Cryptelio

Coinkite Releases Critical Firmware Update for COLDCARD After Major Bitcoin Theft

Cryptelio Editorial Published 21 Aug 2026 · 17:01 UTC
Coinkite Releases Critical Firmware Update for COLDCARD After Major Bitcoin Theft

Coinkite, the Canadian firm behind the COLDCARD hardware wallet, has released firmware version 5.6.1 for its Mk4 and Mk5 devices, along with version 1.5.1Q for its Q-series models. This update comes in the wake of a serious security vulnerability that allowed attackers to exploit a seed-generation flaw, leading to the theft of approximately 1,816 BTC, worth around $114M to $116M.

The vulnerability had existed since firmware version 4.0.1, released in March 2021, and affected a range of COLDCARD models, including Mk2, Mk3, Mk4, Mk5, and Q devices. The flaw stemmed from a defect in the true random number generator (TRNG) used for seed generation, which significantly reduced the randomness and predictability of generated seeds.

Attackers began exploiting this weakness on July 30, 2026, prompting Coinkite to issue an urgent hotfix the following day. Despite this quick response, the damage was already extensive. The new firmware mandates that users contribute their own physical randomness during seed generation, such as rolling dice or performing timed keypresses, to enhance security.

In addition to the seed generation improvements, the firmware updates also address bugs related to transaction signing and backup procedures. Coinkite has advised users who may have generated seeds on vulnerable firmware versions to create new wallets and transfer their funds. Users are also encouraged to utilize passphrase-protected wallets for added security.

Those using COLDCARD Mk4 or Mk5 devices should update to firmware 5.6.1 immediately, while Q-series owners should install version 1.5.1Q. Anyone who generated a seed on firmware 4.0.1 or later prior to the July 31 hotfix should consider their current seed potentially compromised and follow Coinkite’s migration guidance.

FAQ

What is the latest firmware version released for COLDCARD devices?

Coinkite has released firmware version 5.6.1 for Mk4 and Mk5 devices, and version 1.5.1Q for Q-series models.

What security vulnerability was addressed in the recent firmware update?

The update addresses a critical vulnerability in the true random number generator (TRNG) used for seed generation, which allowed attackers to exploit a seed-generation flaw, leading to the theft of approximately 1,816 BTC.

What should users do if they generated seeds on vulnerable firmware versions?

Users who generated seeds on vulnerable firmware versions should create new wallets and transfer their funds, as their current seed may be compromised.

How does the new firmware enhance seed generation security?

The new firmware requires users to contribute their own physical randomness during seed generation, such as rolling dice or performing timed keypresses, to improve security.

Which COLDCARD devices are affected by the vulnerability?

The vulnerability affected a range of COLDCARD models, including Mk2, Mk3, Mk4, Mk5, and Q devices, particularly those using firmware version 4.0.1 or later prior to the July 31 hotfix.

Related

Comments

Comments are moderated before publish.

No comments yet — be the first.

Comment as guest

Captcha