Coldcard now requires 65 key presses after seed exploit, while exposed funds still must move
核心要点
- Affected users should create a new seed and migrate funds unless they meet the private 50-roll exception.

Coldcard now requires 65 key presses after seed exploit, while exposed funds still must move
Firmware 5.6.1 and 1.5.1Q harden new wallet creation but cannot repair a seed made on an affected release.
Quick Take
01 Coldcard now requires 65 key presses, 50 die rolls, or 128 coin flips for new seeds.
02 Seeds created on affected firmware may remain exposed; installing a fix cannot repair them.
03 Affected users should create a new seed and migrate funds unless they meet the private 50-roll exception.
Coinkite , the maker of the Coldcard Bitcoin hardware wallet, released new standard firmware on Aug. 20 that forces users to add physical randomness whenever they generate a seed.
Owners who generate a seed after installing the current fixed release can use the hardened process. Owners still relying on a seed produced by affected firmware must generate another seed and transfer the funds unless that wallet meets the dice-roll exception.
During standard seed creation, every seed combines fresh device entropy with one required human input source: at least 65 key presses made at unpredictable intervals, 50 rolls of a physical six-sided die, or 128 physical coin flips. The requirement reduces reliance on the wallet's random-number generator alone.
Coldcard's current security status recommends version 5.6.1 for Mk4 and Mk5 devices and 1.5.1Q for Q devices. The advisory's exposure list is wider and track-specific. Coinkite's official migration guidance covers Mk2 and Mk3 firmware 4.0.1 through 4.1.9; Mk4 and Mk5 standard firmware before 5.6.0 and Edge firmware before 6.6.0X; and Q standard firmware before 1.5.0Q and Edge firmware before 6.6.0QX.
Block's independent technical analysis uses a broader Mk2 and Mk3 boundary that includes version 4.0.0. Owners of that release should not treat the vendor boundary as proof of safety.
A flaw in Coldcard seed generation lets attackers recreate private keys from the press of a button
Installing fixed firmware does not change an old seed. Unless the advisory's dice exception applies, Coinkite's migration guide tells affected users to generate a genuinely new seed, verify its backup and wallet fingerprint, confirm a receiving address on the device, send a small test transaction, and then transfer every balance tied to the old seed. Cloning or restoring the wallet does not create a new seed.
The signal, before the noise.
Start your day with the crypto stories moving markets, decoded by CryptoSlate’s editors.
Weekday mornings
5-minute read
One email. Everything that matters.
Free to join. Unsubscribe any time.
Migration is not required for this RNG flaw when the user added at least 50 fair, independent and private physical die rolls through the affected workflow and never recorded or exposed the sequence. Fewer rolls, or uncertainty about those conditions, means the user should migrate.
Block traced the original defect to code that could route requests to a deterministic MicroPython fallback because a feature flag defined as zero was treated as present. Mandatory human input adds outside entropy to new standard seeds, limiting damage if device randomness fails again. It cannot retroactively add entropy to a seed that already exists.
Coldcard treats the mixed flow differently from the advanced Dice Rolls Only option. That mode excludes hardware randomness and requires 50 rolls for a 12-word seed or 99 for a 24-word seed.
The firmware package reaches signing and data paths too. It binds USB review to a staged PSBT checksum, rechecks transaction bytes before signing, blocks SIGHASH_SINGLE modes by default, restricts USB downloads to the current encrypted-session result, and validates firmware file length. It adds persistent RNG-fault stops, a boot-time hardware-RNG linkage check, more Delta Mode isolation, and active-wallet backup behavior.
CryptoBandits malware lets criminals use your USB drive to access crypto wallets – Microsoft warns
The status page lists targeted source review, a real-device RNG-path test, and a reproducible build and dice-path trace , but Coldcard says they do not amount to a full audit of every fixed binary. Coinkite says some customers suffered severe losses and law enforcement is investigating, but it has not published a verified victim count or loss total.
Bitcoin
Bitcoin is -2.35% over the past 24 hours and currently sits at rank # 1 by market cap.
Mentioned in this article
Editorial credits
Also known as "Akiba," Liam Wright is a reporter, podcast producer, and Editor-in-Chief at CryptoSlate. He believes that decentralized technology has the potential to make…
Related coverage
Reaching instant 27ms validation on Bitcoin will take 17 GPU years of compute power
More coverage
Attackers drove 63% of early use of Ethereum’s new smart wallet feature
Bitcoin crash forced Riot to pledge 1,825 BTC, but this huge rally may now free up 1,500 BTC
Bitcoin hits $80,000’s doorstep just as the ETF bid disappears for the weekend
CryptoSlate may use AI tools to support research, editing, and production workflows. Our journalism remains human-led, with our editorial team responsible for every published article. Read our full AI usage disclaimer .
Our writers' opinions are solely their own and do not reflect the opinion of CryptoSlate. None of the information you read on CryptoSlate should be taken as investment advice, nor does CryptoSlate endorse any project that may be mentioned or linked to in this article.
Buying and trading cryptocurrencies should be considered a high-risk activity. Please do your own due diligence before taking any action related to content within this article. Finally, CryptoSlate takes no responsibility should you lose money trading cryptocurrencies. For more information, see our company disclaimers .
Follow the signal
