Hardware wallet manufacturer Coldcard has officially released a critical firmware update to address a significant security vulnerability involving seed phrase generation. The new software versions—5.6.1 for Mk4/Mk5 devices and 1.5.1Q for Q-series models—arrive after a three-week intensive review period following an emergency patch issued on July 31st. This update aims to fortify the entropy process used to create private keys, following reports of financial losses linked to a specialized "seed phrase generation attack" that exploited weaknesses in how the devices generated randomness.
Enhanced Entropy Requirements for Secure Key Generation
To mitigate the risk of predictable seed generation, Coldcard has overhauled the technical requirements for creating new wallets. The updated firmware mandates the inclusion of user-provided entropy every time a new seed phrase is produced. This manual input is now combined with existing internal entropy sources, including the STM32 TRNG (True Random Number Generator) and two secure elements, SE1 and SE2. Users must now provide a substantial amount of external randomness through one of the following methods:
- At least 65 unpredictable keystrokes with varying time intervals between each press.
- A minimum of 50 manual dice rolls recorded into the device.
- At least 128 coin flips to ensure maximum cryptographic variance.
By requiring external physical entropy, the manufacturer aims to ensure that even if a hardware-based random number generator were compromised, the resulting seed phrase remains statistically unique and impossible to guess via brute force.
Mandatory Migration for Affected Users
Despite the security enhancements in the new firmware, the manufacturer emphasized that updating the device will not retroactively secure existing seed phrases generated under the vulnerable software versions. Users who created their recovery phrases during the affected period remain at risk unless they perform a manual migration. The company advises a two-step recovery process: first, installing the latest firmware to secure the device environment, and second, generating a completely new seed phrase to which all assets must be transferred.
Updating the firmware will not fix seed phrases already generated on the affected firmware. If this notification applies to a user's seed phrase, they must first update their device, then generate and verify a new seed.
This incident highlights the ongoing challenges in Bitcoin self-custody and the critical importance of robust entropy in the creation of BIP-39 recovery phrases. Coldcard has extended its apologies to those who experienced financial setbacks due to this exploit, reaffirming its commitment to rigorous security audits. For the broader cryptocurrency community, this event serves as a reminder to monitor official manufacturer channels for security advisories and to prioritize hardware wallet updates as part of standard digital asset maintenance.
Frequently Asked Questions
Quick answers to the most common questions about this topic.