COLDCARD released a new security update for the Mk4, Mk5 and Q wallets after reviewing a seed generation flaw exploited in attacks that caused financial losses to customers. The company recommends immediate installation of firmware 5.6.1 on Mk4 and Mk5 models and version 1.5.1Q on the Q.

The update extends the fix released on July 31 and strengthens areas such as seed generation, transaction signing, USB communication and backups.

Seeds created on vulnerable versions between 2021 and July 2026 remain potentially insecure. Updating the firmware does not fix an already affected seed: in these cases, the guidance is to generate a new one on updated firmware and transfer the funds.

New seed generation requires user action

Creating a seed now requires an additional source of entropy provided manually. The user must perform at least 65 key presses, 50 rolls of a physical die, or 128 coin flips.

The firmware combines this input with the device's own sources of randomness and has replaced the auxiliary Yasmarang generator with SHA-256 Hash_DRBG.

Transactions gain new verification

COLDCARD now also re-verifies a PSBT transaction immediately before signing. If the connected computer modifies the data after the review performed on the device, the operation is interrupted.

The update also strengthens USB controls, restricts certain signing modes and adds new checks to the random number generator.

Authorities continue investigating the thefts related to the original flaw. The company says it will continue assisting affected users during the migration to new seeds.

More from Radar