Overview
- A March 2021 code change routed seed generation to a deterministic MicroPython fallback instead of the STM32 hardware TRNG, which reduced effective entropy in some Coldcard seeds and made them enumerable.
- Attackers began exploiting the weakness on July 30, 2026, and forensic teams attribute roughly 1,800 to 1,820 BTC stolen from thousands of single‑signature addresses in coordinated sweep waves.
- Coinkite published firmware 5.6.1 for Mk4/Mk5 and 1.5.1Q for Q after a three‑week review and now requires owners to add physical randomness when creating new seeds, such as 65 timed key presses, 50 private six‑sided die rolls, or 128 coin flips.
- Installing the update does not fix seeds created under the affected firmware, so owners must update, create a verified replacement wallet on patched firmware, confirm on‑device receiving addresses, perform a small test transfer, and then migrate their Bitcoin.
- The release also adds staged PSBT checks before signing, changes default SIGHASH handling, and tightens USB and firmware validation; investigators and exchanges continue to monitor attacker addresses while many victims shift custody toward multisignature setups or exchanges.