Coinkite launched a brand new safety improve to strengthen seed phrase technology by requiring user-supplied entropy blended with improved gadget randomness.
Coinkite introduced firmware 5.6.1 for Coldcard Mk4 and Mk5 units and 1.5.1Q for the Coldcard Q in a Thursday weblog publish.
The discharge requires newly generated seeds to incorporate user-supplied entropy by way of a minimum of 65 keypresses with unpredictable timing, 50 rolls of a six-sided die or 128 coin flips. That enter is mixed with randomness from a number of gadget sources, together with its safe parts and {hardware} random-number generator (RNG).
The mixed randomness is used to create the pockets’s seed phrase and is meant to maintain its non-public keys unpredictable even when one of many gadget’s entropy sources fails.
Coinkite informed customers to improve instantly, emphasizing that current seed phrases stay susceptible even after upgrading and should be changed with new seeds earlier than migrating funds.
Confirmed losses from the Coldcard exploit reached 1,778 Bitcoin (BTC), price about $112 million, based on an Aug. 14 report by Galaxy Analysis. This makes the Coldcard hack the third-largest cryptocurrency exploit of 2026, based on information aggregated by DefiLlama.
Coldcard provides transaction and USB safeguards
The corporate’s July 31 firmware replace had already mounted the seed-generation failure for newly created wallets. Thursday’s launch follows three weeks of broader safety overview and likewise provides safeguards round USB information dealing with, transaction signing and {hardware} randomness.
Coinkite mentioned the replace addresses a theoretical assault involving a compromised pc USB port by re-verifying transactions instantly earlier than signing. The firmware additionally introduces further {hardware} RNG checks and a boot-time take a look at designed to confirm that the pockets is utilizing its supposed {hardware} path.
Associated: Cybersecurity agency unveils crypto phishing marketing campaign concentrating on 885,000 telephone numbers
Different adjustments prohibit USB downloads to the gadget’s most up-to-date output and require an encrypted session, whereas sure Bitcoin signature hash modes that enable transaction outputs to stay modifiable are actually blocked by default.
Coinspect launches weak-seed detection software
Different corporations are additionally launching software program to determine wallets doubtlessly uncovered by weak seed technology.
Blockchain safety firm Coinspect revealed Unlukey, a free public software for figuring out pockets addresses generated from weak seed phrases. The primary iteration of the software goals to breed recognized weak seed technology and verify whether or not public addresses belong to the affected dataset, Coinspect mentioned in a Friday X publish.
Weak seed phrase technology was one of many foremost vulnerabilities that led to the Coldcard exploit. TRM Labs mentioned {that a} firmware bug from March 2021 weakened seed randomness on some Coldcard wallets, decreasing key power from 128 bits to 40 bits and making them “brute-forceable with out bodily entry.”
Journal: Contained in the ‘pretend police raid’ that pressured a $1M Bitcoin switch


