Close Menu
Techora News HubTechora News Hub
    Facebook X (Twitter) Instagram
    Techora News HubTechora News Hub
    • Home
    • Crypto News
      • Bitcoin
      • Ethereum
      • Altcoins
      • Blockchain
      • DeFi
    • AI News
    • Stock News
    • Learn
      • AI for Beginners
      • AI Tips
      • Make Money with AI
    • Reviews
    • Tools
      • Best AI Tools
      • Crypto Market Cap List
      • Stock Market Overview
      • Market Heatmap
    • Contact
    Techora News HubTechora News Hub
    Home»Crypto News»Bitcoin»Coldcard Firmware 5.6.1 Forces User Entropy Into Every New Seed After $100M Exploit
    Bitcoin

    Coldcard Firmware 5.6.1 Forces User Entropy Into Every New Seed After $100M Exploit

    August 24, 2026
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Coldcard Firmware 5.6.1 Forces User Entropy Into Every New Seed After $100M Exploit
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email
    kraken




    Coinkite has released new Coldcard firmware that forces users to provide their own randomness when generating new wallet seeds.

    Coinkite, the company behind Coldcard, has shipped a firmware update that will not generate a new wallet seed until the owner supplies randomness by hand.

    That means at least 50 dice rolls, 128 coin flips, or 65 timed key presses, three weeks after a defect in its random number generator opened customer funds to attackers.

    coinbase

    Coldcard’s two device lines run separate firmware tracks, so the release carries two numbers, 5.6.1 for the Mk4 and Mk5, and 1.5.1Q for the Q, the larger model with a keyboard and QR scanning.

    Boot Check Targets the Defect

    Coinkite stated that the input is added on top of device randomness from the STM32 TRNG and both secure elements.

    Coldcard was built to draw seed entropy only from its hardware generator, but Coinkite traced the failure to a build and link error that left the setting meant to disable the software path without effect, sending the random-number call to MicroPython’s Yasmarang PRNG, which entered the seed path in March 2021.

    Affected seeds carry about 72 bits of entropy instead of the expected 128 bits after 594.5 BTC was swept from 500 addresses on July 30.

    Firmware 5.6.1 now verifies at boot that the random-number call reaches the intended hardware path, halting the device if it fails. Coinkite replaced Yasmarang with a SHA-256 Hash_DRBG, specified in NIST SP 800-90A, and seeds it at startup with a full 256-bit digest from both secure elements, which earlier firmware truncated to 32 bits.

    You may also like:

    Key mashing follows Peter Todd’s push-button RNG design, hashing keypad press timing at CPU-cycle resolution. The first press sets a reference, and each of the 64 gaps that follow is credited with two bits of entropy.

    Old Seeds Still Need Migrating

    “Installing this update does not make an existing vulnerable seed safe,” Coinkite wrote, directing anyone whose seed may have been generated on affected firmware between 2021 and July 2026 to create a replacement and move their Bitcoin (BTC). Mk2 and Mk3 fall outside this release, and their minimum fixed version stays at 4.2.0.

    A compromised USB host could rewrite a staged transaction after the owner approved it, so the signature covered different outputs. The device now rechecks those bytes before signing and stops with a “Transaction modified” warning.

    Coinkite’s new Security Status page lists four independent reviews, among them a real-device test that observed eight hardware RNG reads for a 32-byte seed request and a rebuild matching every byte of the signed firmware.

    The company noted that the checks are “not a complete audit of every firmware binary.” As CryptoPotato reported, confirmed losses passed $100 million, with Galaxy Research counting 1,596 BTC from roughly 7,300 addresses, and a suspected fourth wave sweeping nearly 449 BTC on August 3.



    Source link

    frase
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Bitcoin Price Drops to $81,000 for the First Time in Nearly Three Weeks

    October 8, 2026

    Ethereum Price Cracks as 3 Prediction Markets Make Their Calls

    October 8, 2026

    AI Is Overbuilt, and Bitcoin Could Benefit From It

    October 7, 2026

    Bitcoin Coils Below $87,000 Ask Liquidity as Stocks Return to All-Time Highs

    October 7, 2026

    Fortitude Bets Up to $100 Million on Bitmain Zcash Mining Hardware

    October 6, 2026

    Trump’s $5,000 Checks Could Send Billions Into Bitcoin and Crypto: But There’s a Catch

    October 6, 2026
    binance
    Latest Posts

    AI Agents Made Me 1K Day Trading (AI Trading Bot Setup Review)

    October 8, 2026

    How AI Actually Learns From Data | AI for Beginners

    October 8, 2026

    AI for Absolute Beginners — The 5-Minute Starter Guide

    October 8, 2026

    Fairshake PAC to Initially Spend $6M on House Races as US Midterms Loom

    October 8, 2026

    Tokenized Securities Firm KoreInside Targets Ethereum, Solana And Avalanche With New Web3 Partnership

    October 8, 2026
    changelly
    LEGAL INFORMATION
    • Privacy Policy
    • Terms Of Service
    • Social Media Disclaimer
    • DMCA Compliance
    • Anti-Spam Policy
    Top Insights

    Bitcoin Price Drops to $81,000 for the First Time in Nearly Three Weeks

    October 8, 2026

    How Much Should Canadians Have Saved by 55? Here’s a More Useful Number

    October 8, 2026
    binance
    Facebook X (Twitter) Instagram Pinterest
    © 2026 TechoraNewsHub.com - All rights reserved.

    Type above and press Enter to search. Press Esc to cancel.

    bitcoin
    Bitcoin (BTC) $ 82,178.00
    ethereum
    Ethereum (ETH) $ 2,487.53
    tether
    Tether (USDT) $ 0.999296
    bnb
    BNB (BNB) $ 739.64
    xrp
    XRP (XRP) $ 1.39
    usd-coin
    USDC (USDC) $ 0.999616
    solana
    Solana (SOL) $ 110.08
    tron
    TRON (TRX) $ 0.332059
    staked-ether
    Lido Staked Ether (STETH) $ 2,265.05
    figure-heloc
    Figure Heloc (FIGR_HELOC) $ 1.03