COLDCARD releases major security update after seed-generation hack

COLDCARD releases major security update after seed-generation hack

The team has changed how backups and passphrase wallets are handled and strengthened multisig and firmware-update validation.

Coldcard has issued a sweeping security update three weeks after disclosing a seed-generation vulnerability that was exploited in an attack against customers.

The company is urging users of its Mk4, Mk5 and Q devices to install firmware 5.6.1, which adds stronger seed-generation protections, transaction-integrity checks and tighter USB data controls.

The new seed-generation system introduces mandatory user-provided randomness, with users choosing between unpredictable key presses, physical dice rolls or coin flips. That input is combined with fresh entropy from multiple hardware sources and processed using updated cryptographic safeguards.

Advertisement

Coldcard warns that these changes only protect newly generated seeds and do not repair an existing vulnerable seed.

Beyond seed generation, the update focuses on transaction integrity and data isolation.

The device now checks a PSBT again immediately before signing and displays “Transaction modified” if a host computer changes the transaction after approval. USB data transfers have been restricted to recent device-generated results and require encrypted sessions, while several Delta Mode functions that could expose seed-derived information have been blocked.

The release also strengthens hardware RNG self-testing, backup and restore procedures, multisig protections, firmware validation and several other wallet functions.

Coldcard has launched a public security status page and continues to support customers migrating funds from potentially compromised seeds, while authorities investigate thefts linked to the original vulnerability.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.
COLDCARD releases major security update after seed-generation hack
COLDCARD releases major security update after seed-generation hack

The team has changed how backups and passphrase wallets are handled and strengthened multisig and firmware-update validation.

Share

Add us on Google

Coldcard has issued a sweeping security update three weeks after disclosing a seed-generation vulnerability that was exploited in an attack against customers.

The company is urging users of its Mk4, Mk5 and Q devices to install firmware 5.6.1, which adds stronger seed-generation protections, transaction-integrity checks and tighter USB data controls.

The new seed-generation system introduces mandatory user-provided randomness, with users choosing between unpredictable key presses, physical dice rolls or coin flips. That input is combined with fresh entropy from multiple hardware sources and processed using updated cryptographic safeguards.

Advertisement

Coldcard warns that these changes only protect newly generated seeds and do not repair an existing vulnerable seed.

Beyond seed generation, the update focuses on transaction integrity and data isolation.

The device now checks a PSBT again immediately before signing and displays “Transaction modified” if a host computer changes the transaction after approval. USB data transfers have been restricted to recent device-generated results and require encrypted sessions, while several Delta Mode functions that could expose seed-derived information have been blocked.

The release also strengthens hardware RNG self-testing, backup and restore procedures, multisig protections, firmware validation and several other wallet functions.

Coldcard has launched a public security status page and continues to support customers migrating funds from potentially compromised seeds, while authorities investigate thefts linked to the original vulnerability.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.