Firmware 5.6.1 requires owners to supply their own randomness for every new seed following reports of a major Bitcoin exploit
Coinkite has pushed out firmware version 5.6.1 for its Coldcard hardware wallet. The update requires users to supply their own entropy for every new seed created on the device. Previously, seed generation relied primarily on the wallet's internal random number generator.
The change follows reports of a seed-related vulnerability tied to a significant theft of Bitcoin. CryptoPotato reported the losses at around $100 million. The Cryptonomist EN put the figure at $112 million. Both figures describe the same underlying incident, though the exact loss total remains unsettled across reporting.
Seed generation is the foundation of self-custody wallets. A seed phrase, typically 12 or 24 words, encodes the private keys controlling a user's funds. If the randomness behind that seed is predictable, weak, or compromised in any way, an attacker could theoretically reconstruct the keys and drain the associated wallet. That risk sits at the center of the vulnerability now under scrutiny.
Forcing user-supplied entropy is a mitigation technique long recommended by security researchers. It typically involves methods such as dice rolls, camera-captured images, or other manual randomness sources. That input is combined with the device's internal randomness rather than replacing it. The goal is to reduce reliance on any single source of randomness, including one that might be flawed due to a firmware bug or supply-chain compromise.
Hardware wallets are marketed as a safer alternative to exchange custody, since private keys never leave the device. That reputation depends heavily on the integrity of the random number generation process during setup. A flaw at that stage undermines the core security promise of cold storage, regardless of how well the device protects keys afterward.
The incident adds to a recurring pattern in crypto security. Losses tied to exchange hacks and smart contract exploits are more commonly reported. Vulnerabilities inside hardware wallets or key-generation processes are rarer but potentially more damaging, since they can silently expose funds that owners believe are fully secured. Users who generated seeds on affected firmware versions may need to review Coinkite's guidance on whether migration to newly generated seeds is warranted.
Coinkite has not been quoted directly in the available reporting regarding the specific technical root cause of the flaw. The firmware change itself, however, signals that the company viewed the existing entropy process as insufficient on its own. Requiring user input going forward is presented as a direct response to the reported exploit.
The immediate effect is likely concentrated among Coldcard users and the broader hardware wallet segment of the self-custody market. Renewed scrutiny of seed-generation practices could push other hardware wallet makers to review or strengthen their own entropy implementations.
For the wider crypto market, the episode reinforces ongoing debate over custody risk. Institutional and retail investors weighing self-custody against exchange-held assets may factor this incident into their risk assessments. No pricing or trading data has been tied to this event in the available reporting, so any broader market reaction remains unconfirmed.
The firmware update reflects a direct response to a reported seed vulnerability, with the scale of associated losses still described differently across outlets. Coldcard users are advised to update and to consult Coinkite's official guidance on seed handling going forward.
Coldcard is a hardware wallet made by Coinkite, designed to store Bitcoin private keys offline for self-custody.
User entropy refers to randomness a person manually contributes, such as dice rolls or camera input, which is combined with the device's internal randomness when generating a new seed.
Reports vary, with CryptoPotato citing roughly $100 million in losses and The Cryptonomist EN citing $112 million.
Users who generated seeds before this update may want to review Coinkite's official guidance to determine whether regenerating a seed is recommended.
August 24, 2026
August 23, 2026
We measure how many people read this site. That is all it is used for — there is no ad network, no advertising cookie, and nothing sold to anyone. Decline and the site works exactly the same. What we collect