Coinkite has rolled out a broad security update for its Coldcard hardware wallets after identifying a seed-generation flaw that it says enabled attackers to steal more than $100 million in Bitcoin.

The company is urging users of Coldcard Mk4, Mk5, and Q devices to install firmware version 5.6.1 or 1.5.1Q. It also said customers whose wallet seeds were created on affected software between 2021 and July 2026 should generate a new seed on the updated firmware and transfer their Bitcoin to fresh wallets.

Upgrade follows review of wallet systems

The new release comes after what Coinkite described as a three-week review of Coldcard systems. According to the company, that process included external security researchers as well as AI models.

Coinkite said its investigation into the thefts is still underway. It added that affected customers are continuing to move funds and that law enforcement authorities are also investigating the thefts.

Firmware update changes several security controls

The overhaul addresses multiple parts of the Coldcard software stack. Coinkite said the update fixes issues related to transaction signing, USB data handling, firmware validation, Delta Mode, and wallet backups.

The company also changed how backup randomness is handled, replacing the Yasmarang backup generator with SHA-256 Hash_DRBG. In addition, new checks were introduced to detect failures in the hardware random number generator.

New seed creation now requires user-supplied entropy

One of the biggest changes affects how new wallet seeds are created. Under the updated firmware, users must now contribute their own randomness during seed generation instead of relying only on the device.

Coinkite said the process requires at least 65 key presses, 50 dice rolls, or 128 coin flips. The wallet combines that user-supplied entropy with its own internal randomness when creating the seed.

Affected users are being told to replace old seeds

Coinkite said anyone who generated a seed on affected firmware versions between 2021 and July 2026 needs to treat that seed as no longer safe. The company’s guidance is to create a new seed using the latest firmware and then move any Bitcoin held under the old seed to the newly created wallet.

The company said it will continue helping customers migrate to new wallets while the broader investigation continues. For now, the next confirmed step for users on the listed devices is to install the updated firmware and replace any seed created during the affected period.

Source: decrypt.co