Coinkite, the Canadian firm behind the Coldcard Bitcoin hardware wallet, has rolled out a significant firmware upgrade in the wake of a major security incident that saw substantial amounts of Bitcoin drained from affected devices.
The company is urging owners to act promptly, highlighting that the underlying exploit linked to compromised wallets continues to pose risks.
The update, version 5.6.1 for Mk4 and Mk5 models and 1.5.1Q for the Q series, arrives after an intensive three-week examination of the entire system following an emergency patch in late July.
That earlier flaw stemmed from a long-standing issue in how certain devices generated wallet seeds, reducing the effective randomness far below intended levels and allowing attackers to reconstruct private keys offline without physical access to the hardware.
Losses from the resulting thefts have been estimated by independent trackers in the range of well over $100 million in Bitcoin across thousands of addresses.
According to Coinkite, the comprehensive review process incorporated assistance from advanced AI systems, including the Kimi model and other leading frontier models.
These tools helped scrutinize not only the original randomness-generation pathway but the broader codebase and related functions.
The effort uncovered additional potential issues that were unrelated to the primary seed-generation defect.
These included matters around how transactions are reviewed and approved, the handling of data over USB connections, validation of firmware updates, isolation features in specialized modes, and processes for wallet backups.In response, the new firmware introduces multiple layers of hardening.
New seed creation now mandates user-contributed physical randomness—such as a minimum of 65 timed key presses, 50 dice rolls, or 128 coin flips—which is then combined with entropy from the device’s secure elements and hardware random number generator.
The backup pseudorandom generator has been replaced with a more robust SHA-256-based design, and additional checks verify the integrity of the hardware randomness pathway at boot and during operation.
Transaction signing now includes an immediate re-verification step to detect any post-review modifications, certain advanced sighash modes are restricted by default, USB data access is more tightly bounded, and Delta Mode has received further isolation improvements.
Critically, Coinkite emphasizes that installing the update alone does not secure any wallet whose seed was generated on vulnerable firmware between 2021 and July 2026.
Users in that category must create an entirely new seed on the updated device and carefully transfer their Bitcoin to the new wallet.
The company has repeatedly stressed the urgency of this migration, noting that the active exploitation of weak seeds appears to remain an ongoing concern for those who have not yet moved their funds.
Law enforcement continues to investigate the thefts, and Coinkite has stated it stands ready to assist authorities while supporting affected customers through the migration process.
The firm has also launched a public security status page to provide clear guidance on fixed releases and recommended steps.
This episode underscores evolving challenges in hardware wallet security, particularly as AI tools accelerate both the discovery of latent flaws in open-source code and the defensive review of complex systems. Coldcard users are directed to download firmware exclusively from official channels, verify signatures, and follow migration instructions carefully to protect their holdings.