BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up
HomeNewsCoinkite's Coldcard Firmware Forces User-Provided Randomness After RNG Defect

Coinkite’s Coldcard Firmware Forces User-Provided Randomness After RNG Defect

-

Coinkite has released new firmware for its Coldcard hardware wallets that requires users to manually supply at least 50 dice rolls, 128 coin flips, or 65 timed key presses before a new seed is generated. The update follows a defect in the device’s random number generator that left seeds with only 72 bits of entropy instead of the expected 128, enabling attackers to sweep 594.5 BTC from 500 addresses on July 30. The new firmware, version 5.6.1 for Mk4/Mk5 and 1.5.1Q for the Q model, verifies at boot that hardware randomness is used and replaces the flawed MicroPython PRNG with a NIST-approved Hash_DRBG.


Coinkite, the company behind Coldcard, has shipped a firmware update that will not generate a new wallet seed until the owner supplies randomness by hand. At least 50 dice rolls, 128 coin flips, or 65 timed key presses are required, three weeks after a defect in its random number generator opened customer funds to attackers.

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading

Coldcard’s two device lines run separate firmware tracks, so the release carries two numbers, 5.6.1 for the Mk4 and Mk5, and 1.5.1Q for the Q, the larger model with a keyboard and QR scanning. Coinkite stated that the input is added on top of device randomness from the STM32 TRNG and both secure elements.

The failure was traced to a build and link error that left the setting meant to disable the software path without effect, sending the random-number call to MicroPython’s Yasmarang PRNG. Affected seeds carry about 72 bits of entropy instead of the expected 128 bits after 594.5 BTC was swept from 500 addresses on July 30.

Firmware 5.6.1 now verifies at boot that the random-number call reaches the intended hardware path, halting the device if it fails. Coinkite replaced Yasmarang with a SHA-256 Hash_DRBG, specified in NIST SP 800-90A, and seeds it at startup with a full 256-bit digest from both secure elements, which earlier firmware truncated to 32 bits.

Key mashing follows Peter Todd’s push-button RNG design, hashing keypad press timing at CPU-cycle resolution. The first press sets a reference, and each of the 64 gaps that follow is credited with two bits of entropy.

“Installing this update does not make an existing vulnerable seed safe,” Coinkite wrote, directing anyone whose seed may have been generated on affected firmware between 2021 and July 2026 to create a replacement and move their Bitcoin. Mk2 and Mk3 fall outside this release.

A compromised USB host could rewrite a staged transaction after the owner approved it, so the device now rechecks those bytes before signing and stops with a “Transaction modified” warning. Coinkite’s new Security Status page lists four independent reviews, including a real-device test that observed eight hardware RNG reads for a 32-byte seed request.

The company noted that the checks are “not a complete audit of every firmware binary.” Confirmed losses passed $100 million, with Galaxy Research counting 1,596 BTC from roughly 7,300 addresses, and a suspected fourth wave sweeping nearly 449 BTC on August 3.

Most Popular

Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount