Coldcard firmware requires physical randomness after wallet seed RNG flaw

Coinkite, maker of the Coldcard Bitcoin hardware wallet, released new standard firmware on Aug. 20 requiring users to add physical randomness when generating a seed. Each new standard seed combines device entropy with at least 65 unpredictable key presses, 50 rolls of a physical six-sided die, or 128 physical coin flips, reducing reliance on the wallet's random-number generator (RNG). The current security status recommends version 5.6.1 for Mk4 and Mk5 devices and 1.5.1Q for Q devices. Coinkite's migration guidance covers Mk2 and Mk3 firmware 4.0.1 through 4.1.9; Mk4 and Mk5 standard firmware before 5.6.0 and Edge firmware before 6.6.0X; and Q standard firmware before 1.5.0Q and Edge firmware before 6.6.0QX. Block's independent technical analysis uses a broader Mk2 and Mk3 boundary that includes version 4.0.0. Installing fixed firmware does not change an existing seed. Unless the dice exception applies, affected users should generate and verify a new seed, confirm a receiving address, send a small test transaction, and transfer all balances from the old seed. The exception applies only where users added at least 50 fair, independent and private physical die rolls through the affected workflow and never recorded or exposed the sequence. Coinkite says some customers suffered severe losses and that law enforcement is investigating, but it has not published a verified victim count or loss total.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.
Coldcard firmware requires physical randomness after wallet seed RNG flaw - CoinPost Terminal