Coldcard Releases Follow-Up Security Firmware After Seed Generation Flaw

COLDCARD, a hardware wallet that generates Bitcoin private keys offline and signs transactions, released security firmware 5.6.1 for Mk4 and Mk5 and 1.5.1Q for Q on August 20. When creating a new seed, this version requires the user to supply one of the following: at least 65 hard-to-predict key presses, 50 dice rolls, or 128 coin flips, and combines that input with the device's internal randomness. The immediate reason Coldcard tightened its seed generation procedure this way was a large-scale theft on July 30 in which 1,082.65 bitcoin, worth about $70.2 million at the time, was drained from roughly 1,200 Coldcard-related addresses over the course of 41 minutes. Investigation found that a firmware integration error in March 2021 caused new recovery seeds to use a predictable software method instead of the dedicated hardware random number generator, substantially weakening the randomness used to create seeds. If an attacker could narrow down a device's identifying information and the time the seed was generated, they could compute possible seeds without direct physical access to the device and compare them against publicly visible Bitcoin addresses. As additional theft cases were subsequently confirmed, the total confirmed loss for victims that Galaxy Research had verified as of August 14 rose to 1,778 bitcoin (about $112 million). Including candidate cases where victim verification is not yet complete, it estimated that potential losses could reach 2,417 bitcoin (about $151 million). In the cases Galaxy confirmed, no new fund movements were observed after August 6, but this may be because vulnerable users moved their assets or because most of the exploitable funds had already been drained, and not every affected address has been technically matched and confirmed as having a seed generated by this flaw. The manufacturer, Coinkite, first distributed emergency firmware fixing the random number generation flaw on July 31, and the version released on August 20 is a follow-up reinforcement that also makes user-supplied randomness mandatory. The update only protects newly created seeds, however, so existing vulnerable seeds must be replaced and assets moved to a new wallet. External reviewers verified the core fixes in the corrected firmware, including whether the hardware random number generator operates properly and whether the problematic software fallback method has been removed. A comprehensive security audit covering the entire firmware and an official post-mortem report laying out the cause of the incident have not yet been completed.

Metanomia View

Self-custody reduces intermediary risk, but in exchange it shifts responsibility for key generation and firmware verification onto users, manufacturers, and auditors. The problem is that a flaw at the key generation stage cannot be undone by a later update alone. A seed by itself offers little way to confirm whether it was generated with sufficient randomness, so fixing the device does not restore the safety of keys already created: a new seed must be generated and assets moved. Domestic custody and self-custody policy should likewise look beyond product certification and also require verification of random number generation, disclosure of incidents, and procedures for safely migrating existing keys.

Sources