Coldcard Now Makes You Roll the Dice for a Safer Seed — After a 1,778 BTC Lesson

Coldcard Now Makes You Roll the Dice for a Safer Seed — After a 1,778 BTC Lesson

Bitcoin hardware-wallet maker Coldcard wants its users to stop trusting a black box to generate their keys — and start rolling dice. According to Cointelegraph, its parent company Coinkite released firmware updates, versions 5.6.1 for the Mk4 and Mk5 and 1.5.1Q for the Coldcard Q, that require newly generated seed phrases to blend user-supplied randomness with the device’s own.

Under the update, creating a new seed means contributing entropy through one of three methods: at least 65 keypresses with unpredictable timing, 50 rolls of a six-sided die, or 128 coin flips — each mixed with the device’s internal randomness sources. The idea is straightforward. If a user’s manual input is unpredictable, the resulting key stays strong even if the hardware’s randomness is somehow compromised.

That defense-in-depth thinking runs through the rest of the release. Cointelegraph reports the firmware combines randomness from the device’s secure elements and its hardware random number generator, so unpredictability survives even if one entropy source fails. Coldcard also added boot-time verification tests and extra checks on the hardware RNG to catch problems before a key is ever created.

The update tightens the wallet’s connection to the outside world as well. New USB safeguards force transaction re-verification before signing, downloads over USB are restricted to the most recent output and require encrypted sessions, and certain Bitcoin signature modes that could allow transaction outputs to be modified are now disabled by default — closing subtle avenues an attacker might use to redirect funds.

There is a blunt warning attached. Upgrading the firmware does not retroactively fix a weak key: existing seed phrases remain vulnerable even after the update and must be replaced with newly generated seeds before funds are migrated. For anyone whose seed may have been created with insufficient randomness, patching the software is only half the job.

The urgency has a painful backstory. Cointelegraph notes that a firmware bug dating to March 2021 weakened seed randomness on some devices, cutting effective key strength from 128 bits to just 40 bits — a range low enough to be brute-forced without any physical access to the wallet. Confirmed losses tied to the flaw reached 1,778 BTC, worth roughly $112 million, ranking it among the largest crypto exploits of 2026.

That episode reframes the new firmware as more than a routine security bump. For self-custody, the strength of a wallet ultimately rests on the quality of the randomness behind a single seed — and Coldcard’s answer is to take that randomness partly out of the machine’s hands and put it into the user’s. Rolling dice may feel low-tech, but it is a deliberate hedge against the possibility that the code, once again, gets it wrong.

Written for Red Robot with AI assistance and human editing. Based on reporting by Cointelegraph.

Happy
Happy
0%
Sad
Sad
0%
Excited
Excited
0%
Angry
Angry
0%
Surprise
Surprise
0%
Sleepy
Sleepy
0%
A Blockchain Safety Net: Paul Ryan’s Foundation and Digital Asset Pilot Public Benefits on Canton

A Blockchain Safety Net: Paul Ryan’s Foundation and Digital Asset Pilot Public Benefits on Canton

From FTX Trading Bans to a $165M Ponzi: Crypto’s Courtrooms Had a Busy Week

From FTX Trading Bans to a $165M Ponzi: Crypto’s Courtrooms Had a Busy Week

Leave a Reply

Your email address will not be published. Required fields are marked *

6 + twenty =