Coinkite has released firmware updates for its Coldcard hardware wallets to address vulnerabilities in seed phrase generation exposed by a $112 million exploit in August.
The upgrade, version 5.6.1 for Coldcard Mk4 and Mk5 devices and 1.5.1Q for the Coldcard Q, mandates that new seeds incorporate user-supplied entropy alongside device-generated randomness. Users must provide input through at least 65 keypresses, 50 die rolls, or 128 coin flips, which is then combined with randomness from the device’s secure elements and hardware random-number generator (RNG). The combined entropy is used to create wallet seeds, ensuring private keys remain unpredictable even if one entropy source fails.
Coinkite urged immediate upgrades, noting that existing seed phrases remain vulnerable and must be replaced before migrating funds. The exploit, disclosed in an Aug. 14 Galaxy Research report, resulted in confirmed losses of 1,778 Bitcoin (BTC), marking the third-largest cryptocurrency hack of 2026, according to DefiLlama data.
The July 31 firmware update had already addressed seed-generation failures for newly created wallets. The latest release follows a three-week security review and introduces additional safeguards, including transaction and USB protections. A compromised USB port attack vector is mitigated by re-verifying transactions immediately before signing. The firmware also adds hardware RNG checks, a boot-time test to confirm proper hardware path usage, and restricts USB downloads to the device’s most recent output while requiring encrypted sessions.
Default settings now block certain Bitcoin signature hash modes that allow transaction outputs to remain modifiable.
In parallel, blockchain security firm Coinspect launched Unlukey, a free tool to detect wallets generated from weak seed phrases. The tool checks public addresses against a dataset of known weak seeds, with the initial version targeting seed-generation flaws linked to the Coldcard exploit. A March 2021 firmware bug had reduced key strength from 128 bits to 40 bits on some wallets, making them vulnerable to brute-force attacks without physical access, according to TRM Labs.












