Particle.news

Coldcard Forces Users to Replace Wallet Seeds After Entropy Regression

Owners must move funds to newly created wallets that use private randomness to stop offline reconstruction of weak recovery phrases.

Overview

  • Coldcard published firmware 5.6.1 for Mk4/Mk5 and 1.5.1Q for Q on Aug. 20 and now requires private user entropy for every newly generated seed.
  • A March 2021 code change routed seed creation into a deterministic MicroPython fallback that cut effective randomness to about 40 bits on some older models and about 72 bits on later vulnerable models, making offline brute-force reconstruction practical.
  • Installing the update does not fix previously generated seeds so affected owners must update, create and verify a new seed using the mandated user entropy (for example 65 unpredictable key presses, 50 private six‑sided die rolls, or 128 coin flips), and transfer their Bitcoin to the replacement wallet after testing a small payment.
  • Researchers traced coordinated on‑chain sweeps that began July 30 and removed an estimated 1,816 BTC from more than 5,200 addresses, investigators say most stolen coins remain in attacker wallets and exchanges have seen elevated inflows as some users move assets to custodial or multisignature options.
  • Beyond seed fixes the release adds staged PSBT checks before signing, alters default SIGHASH behavior and tightens USB and firmware isolation, and the episode has prompted calls for stricter build controls, independent audits and clearer user guidance on supplying private entropy.