The coldcard firmware update fix, in one sentence
Coinkite shipped firmware 5.6.1 for the Mk4 and Mk5, and 1.5.1Q for the Coldcard Q, on August 20-21. The update closes a real flaw in how the device generates a new seed phrase. It does nothing for a seed that already exists on your Coldcard. If your wallet was set up any time between March 2021 and this week, installing the patch and stopping there leaves you exactly as exposed as you were before you updated.
Why the flaw existed in the first place
The bug traces back to firmware 4.0.1, released in March 2021. When a Coldcard generated a brand-new seed, it leaned on the device's own random-number generator without also forcing the user to contribute unpredictable input of their own. On the earlier Mk2 and Mk3 hardware in particular, researchers found the effective randomness behind that process could shrink to roughly 40 bits — small enough that, with enough compute, an attacker could plausibly narrow down and eventually guess the seed. That weakness sat quietly in the code for five years before it became the entry point for a wave of thefts: on-chain trackers have linked roughly 2,055 BTC — worth roughly $130 million by Galaxy Research's latest tally — to Coldcard-related theft since late July, with the bulk of those coins still unmoved and traceable rather than laundered.
I updated my Coldcard firmware — am I safe now?
No, not automatically. The new firmware changes what happens the next time you generate a seed, not what already happened. From 5.6.1 and 1.5.1Q onward, creating a seed requires you to physically feed the device your own entropy — at least 65 timed keypresses, 50 dice rolls, or 128 coin flips, which the firmware then hashes together with its internal randomness. That closes the original gap for good, but only for seeds made after you do it. Coinkite's own migration guidance is blunt: anyone whose seed was generated on any firmware version between 2021 and July 2026 needs to create an entirely new seed on the updated firmware, then manually move their funds into a fresh wallet built from that new seed. The one exception is a seed you deliberately strengthened yourself at creation — with a long private dice-roll session or a unique BIP-39 passphrase — but if you're not certain you did that, treat the seed as compromised. The old seed, and anything still sitting behind it, stays vulnerable indefinitely.
What the update does fix on its own
It isn't only about seed generation. 5.6.1 and 1.5.1Q also add real-time re-verification of transaction details immediately before signing, aimed at a different problem: a compromised computer or tampered microSD card trying to swap in a fraudulent transaction at the last second. That protection applies the moment you update, no seed migration required. It's a genuine improvement, but it's a separate one from the entropy fix, and it's easy to see both changes bundled into a single release note and assume the whole update is a single "you're covered now" event.
What it means beyond your own wallet
Coinkite has already treated this as a business-level problem, not just a software one: it paused shipments of affected units and destroyed compromised inventory rather than shipping a patch and moving on. For the wider hardware-wallet market, the fallout is reputational more than systemic — roughly $130 million is a rounding error against Bitcoin's total market capitalization, but it lands squarely on the self-custody pitch, which only works if the device generating your keys does its job correctly. Expect rivals to use this in their own marketing, and expect closer scrutiny of how every hardware-wallet vendor tests and audits randomness generation, not just Coinkite.
The gap most owners will miss
This is the part Coinkite is clearly worried about, because normal use of the device gives no visible warning that anything is wrong. A patched Coldcard holding coins on an old, weak seed looks and behaves identically to one that's fully secure — there's no on-screen flag distinguishing them. That makes complacency the likeliest outcome: install the update, see nothing alarming, assume the job is done. Migrating funds is genuinely more work than tapping "update" — generate a new seed, verify it, set up a new wallet, and if you're in a multisig setup, coordinate that change across every signer before moving a single coin.
What to actually do this week
If your Coldcard's seed predates this week's patch, treat the firmware update as step one of two, not the whole fix. Generate a fresh seed using the new mandatory-entropy process, confirm the new wallet address independently, and move your funds over deliberately rather than in a rush. Until that second step happens, the coins behind your old seed carry the same exposure they did before Coinkite shipped anything. Given that over 85% of the funds already linked to this flaw remain unmoved, the realistic risk window is still open — it just now has a clear, if unused, way to close it.
Sources
- https://blog.coinkite.com/coldcard-security-update-5.6.1-1.5.1q/
- https://coldcard.com/security/status
- https://cryptobriefing.com/coldcard-firmware-update-114m-exploit/
- https://crypto.news/coldcard-firmware-update-requires-users-move-bitcoin/
- https://cointelegraph.com/news/coldcard-upgrade-strengthen-seed-phrase-generation
- https://www.cryptotimes.io/2026/08/21/coinkite-updates-coldcard-after-seed-flaw-exposed-bitcoin-wallets/
- https://coldcard.com/docs/upgrade/