Coinkite Releases Coldcard Firmware After Seed-Generation Flaw Linked to Up to $130 Million in Bitcoin Thefts

Coinkite released Coldcard firmware 5.6.1 for Mk4 and Mk5 devices and 1.5.1Q for the Q series after a seed-generation flaw dating to 2021 was linked to Bitcoin thefts reported at $114 million to roughly $130 million. The flaw reduced entropy on some air-gapped wallets from 128 bits to about 40 bits, allowing private keys to be guessed without physical access. A three-week review involving outside researchers and AI-assisted tools identified additional unrelated bugs and led to mandatory user-supplied randomness, stronger hardware random-number-generator checks, and broader security fixes. Coinkite warns that updating firmware cannot secure a wallet whose seed phrase or private keys were already exposed; potentially affected users should create new seeds on clean, updated devices and move their funds.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.