Crypto News

Coldcard releases security update to fix seed phrase vulnerability

Coldcard releases security update to fix seed phrase vulnerability

Coldcard firmware update forces stronger seed phrase generation

Coldcard, a hardware wallet used to store cryptocurrency securely, has released a new firmware update to fix a vulnerability in how it generates seed phrases. The update requires users to provide additional randomness when creating new seed phrases to prevent potential theft of funds.

The vulnerability, which was discovered earlier this year, allowed attackers to guess weak seed phrases and steal Bitcoin from affected wallets. Coldcard’s manufacturer, Coinkite, has urged all users to upgrade their devices and generate new seed phrases immediately.

Existing seed phrases remain unsafe even after the update, so users must create new ones and move their funds to the new wallets.

How the new update works

The latest firmware (version 5.6.1 for Coldcard Mk4 and Mk5, and 1.5.1Q for Coldcard Q) now requires users to supply extra randomness when generating a new seed phrase. This can be done in one of three ways:

  • Pressing at least 65 keys with unpredictable timing
  • Rolling a six-sided die 50 times
  • Flipping a coin 128 times

This user-supplied randomness is combined with randomness from the device’s hardware to create a stronger, more secure seed phrase. The goal is to ensure that even if one source of randomness fails, the seed phrase remains unpredictable.

Additional security improvements

The update also includes new safeguards for USB connections and transaction signing. Coldcard now re-verifies transactions right before signing them to protect against potential attacks from compromised computers. Other changes include:

  • Restricting USB downloads to the most recent data
  • Requiring encrypted sessions for USB transfers
  • Blocking certain Bitcoin transaction modes that could allow outputs to be modified
  • Adding extra checks for the device’s hardware random number generator

Losses from the exploit reach $112 million

According to a report by Galaxy Research, confirmed losses from the Coldcard exploit have reached 1,778 Bitcoin, worth about $112 million. This makes it the third-largest cryptocurrency exploit of 2026 so far, based on data from DefiLlama.

The vulnerability was caused by a firmware bug introduced in March 2021, which reduced the strength of seed phrases from 128 bits to just 40 bits. This made it possible for attackers to guess seed phrases without physical access to the device, according to cybersecurity firm TRM Labs.

Tool launched to detect vulnerable wallets

Blockchain security company Coinspect has released a free public tool called Unlukey to help users check if their wallet addresses were generated from weak seed phrases. The tool compares public addresses against a dataset of known weak seeds to identify potential exposure.

Coinkite had already released a partial fix on July 31, but the latest update follows three weeks of additional security reviews to address other potential risks.

What Coldcard users should do now

  • Upgrade to the latest firmware immediately
  • Generate a new seed phrase using the updated method
  • Move all funds from the old wallet to the new one
  • Do not use the old seed phrase again

Sources

Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!