News Summary
TREE NEWS reports: On August 20, hardware wallet manufacturer Coldcard released new firmware for its Mk4/Mk5 (version 5.6.1) and Q (version 1.5.1Q) devices. The update follows a July 31 hotfix and three weeks of continuous review, addressing users who suffered severe financial losses due to seed-generation attacks. The new firmware requires every newly generated seed to incorporate user-entropy sources—at least 65 keystrokes, 50 physical dice rolls, or 128 physical coin flips—combined with fresh entropy from the STM32 true random number generator and the SE1/SE2 secure elements. Additional improvements include phased PSBT verification before signing, enhanced USB and firmware-update boundaries, improved Delta-mode isolation, a fix for active-wallet backup issues, stronger RNG initialization and fault checks, and safer default SIGHASH settings.
Industry Analysis
This update is a direct response to a critical vulnerability that compromised seed generation on affected devices. By mandating user-supplied entropy, Coldcard is shifting from a purely hardware-based RNG model to a hybrid approach that reduces the risk of deterministic or predictable seeds—a known attack vector in hardware wallets. The requirement for physical randomness (dice, coins) is particularly notable, as it introduces a layer of security that cannot be compromised by remote attackers or firmware bugs alone.
From a broader perspective, this move underscores a growing trend in the crypto hardware wallet industry toward transparency and user involvement in security processes. Coldcard has long been favored by privacy-conscious and technically adept users, and this update reinforces its commitment to a ‘trust but verify’ philosophy. The phased PSBT verification and improved isolation features also align with best practices for secure multi-signature workflows, which are increasingly used by institutional investors and high-net-worth individuals.
However, the update does not retroactively fix seeds generated on compromised firmware. Users who may have been affected are advised to generate new seeds after updating and to verify them before transferring funds. This highlights a persistent challenge in the industry: how to balance security enhancements with user convenience, especially for those who may not fully understand the technical implications.
Forward-Looking Perspective
As hardware wallets become more sophisticated, we can expect further integration of user-entropy requirements and multi-factor authentication mechanisms. The move also signals a potential shift toward more auditable and verifiable firmware update processes, possibly incorporating reproducible builds and signed releases. For Coldcard, this update reinforces its position as a security-first brand, but it also raises the bar for competitors like Ledger and Trezor, who may need to adopt similar measures to maintain trust.
In the longer term, the incident and response could influence regulatory discussions around self-custody and hardware wallet standards. While no formal regulations exist yet, the industry may see voluntary standards emerge, particularly around seed generation and entropy sources. For users, the key takeaway is clear: always update firmware, verify signatures, and—when in doubt—generate new seeds with physical randomness.




