Coldcard has released firmware 5.6.1 for Mk4 and Mk5 devices and version 1.5.1Q for the Q model, following a three-week security review after an emergency fix. The update is aimed at reducing the risk tied to a previously disclosed mnemonic-generation attack. Under the new rules, every newly generated seed phrase must include at least one source of user-provided entropy, either through at least 65 irregular key presses, 50 physical dice rolls, or 128 physical coin flips. That input is then combined with fresh entropy from STM32 TRNG, SE1, and SE2.
The firmware also adds staged PSBT verification immediately before signing, tightens USB connection and firmware-update boundaries, improves Delta Mode isolation, fixes an active wallet backup issue, strengthens random number generator initialization and fault checks, and changes the default SIGHASH setting. Coldcard said the release is meant to cut the risk of device compromise. The company also warned that updating firmware does not repair seed phrases created by affected older firmware. Users covered by the security notice are advised to update first, generate and verify a new mnemonic, then move funds to a new wallet. Coldcard recommended that all Mk4, Mk5, and Q users update promptly and verify firmware signatures before installation.
Coldcard has released firmware 5.6.1 for its Mk4 and Mk5 devices, along with version 1.5.1Q for the Q model, after a three-week security review that followed an emergency fix. The release focuses on addressing the security risk linked to a previously disclosed mnemonic-generation attack.
Under the new firmware, each newly generated mnemonic must include at least one source of user entropy: at least 65 irregular key presses, 50 physical dice rolls, or 128 physical coin flips. That user-provided input is combined with fresh entropy from STM32 TRNG, SE1, and SE2.
The update also adds staged PSBT verification immediately before signing, strengthens the boundaries around USB connections and firmware updates, improves Delta Mode isolation, fixes an active wallet backup issue, hardens random number generator initialization and fault checks, changes the default SIGHASH setting, and includes multiple security and correctness improvements.
Coldcard said the update is intended to reduce the risk of device attacks. The company also said a firmware upgrade does not repair seed phrases that were already generated by affected firmware versions. If a user's mnemonic falls within the scope of the security notice, the recommended process is to update the device first, then generate and verify a completely new mnemonic and move funds to a new wallet.
Coldcard recommended that all Mk4, Mk5, and Q users update their devices promptly and verify the signature of any downloaded firmware.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.