
According to Coinkite, the company shipped Coldcard firmware 5.6.1 for the Mk4 and Mk5 models and 1.5.1Q for the Q model on August 20, 2026. However, as the company clearly states, "Installing this update does not make an existing vulnerable seed safe." The update covers four key areas: seed generation, transaction checking before signing, USB data isolation, and backup behavior. The maker prefaces these improvements with a sobering caveat: "These are specific controls, not a claim that every conceivable flaw has been ruled out." The firmware replaces releases 5.6.0 and 1.5.0Q, which were pushed out quickly after the emergency update of July 31, and goes beyond a simple bug fix. The file names carry August 20 as a timestamp, with the Mk4/Mk5 version named "2026-08-20T1336-v5.6.1-mk-coldcard.dfu" and the Q version "2026-08-20T1335-v1.5.1Q-q1-coldcard.dfu."
The seed vulnerability affects devices set up between March 2021 and July 2026 that have used the same recovery phrase since setup. As reported by Coinkite, the flaw stems from devices drawing randomness from software substitutes rather than hardware components built in for this purpose. Seeds on the Mk4, Mk5 and Q models came in at roughly 72 bits, while older Mk2 and Mk3 models reported far lower figures of around 40 bits of effective randomness. The cause was the same in both cases: devices drew their randomness not from the hardware component built in for it, but from a software substitute. This means a seed with too little randomness is predictable and stays that way for as long as it is in use. The flaw reaches back to March 2021, with affected builds including the Mk2 and Mk3 on releases 4.0.1 through 4.1.9, the Mk4 and Mk5 on the standard track before 5.6.0, the Q before 1.5.0Q, and the Edge builds before 6.6.0X and 6.6.0QX respectively.
The most conspicuous change in the new release concerns setup, where users must now add randomness themselves through three methods: at least 65 key presses at an unpredictable rhythm, 50 rolls of a real six-sided die, or 128 coin flips. The device mixes this self-generated share with fresh device randomness. According to Coinkite's machine-readable status file, the contribution of both security chips feeds into every seed. The maker provides a separate "Dice Rolls Only" track for users who want to bypass device randomness entirely, requiring 50 rolls for a twelve-word phrase and 99 rolls for a twenty-four-word one. For users who enriched their seed at the time with their own rolls through the "Add Dice Rolls" function, the company considers migration unnecessary under narrow conditions. The migration process leads to movements between your own addresses, requiring users to record transaction times, IDs, and addresses involved for each move.
According to Galaxy Research, 1,789.28 BTC worth $114.7 million when stolen and approximately $138.8 million currently has been traced to the Coldcard exploit across 8,865 addresses. Most significantly, 1,561 BTC, or 87.3% of the attributed losses, remains unmoved and under attacker control in collection or holding addresses. The affected Bitcoin had remained dormant for extended periods before being stolen, with a median address dormancy of 3.2 years and average of 3.6 years. Victim reports show heavier individual losses, with Galaxy receiving 221 reports covering 790.72 BTC, equivalent to 44.2% of total Bitcoin attributed to the exploit. The median reported loss was 1.04272 BTC and average 3.57792 BTC, with Bitcoin covered by those reports having remained dormant for a median of 3.25 years before theft. While the largest holdings remain parked, some funds from later attacks have started moving through CoinJoin transactions, peel chains, and other methods designed to obscure movement across addresses.