Coldcard firmware forces 65 keypresses or 50 die rolls

Coldcard firmware released Aug. 20 adds mandatory human entropy-65 key presses, 50 die rolls or 128 coin flips-for new seeds. Seeds from vulnerable releases must be replaced unless 50 private die rolls were used.

Coinkite released updated Coldcard firmware on Aug. 20 that requires users to add physical randomness when creating a new seed: 65 unpredictable key presses, 50 rolls of a six-sided die, or 128 coin flips. The change mixes device entropy with mandatory human input for every new standard seed.

The advisory lists affected firmware ranges. Recommended patched versions are 5.6.1 for Mk4 and Mk5 devices and 1.5.1Q for Q devices. The vendor marks Mk2 and Mk3 firmware 4.0.1 through 4.1.9 as exposed, Mk4 and Mk5 standard firmware before 5.6.0 and Edge firmware before 6.6.0X as exposed, and Q standard firmware before 1.5.0Q and Edge firmware before 6.6.0QX as exposed. An independent technical analysis identifies a broader boundary that includes Mk2 and Mk3 version 4.0.0; owners of that release are advised to treat their seeds as potentially exposed.

The defect can route random-number requests to a deterministic MicroPython fallback because a feature flag set to zero was treated as present. That can make the device’s randomness path predictable. The updated firmware’s required human input reduces reliance on the device RNG for seeds created after the update, but it does not change or add entropy to seeds created earlier under the vulnerable code path.

The advisory instructs affected users who did not perform at least 50 fair, independent and private die rolls during original seed creation to generate a new seed and move funds. It advises users to “generate a genuinely new seed, verify its backup and wallet fingerprint, confirm a receiving address on the device, send a small test transaction, and then transfer every balance tied to the old seed.” Restoring or cloning a wallet does not create a new seed.

The firmware also adds multiple signing and integrity protections. Changes include binding USB review to a staged PSBT checksum, rechecking transaction bytes before signing, disabling SIGHASH_SINGLE modes by default, limiting USB downloads to the current encrypted-session result, validating firmware file length, adding persistent stops when the RNG fails, a boot-time hardware-RNG linkage check, expanded isolation for Delta Mode, and changes to active-wallet backup behavior. Coldcard treats the mixed human-plus-hardware randomness flow differently from the Dice Rolls Only option, which excludes hardware randomness and requires 50 rolls for a 12-word seed or 99 rolls for a 24-word seed.

Coinkite reports that some customers suffered severe losses and that law enforcement is investigating; the company has not published a verified victim count or total loss figure. Owners should verify device firmware versions against the advisory and migrate funds to a newly generated seed on patched firmware if they cannot confirm meeting the private 50-roll condition.

Articles by this author