Coldcard Releases Security Update, but Affected Seeds Need Replacing

Coldcard’s latest firmware improves new wallet setup, but Bitcoin held under a seed generated on affected software remains exposed until its owner creates fresh keys and migrates funds.
Key Takeaways
- Mk4/Mk5 5.6.1 and Coldcard Q 1.5.1Q are the current standard releases.
- Check the firmware used when the seed was created.
- The dice exception requires 50 private, independent rolls.
- New seeds require user-generated randomness.
- Outside reviews checked specific fixes, not every firmware risk.
Why a device update is not enough
Coinkite released the current firmware after a seed-generation defect was connected to reported Bitcoin thefts. The incident did not involve an attacker remotely unlocking every Coldcard device. It involved the way certain recovery seeds were created.
During a 2021 code migration, seed generation reached a software pseudo-random-number generator instead of Coldcard’s intended hardware random-number generator. The result was insufficient randomness in some seeds. Coldcard estimates that affected Mk2 and Mk3 seeds may have had an effective search space of about 40 bits; later Mk4, Mk5 and Q models received extra entropy from secure elements, raising the preliminary estimate to around 72 bits. Neither met the company’s 128-bit target.
A firmware download can change the process used for the next seed. It cannot change private keys that have already been derived from a weak one.
| Step | What changes | What remains unchanged |
|---|---|---|
| Install fixed firmware | How the device generates a seed in future. | The old seed and every address derived from it. |
| Create a replacement seed | The keys controlling the replacement wallet. | Bitcoin still sitting at addresses from the old wallet. |
| Transfer the balance | Which keys control the Bitcoin. | Any theft already confirmed on the blockchain. |
For an affected holder, the remedy therefore has three parts: verify the firmware, make a replacement seed, and move the balance to a receiving address derived from it. Skipping the last step leaves the Bitcoin under the same old keys.
Check the version that created the seed
Coldcard’s security-status page separates device models and release tracks. Standard and Edge firmware use different version numbers, so holders should check the track they were using rather than compare the numbers alone.
| Device or release track | Seeds that need review | Minimum fixed release |
|---|---|---|
| Mk2 / Mk3 | Created on firmware 4.0.1 through 4.1.9 | 4.2.0 or later |
| Mk4 / Mk5 standard | Created before version 5.6.0 | 5.6.0 or later; 5.6.1 is currently recommended |
| Coldcard Q standard | Created before version 1.5.0Q | 1.5.0Q or later; 1.5.1Q is currently recommended |
| Mk4 / Mk5 Edge | Created before version 6.6.0X | 6.6.0X or later |
| Coldcard Q Edge | Created before version 6.6.0QX | 6.6.0QX or later |
Coldcard offers one important exception. A user who added at least 50 fair, independent and private dice rolls when creating the seed supplied enough additional entropy to avoid this particular RNG risk, according to the company. The dice sequence must not have been stored, photographed or otherwise exposed.
A strong, unique BIP-39 passphrase also makes it harder to use an affected seed, but it does not correct the underlying flaw. Coldcard still recommends migration as soon as practical for passphrase wallets unless the documented dice condition applies. Anyone who cannot clearly establish that their setup met the exception should follow the migration guidance rather than rely on memory.
What 5.6.1 and 1.5.1Q change
The current standard releases add controls beyond the original RNG hotfix. New seed generation now combines fresh device entropy with a required user contribution: at least 65 key presses with unpredictable timing, 50 physical six-sided-die rolls or 128 physical coin flips.
| Area | Control in the current standard releases | Practical purpose |
|---|---|---|
| Seed setup | Fresh device entropy plus a required user-generated input. | Seed creation no longer rests on one source of randomness. |
| USB signing | The staged PSBT checksum must match before review and immediately before signing. | Helps detect a transaction that changed after it was staged. |
| Transaction approval | SIGHASH_SINGLE modes are blocked by default. |
Reduces an approval edge case that can be difficult to spot on a wallet screen. |
| Firmware handling | The firmware file must match its signed length; users are instructed to verify the hash and signed file. | Helps users identify a corrupted or substituted update. |
Coinkite says AI-assisted review also identified issues involving transaction approval, USB handling and firmware validation. Its security page lists targeted work by outside reviewers, including a real-device RNG test, source reviews and reproducible-build work. The stated scope matters: these checks validate the listed mechanisms, not every possible condition across every firmware binary.
How to replace an affected seed safely
Coldcard’s own migration guidance is deliberately cautious. Moving Bitcoin under pressure can create a new problem if a user sends to the wrong address, loses the replacement backup or installs a counterfeit firmware file.
- Open Coldcard’s website directly: Download the correct release for the device and release track, then verify the SHA-256 hash and signed
signatures.txtfile. - Generate a completely new seed: Do not reuse the old words or transfer Bitcoin to another address derived from the same seed.
- Back up the replacement wallet offline: Record the seed carefully. If using a passphrase, store it separately from the seed words and note the wallet fingerprint.
- Restart and check the wallet: Confirm the fingerprint and receiving address on the Coldcard screen before sending funds.
- Send a small test transaction: Confirm its arrival and recovery details before moving the remaining balance.
- Keep the old backup until the migration is complete: It may be needed to access the old wallet or document a theft report.
Coldcard’s technical backgrounder provides the model-specific migration instructions. It also warns that a passphrase creates a different wallet every time it is entered; a typo can lead to a valid but empty wallet. That is why confirming the wallet fingerprint matters before depositing the full balance.
Expect fake migration help
Security incidents create a ready-made pretext for phishing. A fake support account can offer an “RNG checker,” a recovery tool or a temporary address for moving Bitcoin. None of those services need the recovery phrase, PIN or private key to help a holder verify a public transaction.
Use a saved Coldcard address or type the official domain directly. Do not install firmware from a message, ad or social-media reply. The same principle applies to any genuine security alert: as our team covered in its report on MiCA-related migration scams, a real announcement can be copied to direct users toward a fake support channel.
If an unauthorised transaction is still unconfirmed and marked replaceable, there may be a narrow chance to supersede it with a higher-fee transaction to a secure wallet. That process is technical and time-sensitive. Our guide on stopping eligible pending Coldcard transfers explains the conditions; holders who are unsure should seek help from a trusted Bitcoin security professional rather than improvise with the remaining balance.
The action is a key replacement, not a routine update
Coldcard’s new releases address the published seed-generation defect and add several controls around setup, signing and firmware handling. For a seed created on the affected versions without the qualifying dice protection, the remaining task is straightforward in principle: establish a verified replacement wallet and move the Bitcoin under its new keys.
Source review: Technical cause, affected versions, current release recommendations, seed-creation requirements, migration steps and validation scope are based on Coldcard’s security-status page and Coinkite’s technical backgrounder. Coldcard says its advisory does not establish the cause of any individual reported loss; this article therefore does not present reported theft totals as a conclusion confirmed by the firmware update.








