Coldcard firmware update mandates dice rolls or coin flips after seed-generation failure

Coldcard firmware update mandates dice rolls or coin flips after seed-generation failure

N
News Editor
2026-08-24 09:14:47
Coinkite has released new firmware for its Coldcard hardware wallets three weeks after disclosing a seed-generation failure tied to bitcoin thefts exceeding $114 million. The update changes how new wallet seeds are created by requiring user-supplied entropy, either through at least 65 unpredictably timed key presses, 50 rolls of a physical six-sided die, or 128 coin flips. The company also replaced its backup random number generator, moving from Yasmarang to a SHA-256-based design. Coinkite said the review behind the release was assisted by AI tools, including Kimi and other frontier models, and covered the broader system rather than only the randomness bug. That review surfaced additional issues in transaction approval, USB data handling, and firmware update validation. The new firmware now re-checks a staged transaction immediately before signing, and blocks by default signature modes that leave later outputs editable. The company said users who created seeds on affected firmware between 2021 and July 2026 still need to generate a new seed on fixed firmware and move their funds. Installing the update alone does not secure an already compromised wallet. Coinkite also launched a public security status page with fixed-release information and migration guidance, while law enforcement continues to investigate the thefts.

Coinkite released new firmware for its Coldcard hardware wallets on Thursday, three weeks after disclosing a seed-generation failure that allowed attackers to drain more than $114 million in bitcoin.

The Canadian company said the review behind the release was assisted by AI tools, naming Kimi and other frontier models among the systems used to examine the full stack rather than only the faulty randomness path.

New seed creation now requires user-supplied entropy

Under the update, every newly generated seed must include entropy provided by the user. Coinkite said users must complete one of the following:

  • at least 65 key presses with unpredictable timing;
  • 50 rolls of a physical six-sided die; or
  • 128 coin flips.

Coinkite also changed its backup random number generator, replacing the Yasmarang algorithm with one built on SHA-256.

Mk4 and Mk5 owners are advised to install version 5.6.1, while Q owners should install version 1.5.1Q.

The update does not secure already compromised wallets

Coinkite said installing the new firmware does not make an existing compromised wallet safe. Anyone whose seed was created on affected firmware between 2021 and July 2026 still needs to generate a new seed on fixed firmware and move funds to it.

The company added that its July 31 hotfix had already corrected seed generation for newly created seeds. This release, it said, gives affected users a more thoroughly reviewed base for migration.

Review found additional issues beyond the original bug

The broader review identified problems unrelated to the original vulnerability, including the way transactions are approved, how data is handled over USB, and how firmware updates are validated.

With the new release, the device re-verifies a staged transaction immediately before signing. That means a computer compromised at the USB port cannot change a payment after the owner has already approved it on the device screen.

Signature modes that leave later outputs editable are now blocked by default.

Security status page goes live as theft probe continues

Coinkite has launched a public security status page that lists the current fixed-release matrix and migration guidance. The company also said law enforcement is still investigating the thefts and working to identify those responsible.

Bitcoin Red Team cites AI-driven findings after the exploit

Following the Coldcard exploit, volunteer group Bitcoin Red Team, made up of 16 developers working across time zones, said it has used AI tools to file at least 4,900 findings across 390 projects. Those findings include at least 85 critical issues and 635 high-severity issues.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
10

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.