Coldcard Releases Security-Focused Firmware Update: Affected Users Should Regenerate Seed Phrases and Migrate Funds
Coldcard Releases Security-Focused Firmware Update: Affected Users Should Regenerate Seed Phrases and Migrate Funds
Coldcard has released new firmware versions for its hardware wallet product line, introducing stricter seed phrase generation rules and multiple security hardening measures after a recent review of risks related to mnemonic generation.
The update covers Coldcard Mk4 and Mk5 firmware version 5.6.1, as well as Coldcard Q firmware version 1.5.1Q. The release follows an emergency fix issued on July 31 and a subsequent multi-week security review. The key message for users is clear: firmware updates can improve future security, but they cannot retroactively secure seed phrases that may have been generated under affected conditions.
For crypto users, this is an important reminder of a basic principle in self-custody: the security of a wallet begins at the moment the recovery phrase is created.
What Changed in the New Coldcard Firmware?
The most important change is that newly generated seed phrases must now include at least one user-provided entropy source. According to Coldcard’s latest firmware notes and security guidance, users creating a new wallet must contribute randomness through one of several physical methods:
- At least 65 irregular button presses
- 50 physical dice rolls
- 128 physical coin flips
This user-generated randomness is then combined with fresh entropy from the device’s STM32 true random number generator and secure elements SE1 and SE2. In practical terms, the new workflow is designed to reduce dependence on any single source of randomness and make attacks against mnemonic generation significantly harder.
For users who want to understand why randomness matters in wallet creation, the broader cryptographic concept is explained by the U.S. National Institute of Standards and Technology in its guidance on random bit generation.
Why Seed Phrase Entropy Matters
A seed phrase is not just a backup phrase. It is the root of control over a crypto wallet. In Bitcoin and many other blockchain systems, the mnemonic phrase is used to derive private keys, addresses, and signing authority. If an attacker can predict or influence how that phrase is generated, the entire wallet may be at risk.
Modern wallets typically follow standards such as BIP-39 mnemonic code and hierarchical deterministic wallet designs such as BIP-32. These standards are widely used because they make wallet backup and recovery practical. However, their security still depends on the quality of the original entropy.
This is why adding physical entropy, such as dice rolls or unpredictable key presses, can be meaningful. It introduces randomness that is external to the device, making it harder for a compromised or faulty internal component to determine the final seed.
More Than Mnemonics: Additional Security Hardening
The firmware update is not limited to seed phrase generation. Coldcard also introduced several other security and correctness improvements, including:
- Immediate staged PSBT verification before signing
- Stronger boundaries around USB connection behavior and firmware update flows
- Improvements to Delta Mode isolation
- A fix for active wallet backup handling
- More robust random number generator initialization and failure checks
- Changes to default SIGHASH behavior
- Multiple additional security and correctness refinements
For Bitcoin users, the PSBT-related changes are especially relevant. Partially Signed Bitcoin Transactions, described in BIP-174, are widely used in air-gapped and multi-device signing workflows. Stronger validation before signing can reduce the chance that a user signs something different from what they intended.
Updating Firmware Does Not Fix Old Seed Phrases
The most important user action is not simply installing the latest firmware. Coldcard has emphasized that if a seed phrase was created using affected firmware, updating the device does not change the historical conditions under which that seed was generated.
In other words:
- A firmware update can protect future wallet creation.
- It cannot make a previously generated mnemonic safer.
- Users in the affected scope should create a new wallet after updating.
- Funds should then be moved to addresses controlled by the new seed phrase.
This distinction is critical. Many users assume that updating firmware automatically resolves all known security issues. That is true for some software bugs, but not for weaknesses that may have affected the generation of long-term cryptographic secrets.
Recommended Steps for Affected Coldcard Users
If your device model and firmware history fall within the affected range described by Coldcard, a cautious migration process is recommended.
1. Verify the Firmware Before Installing
Only download firmware from the official source and verify its signature before installation. Firmware authenticity checks help prevent supply-chain attacks, where a user may unknowingly install malicious software disguised as an update.
Coldcard users should refer to the company’s official firmware upgrade documentation for the correct verification process.
2. Install the Latest Firmware
After confirming the file is authentic, update the device to the latest available firmware for your model. Users of Mk4, Mk5, and Q devices should make sure they are using the newly released versions that include the mnemonic-generation changes.
3. Generate a Fresh Seed Phrase
Create a new wallet only after the update is complete. During setup, use one of the required physical entropy methods, such as dice rolls, coin flips, or irregular key presses.
When writing down the new recovery phrase, keep it offline and never enter it into a website, cloud note, screenshot, chat app, or password manager.
4. Verify the Backup
Before transferring funds, confirm that the recovery phrase has been recorded accurately. A mistaken backup can be just as damaging as a compromised one.
5. Move Assets to the New Wallet
Once the new wallet is verified, migrate assets from the old wallet to addresses derived from the new seed phrase. For Bitcoin users, consider sending a small test transaction first before transferring the full balance.
6. Retire the Old Seed
After confirming that funds have arrived safely in the new wallet, treat the old seed as no longer suitable for future use.
What This Means for the Hardware Wallet Industry in 2025
This incident reflects a broader trend in crypto security: the industry is moving away from assuming that hardware alone is enough. In 2025, users increasingly expect transparent firmware processes, verifiable updates, stronger entropy design, open security communication, and clearer migration guidance when risks are discovered.
As self-custody adoption grows, the quality of seed generation, transaction verification, and firmware integrity will remain central to user safety. The rise of more advanced phishing, supply-chain threats, and transaction-manipulation attacks has made it necessary for wallet makers to design systems that assume users may operate in hostile environments.
For users, the lesson is equally clear: owning a hardware wallet is not a one-time setup task. It also requires periodic firmware review, backup verification, and attention to security advisories.
A Self-Custody Reminder
The Coldcard firmware release is a useful case study in how deeply wallet security depends on entropy and transparent device behavior. A secure recovery phrase must be unpredictable, properly generated, and protected throughout its lifetime.
For users evaluating hardware wallet options, OneKey focuses on open-source security, transparent signing, multi-chain asset management, and practical self-custody workflows. Regardless of the device you use, the best practice remains the same: verify firmware, generate seed phrases in a trusted environment, keep backups offline, and never ignore a security advisory involving mnemonic generation.



