The latest firmware introduces mandatory user entropy for every new wallet creation. Owners are now required to provide randomness directly through at least 65 key presses, 50 private dice rolls, or 128 physical coin flips. This input supplements the device's internal random-number generator, ensuring that no single component dictates the security of the resulting seed. Coldcard emphasizes that these inputs must remain strictly private, as any recorded sequence could potentially be used to reconstruct the wallet.
Updating the device does not retroactively secure existing wallets created under previous firmware versions. Affected users—specifically those with Mk2, Mk3, Mk4, Mk5, or Q models generated before recent security patches—must move their funds to a completely new, independently verified wallet. Importing old seed phrases into updated firmware fails to mitigate the original weakness. While a BIP-39 passphrase adds a layer of security, it does not resolve the underlying entropy defect, necessitating a full migration.
The firmware release also enhances security by implementing staged verification for partially signed Bitcoin transactions (PSBT) and tightening boundaries for USB connections and firmware updates. These changes follow a March 2021 regression that caused devices to rely on a deterministic MicroPython fallback, resulting in significantly lower-than-intended randomness. With estimated losses reaching 1,816 BTC, the incident has prompted a shift in custody habits, with some owners moving assets to centralized exchanges or regulated ETFs to mitigate self-custody risks.

Comments (0)
No comments yet. Be the first!