Coldcard releases new firmware after a three-week security review
Coldcard released firmware 5.6.1 for Mk4 and Mk5 devices, and 1.5.1Q for Q devices, on Aug. 20, according to BlockBeats. The update follows an emergency fix on July 31 and a three-week security review, with the focus on risks tied to a seed-phrase generation attack disclosed earlier.
The company said every newly generated seed phrase must now include at least one source of user entropy. The options include at least 65 irregular key presses, 50 rolls of a physical die, or 128 flips of a physical coin. User input is then combined with fresh entropy from STM32 TRNG, SE1 and SE2.
Firmware changes extend beyond seed generation
Coldcard said the new release also adds just-in-time staged PSBT verification before signing, tightens the USB connection and firmware update boundary, improves Delta Mode isolation, fixes an active wallet backup issue, and strengthens random-number-generator initialization and fault checks. The update also changes the default SIGHASH setting and includes several security and correctness fixes.
The company said the goal is to further reduce the risk of device compromise.
Affected seed phrases cannot be repaired by updating firmware
Coldcard stressed that updating the firmware will not fix seed phrases already generated by affected versions. Users whose seed phrases fall under the security notice should update the device first, then generate and verify a brand-new seed phrase and move funds to a new wallet.
The company also strongly advised all Mk4, Mk5 and Q users to update promptly and verify the signature of the firmware they download.

