Coinkite released Coldcard firmware 5.6.1 for Mk4 and Mk5 devices and 1.5.1Q for the Q series after a seed-generation flaw dating to 2021 was linked to Bitcoin thefts reported at $114 million to roughly $130 million. The flaw reduced entropy on some air-gapped wallets from 128 bits to about 40 bits, allowing private keys to be guessed without physical access. A three-week review involving outside researchers and AI-assisted tools identified additional unrelated bugs and led to mandatory user-supplied randomness, stronger hardware random-number-generator checks, and broader security fixes. Coinkite warns that updating firmware cannot secure a wallet whose seed phrase or private keys were already exposed; potentially affected users should create new seeds on clean, updated devices and move their funds.