INSIGHTS

Coldcard Firmware Update Adds Dice Rolls, Coin Flips After $114M Seed Failure

Share:

Coinkite’s latest Coldcard firmware update forces every new bitcoin wallet seed to be generated with user-supplied randomness, from dice rolls to coin flips, after a weak-entropy flaw enabled attackers to steal more than $114 million in bitcoin. The August 20, 2026 release closes the vulnerability for future seeds, but Coinkite warns it does nothing to protect keys already created on affected firmware.

What the new Coldcard firmware changes for seed generation

Coinkite published Coldcard firmware 5.6.1 and 1.5.1Q on August 20, 2026, directing Mk4 and Mk5 owners to install version 5.6.1 and Q users to move to 1.5.1Q. The update reworks how the hardware wallet builds fresh keys. For related coverage, see Can Zcash Flip XRP? NYSE ETF Launch Sends Privacy Coin to 8-Year High.

Every newly generated seed now requires at least one user-sourced entropy method: 65 key presses with unpredictable timing, 50 rolls of a physical six-sided die, or 128 physical coin flips. The device will no longer trust its internal randomness alone.

Required entropy option
50
Physical die rolls now qualify as one of the mandatory user-entropy inputs for each new seed.

Coin flips are the highest-count manual option, requiring 128 tosses to seed a new key, while the timed key-press method sits between the two. The requirement applies only to seeds generated after the update, not retroactively to existing wallets.

Alternate entropy path
128
Coin flips are the highest-count manual option in the new seed-generation flow.

Beyond seed generation, the release added transaction re-verification, tighter USB data-handling limits, and hardened firmware-update validation, part of a broader tightening after the incident that already prompted a wider self-custody security overhaul across the hardware-wallet space.

Why updating firmware does not make older Coldcard seeds safe

The most important detail for existing users is also the easiest to miss: installing the update does not repair a vulnerable seed. “Installing this update does not make an existing vulnerable seed safe,” Coinkite wrote in its advisory.

“Installing this update does not make an existing vulnerable seed safe.” — Coinkite

A firmware update is not a seed migration. Anyone who created a wallet on affected firmware must generate an entirely new seed and move their funds to it to be protected.

Coinkite’s advisory says Mk2 and Mk3 firmware versions 4.0.1 through 4.1.9 are affected, while seeds generated on Mk4, Mk5, and Q before their fixed releases were exposed as well. The affected seeds carried roughly 72 bits of entropy instead of the expected 128 bits, a shortfall that made them realistically guessable, which is why regenerating rather than patching is the only fix. That entropy gap is the same defect behind a code bug that went unnoticed for years.

How the $114 million seed failure shaped Coinkite’s response

The randomness flaw was not theoretical. Attackers exploited the predictable seeds to steal more than $114 million in bitcoin before the new firmware shipped, according to CoinDesk, which reported the company credited AI tooling with catching additional bugs during the rush.

The theft has unfolded in waves, escalating from an earlier tranche of roughly 594 BTC worth about $38 million to later rounds that pushed the running total higher, including reports of 1,596 BTC allegedly stolen. Because affected seeds sit far below the security margin of a properly random key, funds remained drainable until owners migrated.

That scale explains why Coinkite pivoted to mandatory user-supplied entropy rather than simply patching its internal generator: forcing dice rolls and coin flips removes any reliance on a single software randomness source that could fail silently again. The official security status page now lists Mk4/Mk5 5.6.1 and Q 1.5.1Q as the recommended standard releases and reiterates that an update is not a migration.

Bitcoin traded near $77,611 as the fixes rolled out, with sentiment holding in “Greed” territory, and community discussion has centered on migration urgency rather than price. Coinkite says law enforcement investigations into the thefts are still ongoing.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.