Coinkite shipped COLDCARD firmware 5.6.1 for Mk4/Mk5 and 1.5.1Q for its Q device on August 20, 2026, forcing every newly generated seed to include user-sourced entropy after a hardware-wallet
Coinkite shipped COLDCARD firmware 5.6.1 for Mk4/Mk5 and 1.5.1Q for its Q device on August 20, 2026, forcing every newly generated seed to include user-sourced entropy after a hardware-wallet exploit that drained roughly $100 million in bitcoin. The Coldcard firmware 5.6.1 release closes the randomness flaw for future seeds, but it does not repair wallets already created on the vulnerable builds.
What changed in Coldcard firmware 5.6.1
TLDR KEYPOINTS
- Coldcard released firmware 5.6.1 (Mk4/Mk5) and 1.5.1Q (Q) on August 20, 2026.
- Every new seed now requires a user-supplied entropy step before it can be created.
- Updating alone does not fix an existing vulnerable seed; affected users must migrate funds.
Coinkite urged Mk4 and Mk5 owners to install 5.6.1 and Q owners to install 1.5.1Q in its security update. The central change is that seed generation is no longer fully device-controlled. For related coverage, see Report Claims $40M in Bitcoin Stolen After 500 Coldcard Wallets Hacked.
User entropy means the device now mixes in randomness that the holder physically supplies, rather than relying only on the wallet's internal generator. New seeds require one method: at least 65 key presses with unpredictable timing, 50 physical six-sided-die rolls, or 128 physical coin flips. The requirement applies to new seed creation only. For related coverage, see Bitcoin.com Wallet Adds TRON Support for Direct Asset Access.
Required User Entropy 65 key presses / 50 six-sided-die rolls / 128 coin flips COLDCARD now requires a user-sourced entropy step for every new seed, replacing fully device-generated seed creation on affected flows.
CoinDesk reported that an AI-assisted review surfaced further fixes beyond the original randomness flaw, spanning transaction approval, USB data handling, and firmware validation. Those broader controls are what separate the recommended 5.6.1 and 1.5.1Q builds from the earlier minimum fixed releases. For related coverage, see Judge Lets FTX Recovery Trust Pursue $1.76B Binance Claim Over 2021 Buyback.
Why the $100 million exploit matters to wallet users
The update follows the largest hardware-wallet exploit of 2026. TRM Labs estimates attackers drained roughly 1,816 BTC across more than 5,200 addresses in four waves beginning July 30, 2026, a haul TRM valued near $116 million.
Coinlive has tracked the fallout as the total climbed, from early reports of $40 million stolen across 500 wallets to a suspected fourth wave putting 449 BTC at risk, before losses crossed the $100 million mark.
Security firmware updates reset trust and operational habits, because holders must now assume a seed born on old firmware is exposed. That reframes the fix from a routine patch into a migration decision before any new seed is set up or backed up.
What users should do before generating a new seed
Coldcard's status page lists Mk4/Mk5 standard 5.6.0 or later and Q standard 1.5.0Q or later as the minimum fixed releases, with 5.6.1 and 1.5.1Q as the current recommended builds. Install the recommended firmware first, before creating any new seed.
During setup, expect and complete the new entropy prompt: the key presses, die rolls, or coin flips the device now demands. Installing the update does not repair a seed created on affected firmware from 2021 through July 2026; those users still need to generate a new seed and migrate funds. After generation, store the new seed backup securely offline.
Bitcoin traded near $77,297, down about 0.14% on the day, as coverage centered on migration and firmware hardening rather than a broad selloff.
Bitcoin Price Context $77,297 The reported firmware response landed with BTC roughly flat on the day, reinforcing that the story is operational and security-focused rather than a broader bitcoin selloff.
Market sentiment stayed firm, with the crypto Fear & Greed Index at 71, a "Greed" reading. Coinkite says law enforcement continues investigating the thefts, leaving migration progress and any recovery of stolen funds as the key items to watch in the coming days.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.
Read original article on coinlive.me