Firmware patch enhances Coldcard's seed phrase security mechanisms

Firmware patch enhances Coldcard's seed phrase security mechanisms

Coinkite has instructed Coldcard device owners to create fresh seed phrases, cautioning that previously generated vulnerable seeds continue to pose security risks even after installing the firmware patch.

A new security enhancement has been rolled out by Coinkite to bolster the seed phrase creation process by mandating the inclusion of entropy provided by users, which is then blended with enhanced randomness generated by the device itself.

In a blog post published on Thursday, Coinkite revealed the launch of firmware version 5.6.1 designed for Coldcard Mk4 and Mk5 hardware wallets, alongside version 1.5.1Q specifically for the Coldcard Q model.

Under the new release, any freshly created seeds must incorporate entropy supplied by the user via a minimum of 65 key presses with timing that cannot be predicted, 50 tosses of a standard six-sided die, or 128 flips of a coin. This user-provided input gets merged with randomness gathered from various device sources, which includes its secure element components and the hardware-based random-number generator (RNG) built into the system.

The merged randomness serves as the foundation for generating the wallet's seed phrase and is designed to ensure that its private keys remain unpredictable even in scenarios where one of the device's entropy sources experiences a failure.

Users were urged by Coinkite to install the upgrade without delay, with the company stressing that seed phrases created before the update continue to be vulnerable even following the firmware upgrade and need to be substituted with newly generated seeds prior to transferring any funds.

According to a report published on Aug. 14 by Galaxy Research, verified losses stemming from the Coldcard security breach totaled 1,778 Bitcoin (BTC), representing approximately $112 million in value. Based on information compiled by DefiLlama, this positions the Coldcard security incident as the third-largest cryptocurrency exploit recorded in 2026.

Coldcard adds transaction and USB safeguards

A firmware update released by the company on July 31 had previously resolved the seed-generation vulnerability for wallets created after that date. The release announced on Thursday comes after three weeks spent conducting a more comprehensive security assessment and incorporates additional protective measures related to USB data processing, transaction signing procedures, and hardware-based randomness generation.

According to Coinkite, the update mitigates a theoretical attack scenario involving a USB port on a compromised computer by implementing a re-verification step for transactions right before the signing process occurs. The firmware release also incorporates supplementary hardware RNG validation checks along with a test that runs during boot-up, which is designed to confirm that the wallet is utilizing its designated hardware pathway.

Additional modifications implemented in the update limit USB downloads exclusively to the device's most recently generated output and mandate the use of an encrypted session, while specific Bitcoin signature hash modes that permit transaction outputs to be altered are now disabled by default settings.

Coinspect launches weak-seed detection tool

Additional companies are also rolling out software solutions designed to help identify wallets that may have been compromised due to weak seed generation vulnerabilities.

In a Friday post on X, blockchain security firm Coinspect announced the release of Unlukey, a publicly available free tool created to identify wallet addresses that were generated using weak seed phrases. According to Coinspect's announcement, the initial version of this tool is designed to replicate known instances of weak seed generation and determine whether public addresses are part of the compromised dataset.

One of the primary vulnerabilities that contributed to the Coldcard security breach was weak seed phrase generation. According to TRM Labs, a firmware defect dating back to March 2021 compromised the seed randomness on certain Coldcard wallet devices, diminishing the key strength from 128 bits down to just 40 bits and rendering them "brute-forceable without physical access."

← Zurück zum Blog