Coinkite has rolled out a major security firmware upgrade for its Coldcard hardware wallets, aiming to harden seed phrase generation against a class of failures that can leave private keys more guessable than they should be. The company says the updatesโColdcard firmware 5.6.1 for Mk4 and Mk5 and 1.5.1Q for the Coldcard Qโchange how new wallet seeds are created by requiring user-supplied entropy and combining it with multiple onboard sources of randomness.
The move comes as confirmed losses from the Coldcard exploit continue to be tallied. According to an Aug. 14 report by Galaxy Research, confirmed theft reached 1,778 BTC (about $112 million). Galaxyโs reporting also places the incident among the yearโs largest crypto hacks, with DefiLlamaโs aggregated data ranking it as the third-largest exploit of 2026.
Key takeaways
- Coinkiteโs firmware updates require new seed phrases to include user-supplied entropy collected through interactive user actions.
- Coinkite says the collected entropy is mixed with device randomness from secure elements and the hardware RNG to reduce the impact of any single randomness failure.
- Users are instructed to upgrade immediately, but must also replace existing seed phrases before migrating funds, because old seeds are still considered vulnerable.
- The update adds additional protections around USB data handling and transaction signing by re-verifying transactions immediately before signing.
- As the ecosystem responds to โweak seedโ risks, Coinspect has launched a free tool intended to detect addresses generated from known weak seed phrase datasets.
User entropy becomes a required ingredient for new seeds
The most significant change in Coinkiteโs release is in the mechanics of seed phrase generation. The firmware requires that newly generated seeds incorporate user-supplied entropy through at least 65 keypresses with deliberately unpredictable timing, plus one of two additional interaction-based inputs: 50 rolls of a six-sided die or 128 coin flips. The company pairs this user input with randomness sourced from multiple hardware components, including secure elements and the walletโs hardware random-number generator (RNG).
Coinkiteโs stated goal is straightforward: even if one entropy source fails or behaves unexpectedly, the seed creation process should still produce private keys that remain hard to predict. That โdefense in depthโ matters for users because seed phrases are the single critical root of control in Bitcoin self-custodyโif their generation is weakened, an attacker may be able to brute-force likely keys rather than needing to break cryptography.
Importantly, Coinkite stresses that upgrading the firmware does not automatically immunize existing wallets. The company told users that previously generated seed phrases remain vulnerable after the update and must be replaced with new seeds before any funds are migrated. In practice, this means the security benefit applies to future seed creation, not past ones.
Seed protection continues after a prior fix
The Thursday release follows a broader security review and extends protections that were already introduced in a July 31 firmware update. Coinkite previously said that update addressed the seed-generation failure for wallets created after that point. The new 5.6.1 and 1.5.1Q releases build on that foundation by strengthening how entropy is gathered and validated, and by adding safeguards beyond seed generation alone.
Coinkite also characterizes the new approach as closing a theoretical gap involving a compromised computer USB port. Rather than assuming the external host is trustworthyโor assuming that checks performed earlier in a workflow are sufficientโthe firmware is designed to re-verify transactions immediately before signing. This reduces the chance that altered transaction data could survive earlier checks and make it onto the signing path.
Additional enhancements include hardware RNG checks and a boot-time test intended to confirm that the wallet is using the intended hardware randomness path. Coinkite further restricts how USB transfers occur by limiting downloads to the deviceโs most recent output and requiring an encrypted session.
Finally, certain Bitcoin signature hash modes that can allow transaction outputs to be modified are now blocked by default, tightening the rules around which transaction forms the device will sign.
Coldcard losses remain material while upgrades roll out
Even as Coinkite issues new defenses, the fallout from the Coldcard exploit continues to be quantified. Galaxy Researchโs Aug. 14 report, cited in the coverage of this firmware update, put confirmed losses at 1,778 BTC (about $112 million). The same reporting context notes the incidentโs scale relative to other 2026 hacks, using DefiLlamaโs aggregated exploit rankings.
For users, the critical implication is that remediation must be more than โpatch and hope.โ The requirement to generate new seed phrases underscores that the security model is tied to how a wallet was originally initialized. In other words, if a wallet was created under weaker randomness assumptions, the safest path is typically to replace the root of control rather than rely on later software fixes.
Given the confirmed-loss magnitude, these upgrades also carry practical urgency for anyone who used affected wallets and has not yet assessed whether their seed phrase was produced under the vulnerable conditions. The firmware update provides a clearer security story for new wallet initialization, but it does not undo exposure retroactively.
Software tools emerge to identify weak-seed exposure
Alongside firmware changes, the security ecosystem is increasingly focused on detection. Coinspect announced Unlukey, described as a free public tool for identifying wallet addresses generated from weak seed phrases. In a Friday post on X, Coinspect said the initial version aims to reproduce known weak seed generation behavior and then check whether public addresses fall into an affected dataset.
This kind of tooling matters because it moves the conversation from โwhat might be vulnerableโ to โis this specific wallet address likely connected to weak-seed generation.โ While such tools cannot replace operational security measuresโsuch as upgrading, re-seeding, and moving fundsโtheir role is to help users triage and focus on wallets most likely to be impacted.
The broader context for weak-seed risks includes claims from TRM Labs, which stated that a firmware bug from March 2021 weakened seed randomness on some Coldcard wallets. TRM Labs said this reduced key strength from 128 bits to 40 bits, making affected keys โbrute-forceable without physical access.โ Those figures are particularly relevant because they illustrate how far a randomness failure can go beyond a small quality-of-randomness issueโpotentially changing the feasibility of an attackerโs search.
For builders and traders alike, the evolving response highlights a pattern seen across major wallet incidents: security upgrades address the technical causes going forward, while independent detection tools attempt to quantify exposure in the wild. Investors should watch how these tools perform in practiceโespecially whether they gain broader validation and whether they help more users act quickly and correctly.
Next, users running older Coldcard firmware should confirm they are using the latest releases and follow Coinkiteโs guidance on re-seeding before moving funds, while the wider community will likely keep evaluating how detection tools like Unlukey map to real-world exposure. The remaining uncertainty is how comprehensively the weak-seed issue affected wallets in circulationโand whether further forensic work will refine estimates as additional data comes in.






