Coldcard firmware forces physical randomness after seed-generation flaw

Coinkite, maker of the Coldcard Bitcoin hardware wallet, released new standard firmware on Aug. 20 that requires users to add physical randomness when generating a seed. The process accepts at least 65 key presses at unpredictable intervals, 50 physical six-sided die rolls or 128 physical coin flips alongside device-generated entropy. The change addresses a flaw that could route randomness requests to a deterministic MicroPython fallback when a feature flag defined as zero was treated as present. Users who generated seeds with affected firmware must create a new seed and migrate funds unless they added at least 50 fair, independent and private die rolls without recording or exposing the sequence. Installing fixed firmware does not repair an existing seed. Coinkite recommends version 5.6.1 for Mk4 and Mk5 devices and 1.5.1Q for Q devices, while the affected-version boundaries vary by model and track. Block’s technical analysis includes Mk2 and Mk3 version 4.0.0 in the exposure range, broader than Coinkite’s stated boundary. The release also adds transaction-signing, USB, firmware-validation and RNG-fault protections. Coinkite says some customers suffered severe losses and that law enforcement is investigating, but has not published a verified victim count or loss total.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.
Coldcard firmware forces physical randomness after seed-generation flaw - CoinPost Terminal