 bits to 40 bits, making keys “brute-forceable without physical access.”
Coinspect’s decision to build an address-level detection method suggests the broader industry takeaway from the Coldcard episode: even when hardware vendors issue patches, secondary tooling can help the ecosystem identify which wallet outputs and addresses may be most at risk based on how seed generation was implemented in the past.
Readers should watch how users apply Coinkite’s guidance—especially the requirement to replace existing seed phrases before moving funds—and whether address-detection tools like Unlukey continue to expand coverage as more information about weak-seed generation patterns is validated.
https://www.cryptobreaking.com/coldcard-firmware-update-improves-seed-2/?utm_source=blogger%20&utm_medium=social_auto&utm_campaign=Coldcard%20Firmware%20Update%20Improves%20Seed%20Generation%20Security%20
Comments
Post a Comment