ADVERTISEMENT
LIVE DESK·Global markets desk·Last updated 14s ago
ADVERTISEMENT
Markets/CryptoArticle

Coldcard tightens seed generation with firmware upgrade after $112M hack

Coinkite’s latest firmware update requires user-supplied entropy to strengthen seed phrase generation on Coldcard devices, following a $112 million exploit in August.

MW
Marcus Webb · Crypto Desk · 22 Aug 2026 · 04:53 · 2 min read
Share
Coldcard tightens seed generation with firmware upgrade after $112M hack

Coinkite has released firmware updates for its Coldcard hardware wallets to address vulnerabilities in seed phrase generation exposed by a $112 million exploit in August.

The upgrade, version 5.6.1 for Coldcard Mk4 and Mk5 devices and 1.5.1Q for the Coldcard Q, mandates that new seeds incorporate user-supplied entropy alongside device-generated randomness. Users must provide input through at least 65 keypresses, 50 die rolls, or 128 coin flips, which is then combined with randomness from the device’s secure elements and hardware random-number generator (RNG). The combined entropy is used to create wallet seeds, ensuring private keys remain unpredictable even if one entropy source fails.

Coinkite urged immediate upgrades, noting that existing seed phrases remain vulnerable and must be replaced before migrating funds. The exploit, disclosed in an Aug. 14 Galaxy Research report, resulted in confirmed losses of 1,778 Bitcoin (BTC), marking the third-largest cryptocurrency hack of 2026, according to DefiLlama data.

Bitcoin

BTCUSD
Full profile →
77360.8700▼ 1.25%
As of 22/08/2026, 00:00:00

The July 31 firmware update had already addressed seed-generation failures for newly created wallets. The latest release follows a three-week security review and introduces additional safeguards, including transaction and USB protections. A compromised USB port attack vector is mitigated by re-verifying transactions immediately before signing. The firmware also adds hardware RNG checks, a boot-time test to confirm proper hardware path usage, and restricts USB downloads to the device’s most recent output while requiring encrypted sessions.

Default settings now block certain Bitcoin signature hash modes that allow transaction outputs to remain modifiable.

In parallel, blockchain security firm Coinspect launched Unlukey, a free tool to detect wallets generated from weak seed phrases. The tool checks public addresses against a dataset of known weak seeds, with the initial version targeting seed-generation flaws linked to the Coldcard exploit. A March 2021 firmware bug had reduced key strength from 128 bits to 40 bits on some wallets, making them vulnerable to brute-force attacks without physical access, according to TRM Labs.

This article was produced with AI assistance and edited by a Finance Review Daily journalist.
ADVERTISEMENT
Novara — A Smarter Way to Access Global Markets
Share this story
MW
Written by
Marcus Webb
Crypto Desk

Marcus reports on digital assets, from spot ETF flows to protocol-level developments in DeFi. He pays particular attention to how institutional adoption is reshaping crypto market structure.

More from Marcus Webb →
ADVERTISEMENT
ADVERTISEMENT