Coldcard has released a firmware upgrade after a seed-generation flaw exposed some customers to theft. The company urges Mk4, Mk5, and Q users to install firmware 5.6.1. The update changes how devices create, protect, and validate wallet data. Significantly, Coldcard now requires users to add randomness during seed creation.
Users can press keys, roll dice, or flip coins. The device combines that input with hardware entropy and cryptographic protections. However, the company warns that the upgrade cannot protect seeds created through the vulnerable process.
Besides seed generation, the release adds safeguards around transactions and USB connections. The device now performs a PSBT check immediately before signing. Consequently, users receive a warning when a computer changes transaction details after approval.
Furthermore, encrypted sessions now restrict USB transfers to only latest, device-generated results. In addition, Coldcard blocked Delta Mode features that could expose sensitive information from the seed.
Moreover, the firmware improves hardware randomness testing, backup recovery, multisig security, and firmware verification. These changes reduce risks across stages of wallet use.
Coldcard also created a security status page and helps customers move funds from exposed seeds. Authorities continue investigating thefts associated with the earlier vulnerability.
