Coldcard Releases New Firmware to Enhance Security; Affected Users Must Regenerate Seed Phrases and Migrate Assets
Coldcard has released the latest firmware versions 5.6.1 (Mk4/Mk5) and 1.5.1Q (Q). This update follows a three-week security review after an urgent fix, primarily addressing security risks from…
Coldcard has released the latest firmware versions 5.6.1 (Mk4/Mk5) and 1.5.1Q (Q). This update follows a three-week security review after an urgent fix, primarily addressing security risks from a previous seed phrase generation attack. Each newly generated seed phrase must now incorporate at least one user entropy source, including at least 65 irregular keystrokes, 50 physical dice rolls, or 128 physical coin flips, combined with fresh entropy provided by the STM32 TRNG, SE1, and SE2.
The new firmware also adds immediate staged PSBT verification before signing, strengthens USB connection and firmware update boundaries, improves Delta Mode isolation mechanisms, fixes active wallet backup issues, enhances random number generator initialization and fault checks, adjusts SIGHASH default settings, and includes multiple security and correctness improvements. Coldcard stated that this update aims to further reduce the risk of device attacks.
Officially, updating the firmware cannot fix existing seed phrases generated by previously affected firmware. If users' seed phrases fall within the scope of this security advisory, they should first update the device, then generate and verify a completely new seed phrase, and migrate funds to the new wallet. Coldcard recommends that all Mk4, Mk5, and Q users promptly update their devices and verify the signatures of downloaded firmware.
insigtX content is informational and educational, not investment advice.