Cryptocurrency Market Recovers: Key Events and Warnings Following Recent Bitcoin Hack!

cryptonews.ruPublished on 2026-08-20Last updated on 2026-08-20

Abstract

Coldcard has released a new firmware update (v5.6.1 for Mk4/Mk5, v1.5.1Q for Q) to enhance security following a recent vulnerability that reportedly led to over $70M in Bitcoin theft. The update results from a comprehensive security review. It mandates that all new seed phrases include at least one user-generated physical entropy source, such as irregular key presses, dice rolls, or coin flips, combined with the device's internal randomness. Crucially, the update does not fix potential security flaws in seed phrases generated with affected prior firmware versions. Affected users must update, create and verify a completely new seed phrase, and transfer their Bitcoin to the newly created wallet. The update also introduces real-time PSBT verification, enhances USB and firmware update security, and includes various other security and accuracy improvements. Coldcard strongly advises all Mk4, Mk5, and Q users to update promptly and verify the firmware's digital signature.

Coldcard has released a new firmware update to enhance the security of its hardware wallets. The company stated that some recovery phrases generated in previous versions of the software may pose a potential security risk, advising affected users to create a new recovery phrase and transfer their assets to a new wallet.

As you may know, a security vulnerability in the Coldcard hardware wallet system recently led to the theft of over $70 million worth of Bitcoin from user wallets.

Coldcard released version 5.6.1 for Mk4 and Mk5 models, and version 1.5.1Q for the Q model. The update follows a comprehensive security review lasting about three weeks, prompted by an emergency security patch released on July 31.

With the new firmware, each new recovery phrase generated on Coldcard devices must now include at least one user-provided source of physical entropy.

Users can do this using one of the following methods: at least 65 irregular key presses, 50 dice rolls, or 128 coin flips.

This user-generated randomness will be combined with new entropy from the device's STM32 hardware random number generator and secure elements SE1 and SE2. Coldcard stated that this change aims to make the recovery phrase generation process more resilient to potential attacks.

The update doesn't only change how recovery phrases are generated. The new version also enables real-time PSBT verification and step-by-step verification before the signing process.

Furthermore, security measures for USB connections and firmware update processes have been strengthened, and the isolation mechanism in Delta Mode has been improved.

The update addresses several issues related to backing up active wallets, implements more robust random number generators, and introduces stricter error checks. The update includes various security and accuracy enhancements, as well as changes to default SIGHASH settings.

The most important note in Coldcard's statement concerns existing recovery phrases.

The company specifically emphasized that installing the new firmware does not eliminate the potential security issue in recovery phrases created using previously affected software versions.

Users affected by the security alert must first update their devices to the new firmware version, then create and verify a completely new recovery phrase, and transfer their existing Bitcoin to the newly created wallet.

Coldcard also strongly recommended that all users of Mk4, Mk5, and Q devices update their devices as soon as possible and verify the digital signature of the downloaded firmware file.

*This is not investment advice.

end-content

Related Questions

QWhat was the main reason for Coldcard's firmware update?

AThe main reason for Coldcard's firmware update was to address a security vulnerability in their hardware wallets that led to the theft of over $70 million in bitcoins from user wallets. The update aims to enhance the security of the seed phrase generation process.

QWhat specific new requirement does the updated firmware impose when creating a new recovery phrase?

AThe updated firmware requires that each new recovery seed phrase generated on Coldcard devices must now incorporate at least one user-provided source of physical entropy, such as 65 irregular key presses, 50 dice rolls, or 128 coin flips.

QWhich Coldcard device models are affected by the firmware update?

AThe firmware update affects the Coldcard models Mk4 and Mk5, for which version 5.6.1 was released, and the Q model, for which version 1.5.1Q was released.

QDoes simply installing the new firmware fix the security issue for users with existing wallets?

ANo, simply installing the new firmware does not fix the potential security issue for users with existing wallets. Users affected by the security warning must first update their device, then create and verify a completely new recovery seed phrase, and transfer their existing bitcoins to the newly created wallet.

QWhat are some of the other improvements included in the firmware update besides the seed generation change?

ABesides the seed generation change, the firmware update introduces real-time PSBT verification and staged verification before the signing process. It also strengthens security for USB connections and firmware update processes, improves the Delta Mode isolation mechanism, addresses issues with active wallet backups, implements more robust random number generators, and makes error checks more stringent.

Related Reads

Trading

Spot
活动图片