Coldcard hack firmware 5.6.1: what changed on August 20

Bitcoin is trading around $77,260 as of Saturday, August 22, but the number that matters this week for Coldcard owners isn't the price — it's a firmware version. Coldcard hack firmware 5.6.1, released by Coinkite on Thursday, August 20, closes a five-year-old bug that has already let attackers steal an estimated $115-130 million in bitcoin since late July. The patch fixes how new wallets are created. It does nothing for wallets that already exist, and that distinction is the whole story.

The root problem traces back to a March 2021 build error in Coldcard's firmware. A software library called libngu was supposed to pull randomness from the device's hardware random number generator when creating a new seed phrase — the 12 or 24 words that control your bitcoin. Instead, on certain builds, it silently fell back to a much weaker software-based randomness source. The practical effect: seeds that were supposed to have 128 bits of entropy (astronomically hard to guess) actually had as little as 40 bits on Mk3 devices and around 72 bits on Mk4, Mk5 and Q models. That's still a large number, but it's small enough that a well-resourced attacker with knowledge of the flaw can narrow down and eventually guess the seed.

Firmware 5.6.1 fixes the mechanism going forward. It now forces genuine user-supplied randomness into every new seed — Coinkite's instructions call for at least 65 keypresses, physical dice rolls, or coin flips before the device will generate a wallet. That's a real fix for anyone setting up a Coldcard from today onward.

Am I affected?

If your Coldcard is running any firmware version from March 2021 up to just before 5.6.1 — which, in practice, covers most devices in active use until this week — and you generated your seed phrase on that device during that window, your seed is potentially weak. Updating to 5.6.1 does not change the seed you already have. Coinkite has confirmed this directly: the patch prevents future harm, it does not retroactively repair a compromised seed. The only fix is generating a brand-new seed on the patched firmware and moving your bitcoin to it.

So the real question isn't "did I install the update" — it's "when was my current seed generated, and on what firmware." If you can't answer that with confidence, treat your existing seed as suspect.

Is this still an active threat?

Yes, and that's the part getting lost in the "just update your firmware" advice circulating online. Galaxy Research, which has been tracking the on-chain movement of stolen funds since the first wave hit on July 30, estimates that roughly 90% of the 1,800-2,000+ BTC taken across four separate attack waves is still sitting unmoved in attacker-controlled wallets. That's not just a historical loss tally — it's a signal that whoever is exploiting this bug is still actively scanning for more vulnerable wallets, including ones that haven't been touched yet. Every Coldcard seed generated in the affected window and never migrated is still a live target, weeks after the first drain was reported.

What to do right now

First, update to firmware 5.6.1 — that's non-negotiable regardless of your seed's history, since it closes the door on future weak-entropy generation. Second, and more urgently, if there's any chance your current seed predates the patch, generate an entirely new seed on the updated firmware and move your bitcoin to a fresh wallet address. Don't just re-encrypt or back up the old phrase — abandon it. Third, treat any hardware wallet purchased or set up between 2021 and this week with the same suspicion, even if it's a different brand; a broader AI-assisted security audit reportedly turned up 85 similar entropy and random-number-generator weaknesses across other wallet implementations, none of which have been publicly disclosed yet pending vendor fixes. Coldcard may be the first disclosure in this category, not the last.

The compensation fight nobody's won yet

For anyone who already lost funds, there's no clean resolution in sight. Coinkite has apologized and shipped the patch, but it hasn't published an official loss figure or offered reimbursement, and its terms of service disclaim liability for exactly this kind of defect. A proposed community-funded reimbursement pool, floated by Bitcoin developer Muneeb Ali, exists only as an idea so far — no payouts have gone out. Separately, the law firm Stoltmann Law has been soliciting affected users for a potential class action. Neither route has produced money for victims yet, and there's no fixed timeline for either to.

What this means going forward

The market impact here is narrow — this is not a bitcoin price story, it's a self-custody trust story. Expect a slow, uneven migration over the coming weeks as Coldcard owners who hear about the bug move their funds, punctuated by occasional new drain reports as slower-moving holders get caught out. Don't expect a Coinkite reimbursement announcement soon, and don't be surprised if this turns out to be the first of several similar hardware-wallet disclosures rather than an isolated incident. If you own a Coldcard and haven't checked when your seed was generated, that's the one action item worth doing today — not tomorrow.

Sources