Follow

Keep Up to Date with the Most Important News

By pressing the Subscribe button, you confirm that you have read and are agreeing to our Privacy Policy and Terms of Use
Subscribe

Coldcard Seed Phrase Vulnerability Drives Back-to-Back Firmware Patches

Coldcard seed phrase vulnerability Coldcard seed phrase vulnerability

The Coldcard seed phrase vulnerability that drained 1,778 BTC (roughly $112 million) from affected wallets has pushed Toronto-based Coinkite through two firmware releases in under a month, with a third set of security hardening now in place across every supported model.

What the Firmware Updates Actually Change

Firmware 5.6.1 (Mk4/Mk5) and 1.5.1Q (Coldcard Q), announced in a Thursday blog post, made user-supplied entropy mandatory for all newly generated seeds: at least 65 keypresses with unpredictable timing, 50 die rolls, or 128 coin flips. That input is folded into randomness drawn from the device’s secure elements and hardware RNG, so the seed remains unpredictable even if one source is compromised.

The release also re-verifies transactions immediately before signing to address a theoretical attack via a compromised USB port, adds boot-time hardware RNG checks, restricts USB downloads to the device’s most recent output behind an encrypted session, and blocks by default certain Bitcoin signature hash modes that leave transaction outputs modifiable.

A further update followed quickly. According to Coinkite’s firmware 5.6.2 release notes, the subsequent build restores visibility into the device-generated entropy used during seed creation and adds a standalone tool for independently verifying dice-roll or coin-flip mixing. Version 5.6.2 is now the standard recommended release for Mk4/Mk5; 1.5.2Q serves the same role for the Q. The official firmware downloads page lists the final supported versions for older hardware as 4.2.0 for Mk2/Mk3 and 3.0.6 for Mk1.

One point Coinkite has repeated across every release: upgrading firmware does not repair an existing affected seed. The Coldcard security status page confirms that patched releases are available for every supported model but that any wallet seeded on vulnerable firmware needs to be migrated to a fresh seed on patched firmware before the old funds can be considered safe.

The Attack That Made the Coldcard Seed Phrase Vulnerability Impossible to Ignore

The underlying flaw traces to a firmware integration error from March 2021. TRM Labs established that the bug reduced seed entropy from 128 bits to 40 bits, making keys brute-forceable without physical access to the device. Models affected span MK2 through MK5 and the Q, according to Kaseya’s security roundup.

The exploit played out in identifiable waves. According to The Hacker News, the initial sweep on 30 July drained 1,082.65 BTC (approximately $70.2 million at the time) from 1,196 addresses in 41 minutes. Galaxy Research subsequently identified two additional waves, raising its observed total at that point to 1,367.05 BTC worth about $88.6 million across 4,585 addresses. Galaxy also reported roughly 600 suspected attacker-controlled addresses to federal investigators and compliance firms.

A third wave followed. CoinDesk reported that approximately 208 BTC were drained from 1,912 addresses between Friday midday and Saturday morning UTC on 1-2 August, averaging just over 0.1 BTC per victim, a sharp step down from the opening wave’s average of close to one full coin per address. Galaxy Research believes each wave is the work of a single operator but cannot determine whether the same attacker is behind all three.

By Galaxy Research’s 14 August tally, confirmed losses stood at 1,778 BTC, making this the third-largest crypto exploit of 2026 by DefiLlama’s aggregated data.

Coinspect Releases an Open Detection Tool

Blockchain security firm Coinspect has released Unlukey, a free tool for checking whether wallet addresses were generated from weak seeds. Accessible at illbloom.org, the tool accepts Bitcoin, Tron, Solana, and Ethereum-compatible addresses (including Polygon, BNB Chain, and other EVM chains), according to The Hacker News. The project is described by Coinspect’s security blog as collaborative research into weak wallet-generation vulnerabilities; the name ‘Ill Bloom’ derives from ‘illness blossom,’ the first phrase the weak generator produces, mirroring how the 2023 Libbitcoin Explorer flaw was named ‘Milk Sad.’

The tool’s first iteration reproduces known weak seed-generation patterns and checks whether submitted addresses fall within the affected dataset. It does not recover keys or move funds.

For anyone still running pre-5.6.0 firmware on a supported device, the decision tree is short: patch, generate a new seed under the updated firmware, migrate funds, and then verify the old address against Coinspect’s tool to confirm exposure. Every day a legacy seed sits funded is a day it sits within a brute-forceable keyspace.

Keep Up to Date with the Most Important News

By pressing the Subscribe button, you confirm that you have read and are agreeing to our Privacy Policy and Terms of Use