Coldcard firmware flaw prompts seed migration after reported losses exceed $100 million

Coinkite released firmware 5.6.1 for Coldcard Mk4 and Mk5 devices and 1.5.1Q for the Q after a build and link error allowed MicroPython’s Yasmarang pseudorandom number generator to enter seed generation from March 2021. New standard seeds require device entropy plus at least 65 unpredictable key presses, 50 physical six-sided die rolls or 128 coin flips. Affected seeds may have about 72 bits of entropy instead of the expected 128 bits and must be replaced unless users completed the specified private, independent 50-die-roll exception. Galaxy Research reported at least 1,719 BTC stolen and more than 250 victims, with losses estimated at about $111 million and potentially above $130 million, while another account cited 1,596 BTC from roughly 7,300 addresses. Coinkite has not published a verified total, and the figures may reflect different reporting dates or verification standards. Installing the update does not repair existing seeds; affected users should create and verify a new seed and migrate funds immediately unless the exception applies.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.