TheCryptoUpdates
Crypto Scams

Coldcard requires 65 key presses after seed exploit; exposed funds must move

Coinkite has pushed out a new firmware update for Coldcard hardware wallets. The release, dated Aug. 20, changes how seeds are generated. From now on, users must add physical randomness during seed creation.

This is not a minor tweak. It is a direct response to a security flaw in the wallet’s random number generator. So the update forces at least 65 key presses, 50 six-sided die rolls, or 128 physical coin flips whenever you create a seed. The idea is to mix the device’s own randomness with something you control. That way, a weak RNG is not the only thing standing between you and a compromised wallet.

What changed in the firmware

The new standard firmware makes these requirements part of the normal workflow. You no longer get a seed without adding some human input. That is a big change for people used to letting the device do all the work. The mandatory input does not fix seeds that already exist. It only applies to new ones.

Coinkite’s guidance is fairly clear here. If you are still using a seed generated by affected firmware, you should generate a new seed and transfer your funds. There is an exception. If you used at least 50 fair, independent and private die rolls during the affected workflow, and never recorded or exposed the sequence, migration may not be required. But if you used fewer rolls, or you are not sure about the conditions, the safer move is to migrate.

Who is affected

The advisory covers a lot of devices. It includes Mk2 and Mk3 firmware from 4.0.1 through 4.1.9, Mk4 and Mk5 standard firmware before 5.6.0, and Edge firmware before 6.6.0X. Q devices are also on the list, both standard and Edge. Coinkite recommends version 5.6.1 for Mk4 and Mk5 devices, and 1.5.1Q for Q devices.

There is some disagreement on the exact boundary. Block, the payments company, did its own analysis and found the affected Mk2 and Mk3 range should include version 4.0.0. So if you are on that version, do not assume you are safe just because the vendor’s list stops at 4.0.1.

For migration, Coinkite says to generate a genuinely new seed, verify the backup and wallet fingerprint, confirm a receiving address on the device, send a small test transaction, and then move every balance tied to the old seed. Cloning or restoring the wallet does not create a new seed, so that is not a workaround.

Other fixes in this release

The firmware package also touches signing and data paths. USB review is now bound to a staged PSBT checksum. The device rechecks transaction bytes before signing, blocks SIGHASH_SINGLE modes by default, and restricts USB downloads to the current encrypted-session result. There are also RNG-fault stops, a boot-time hardware-RNG linkage check, and more Delta Mode isolation.

Coldcard’s status page mentions targeted source review and a real-device RNG-path test, but the company admits these do not amount to a full audit of every fixed binary. Meanwhile, Coinkite says some customers suffered severe losses and law enforcement is involved. No verified victim count or total loss amount has been published.

People holding old seeds should not assume the update alone protects them. The firmware fixes the path going forward, but the damage may already be done if the original seed came from a weak RNG. Moving funds to a brand new seed is the only reliable way to leave that risk behind.

Loading

Related posts

Crypto Scams | Cryptojacking Malware KingMiner Escapes Detection to mine Monero

Kesarwani

Oracle Attack of $1.26 Million on Solana-Based Lending Platform Solend

Mridul Srivastava

US Government transfers 667 Bitcoin from seized HashFlare funds

Timm