Community Trust ScoreVerified
Coinkite wants every Coldcard user to ditch their old seed phrase. Not update it. Replace it entirely.
The company pushed out firmware version 5.6.1 for Coldcard Mk4 and Mk5 devices, plus version 1.5.1Q for the Coldcard Q. But here’s the thing — the update alone isn’t enough. Coinkite is pretty explicit: pre-existing seed phrases remain unsafe even after users install the new firmware. Old seeds have to go. The vulnerability that gutted 1,778 BTC — roughly $112 million at the time — was baked into how seeds were originally generated, and no firmware patch can retroactively fix a compromised key. That money is gone. The question now is whether the rest of Coldcard’s user base acts fast enough to avoid the same fate.
What the New Firmware Actually Does
Generating a fresh seed under the new firmware isn’t a one-click process. Users have to supply their own entropy — 65 keypresses with random timing, or 50 dice rolls, or 128 coin flips. That user-generated randomness then gets mixed with multiple device-level sources: secure elements, hardware RNG, and other internal randomness pools. The goal is simple. Even if one source fails or gets compromised, the private key stays unpredictable.
The update also tightens a lot of other things. USB data handling got reworked — downloads are now restricted to recent outputs only, and encrypted sessions are required. Certain Bitcoin signature hash modes, the kind that allow transaction output modifications, are blocked by default. And the firmware now re-verifies transactions immediately before signing, which is a direct response to a theoretical attack scenario involving compromised computer USB ports. If a port has been tampered with, the re-verification step is supposed to catch any unauthorized changes before they go through.
There are also new hardware RNG checks and a boot-time test. That test verifies the wallet is running along its intended hardware path from startup — basically a sanity check that the device hasn’t been messed with at a fundamental level.
A $112 Million Exploit Ranked Third-Largest of 2026
The 1,778 BTC loss ranks as the third-largest cryptocurrency exploit of 2026. That’s a brutal number, and it puts Coldcard in uncomfortable company. The root cause, per TRM Labs, was a firmware bug dating back to March 2021. That bug weakened seed randomness significantly, leaving some wallets vulnerable to brute-force attacks — and critically, attackers didn’t need physical access to the device. They could work remotely. The July firmware update had already addressed seed-generation problems for new wallets, but the August release followed further security reviews that turned up additional gaps.
It’s worth sitting with that timeline for a second. The bug apparently sat in the codebase from March 2021. Years passed. Wallets were created. Bitcoin was stored. And then it wasn’t.
Coinspect’s Free Detection Tool
Coinkite isn’t the only one moving. Blockchain security firm Coinspect launched a free tool called Unlukey, built specifically to identify wallet addresses created from weak seed phrases. The way it works: Unlukey tries to replicate known vulnerabilities in seed generation, then checks whether public addresses fall into the compromised dataset. If your address shows up, your wallet is probably at risk.
It’s a smart move. Not everyone can assess their own exposure, and a free tool lowers the barrier considerably. Whether enough users actually run it is another question entirely.
The broader picture here isn’t great for hardware wallet confidence. Coldcard has long been positioned as one of the more security-conscious options in the self-custody space — the kind of device that serious Bitcoin holders reach for precisely because it’s supposed to be harder to crack. A multi-year firmware bug that drained $112 million and ranked among the year’s biggest exploits is a hard thing to spin.
Coinkite’s message is clear enough: generate new seeds, use the new entropy process, don’t assume the firmware update covers everything. And if you’re not sure whether your wallet address is compromised, Coinspect’s Unlukey tool is there.
The 1,778 BTC is gone either way.
Frequently Asked Questions
What firmware versions did Coinkite release after the Coldcard exploit?
Coinkite released firmware version 5.6.1 for Coldcard Mk4 and Mk5 devices and version 1.5.1Q for the Coldcard Q, both requiring users to generate entirely new seed phrases.
How much Bitcoin was lost in the Coldcard exploit?
The Coldcard exploit resulted in the confirmed loss of 1,778 BTC, worth approximately $112 million, making it the third-largest cryptocurrency exploit of 2026.
What is Unlukey and who made it?
Unlukey is a free tool launched by blockchain security firm Coinspect to identify wallet addresses generated from weak seed phrases by replicating known vulnerabilities in seed generation.
Why It Matters
This incident underscores the importance of security in the cryptocurrency space, especially for hardware wallets, which are often perceived as the safest option for storing digital assets. The loss of a significant amount of Bitcoin highlights the potential risks associated with outdated security protocols and seed phrases, potentially shaking user confidence and prompting a broader reevaluation of security practices across the industry. As users are compelled to adopt new seed phrases, this may lead to increased scrutiny on hardware wallet manufacturers and their commitment to safeguarding assets.
