Coldcard 5.6.1 Is Here: Why the Update Will Not Rescue Your Old Seed
Coinkite shipped Coldcard firmware 5.6.1 and 1.5.1Q on August 20, 2026. The update closes the gap for new seeds but does not repair a seed already affected.

Table of Contents
Table of Contents



Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
Coinkite shipped firmware 5.6.1 for the Coldcard Mk4 and Mk5 and 1.5.1Q for the Q model on August 20, 2026. If you own a Coldcard, you need to keep two things apart. The update closes the gap for everything you create from now on. It does not repair a seed that was generated on a faulty release. For that seed, the only remedy is a move to a freshly generated recovery phrase.
The maker says so in plain terms in its notice: “Installing this update does not make an existing vulnerable seed safe.” The status page at coldcard.com/security/status puts it even more briefly: “An update is not a seed migration.”
That means anyone who set up their device between March 2021 and July 2026 and has used the same recovery phrase ever since is affected. In that case the update alone is not enough, not even when the Coldcard shows the new version number afterwards.
Coldcard 5.6.1 and 1.5.1Q: What the maker shipped on August 20
The two releases are the result of a three-week review Coinkite began after the emergency update of July 31. They replace releases 5.6.0 and 1.5.0Q, which were pushed out quickly at the time, and they go beyond a plain bug fix.
You can read the release off the file name. The file linked on the download page for the Mk4 and Mk5 is called 2026-08-20T1336-v5.6.1-mk-coldcard.dfu, the one for the Q 2026-08-20T1335-v1.5.1Q-q1-coldcard.dfu. Both carry August 20 as a timestamp in the name itself.
According to the maker, the release covers four areas: seed generation, the checking of transactions before signing, the isolation of data over the USB connection, and the behaviour around backups. Coinkite prefaces the list with a caveat that is strikingly sober in its wording: these are specific controls, not a claim that every conceivable flaw has been ruled out.
A firmware update is not a seed migration: why the old seed stays exposed
The seed is the number from which all of a wallet’s keys and addresses are derived; the twelve or twenty-four words on the emergency sheet are only its readable form. That number is generated once, when the device is set up, and never changed again.
That is exactly where the oddity of this case comes from. A firmware update swaps out the software that generates new seeds. It does not touch the existing seed, because it cannot touch it without destroying the wallet. So anyone who updates an affected device and then keeps using it has repaired the software and kept the weakness.
The incident itself demonstrated this over the summer. Attackers cleared bitcoin balances from devices whose recovery phrase was predictable; we described the first waves and the scale on July 31 in our report on the Coldcard firmware flaw. Accounts of the total damage vary: TRM Labs puts it at around $116 million, while CoinDesk cites around $114 million in its report on the new firmware. The account from crypto.news speaks of 1,816 bitcoin from more than 5,200 addresses and notes that around 90 percent of the balances taken in the confirmed waves have not yet been moved on.
72 instead of 128 bits: what the entropy flaw in seed generation means
Entropy is the measure of how many different values were actually possible when a seed was generated; the higher it is, the more hopeless brute-forcing becomes. The target value is 128 bits.
That value was not reached on the affected releases. According to the maker, seeds on the Mk4, Mk5 and Q came in at roughly 72 bits. For the older Mk2 and Mk3 models the reported figure is far lower still: crypto.news cites around 40 bits of effective randomness for them. The cause was the same in both cases: the devices drew their randomness not from the hardware component built in for it, but from a software substitute.
What this difference means in practice is hard to capture in a single image, because the scale is deceptive. The gap between 72 and 128 bits is not a surcharge but a shift of many orders of magnitude. What matters for you is the plain consequence: a seed with too little randomness is predictable, and it stays that way for as long as it is in use.
Which releases count as affected
The maker’s migration guide names the affected builds precisely: the Mk2 and Mk3 on releases 4.0.1 through 4.1.9, the Mk4 and Mk5 on the standard track before 5.6.0, the Q before 1.5.0Q, the Edge builds before 6.6.0X and 6.6.0QX respectively. The flaw thus reaches back to March 2021.

Mandatory entropy for a new seed: 65 key presses, 50 dice rolls or 128 coin flips
The most conspicuous change in the new release concerns setup. On the standard track, a new seed is no longer created from the device’s randomness alone. You have to add randomness yourself, through exactly one of three methods: at least 65 key presses at an unpredictable rhythm, 50 rolls of a real six-sided die, or 128 coin flips.
The device mixes this self-generated share with fresh device randomness. According to the maker’s machine-readable status file, the contribution of both security chips feeds into every seed. Anyone who wants to bypass the device randomness entirely will find the separate “Dice Rolls Only” track for it: it requires 50 rolls for a twelve-word phrase and 99 rolls for a twenty-four-word one.
The effort is deliberate. It shifts part of the trust from the component back to you, and it is the point at which setting up a hardware wallet now feels noticeably different from before. If you have the choice, take the dice method: it is the easiest to follow and can be watched as a process in its own right.
Our own survey: which Coldcard firmware the maker offered on August 22
cryptoticker.io ran this survey itself on August 22, 2026. Method: retrieval of the maker’s public download page at coldcard.com/downloads with a browser identifier, followed by a count of every model row listed there, complete with version number and marking. Seven model rows were checked.
The result: five of the seven rows carry the note “Fixed release,” two do not. Those marked are the Mk5/Mk4 with 5.6.1, the Q with 1.5.1Q, the Edge tracks with 6.6.0X and 6.6.0QX, and the shared row for the Mk3 and Mk2 with 4.2.0. Left without the note are two rows the page itself lists as superseded: a standalone Mk4 row with release 5.4.5 and the Mk1 row with 3.0.6.
For Mk1 owners that is the practically relevant finding. The security notice names 4.0.1 as the first affected release, while the Mk1 line ends at 3.0.6 and shows no corrected build. What that means for an Mk1 the page does not say outright.
A second finding concerns the verification date. The status page carries the stamp “Verified 2026-08-17” and at the same time recommends 5.6.1 and 1.5.1Q, two releases that were not shipped until three days later. Whether the page was checked again after the release and only the stamp was not updated is not apparent from it.
A brief additional check concerned language: three German paths of the maker’s addresses were retrieved, and all three responded with 404. The security notice, the status page and the migration guide are available in English only.
The limits of this survey
What could not be checked was whether the Mk4 row listed as superseded, with 5.4.5, contains the flaw or merely documents a discontinued track. Also not verifiable: how many devices in Germany are affected, how many holders have already installed the update, and whether the maker informs its customers by email in German. The survey only says what the download page displayed on that day.
Hardware wallets comparedRelease track instead of model name: which minimum version applies to your device
A release track is the delivery branch on which a firmware is maintained; the same device can carry entirely different version numbers depending on the branch. That is exactly where checks fail when they go by the model name alone.
The maker therefore names minimum versions per branch. For the Mk2 and Mk3, 4.2.0 or newer applies. For the Mk4 and Mk5 on the standard track, 5.6.0 or newer applies; for the Q on the standard track, 1.5.0Q or newer. Anyone on the Edge track needs 6.6.0X on the Mk4 and Mk5, or 6.6.0QX on the Q. As the currently recommended builds it names 5.6.1 and 1.5.1Q on top of that.
In practice that means: open the firmware version display on the device, note it in full including the letter suffix, and compare it with the minimum version for your branch. An “X” or “QX” at the end points to the Edge track, for which different numbers apply.
The dice exception: when an existing seed need not be migrated, according to the maker
There is one case in which the maker considers the move unnecessary. Anyone who enriched their seed at the time with their own rolls, through the “Add Dice Rolls” function, may under narrow conditions do without it.
The conditions are set out precisely in the guide: at least 50 fair, mutually independent rolls, entered through that function; the roll sequence must have stayed private and never been written down or disclosed; and the words to be used are those the device displayed after the rolls were added. Under these conditions the maker considers at least 128 bits of additional entropy to have been introduced; from 99 rolls he cites around 256 bits.
The sentence that matters comes at the end: with fewer rolls or under uncertain conditions, migrate. Anyone who, after four years, no longer clearly remembers how many rolls there were and whether the sequence really was never recorded anywhere falls into the migration obligation. Uncertainty does not count as relief here.
PSBT checking and SIGHASH_SINGLE: which flaws beyond seed generation were fixed
The three-week review turned up points that have nothing to do with the original randomness flaw. They concern the path a transfer takes from the computer to the device and back.
A PSBT is a partially signed bitcoin transaction: the file in which the wallet software stores the payment proposal and which the hardware wallet is shown for approval. What is new is that the Coldcard checks this file again immediately before signing and aborts the process with the message “Transaction modified” if anything has changed between display and approval. When handed over via USB, the checksum of the request must additionally match the stored file, or the process ends with “PSBT checksum mismatch.”
SIGHASH_SINGLE is a signature variant that fixes only part of a transaction and leaves the rest open. It will be blocked by default in future. On top of that come tighter limits on data retrieval over USB, which is confined to the result of the running encrypted session, and the requirement that a firmware file match its signed length.
Further changes concern the check under BIP-322, the sealing-off of the delta mode, and the behaviour around backups: a backup captures the wallet currently in effect. In the case of a passphrase wallet it contains that wallet’s derived master key, not the words of the parent seed and not the passphrase.
The BIP-39 passphrase: why it does not repair an affected seed
A BIP-39 passphrase is an additional, freely chosen word or sentence from which, together with the seed, a wallet in its own right emerges. It rightly counts as a strong extra safeguard, and the maker expressly recommends it for any wallet whose loss would genuinely hurt its owner.
For the present flaw it still does not solve the problem. The maker puts it unmistakably: a strong, unique passphrase can make access to the underlying seed harder, but it does not repair it. Users with a passphrase should move as soon as is practicable.
Anyone using a passphrase for a new wallet should back it up separately from the seed, note the fingerprint of the passphrase wallet, and test the recovery before any money goes onto it. What “genuinely hurts” the maker deliberately does not fix as an amount; that is a personal threshold.

Checking the firmware file: SHA-256 checksum and signature before installation
A security incident draws imitators, and a forged firmware file would be the most convenient route to someone’s balances. The maker therefore requires two checks before the file goes onto the memory card.
First, the comparison of the SHA-256 checksum: a checksum is a short fingerprint of a file that changes completely at even the smallest alteration. Second, the check of the signed file signatures.txt, which proves that the file really comes from the maker. Only then follows the installation via the memory card, and after the restart the visual check of the displayed version number.
Download the file only from the maker’s address and never from a forum, a chat or a link someone sent you unasked. And one more ground rule the migration guide repeats specifically: never enter your seed words on a website and never send them to a support channel.
Crypto tax tools and portfolio trackers comparedSeed migration step by step: how the move to the new wallet works
The maker describes two routes. The recommended one runs across two devices, because at no point is a working wallet given up.
If you need to buy a second device for this route, you will find the available models and their differences in our hardware wallet comparison. A device from the same maker is not required: a recovery phrase to the BIP-39 standard can in principle also be loaded onto a device from another brand.
On the second device the corrected firmware is installed and an entirely new seed is generated, expressly not a clone of the old one. Then the backup and the fingerprint of the new wallet are checked. There follows a small test transfer from the old to the new wallet, and only once it has arrived does the rest follow. The old backup is kept until the move is complete.
Anyone with only one device takes the fallback route: first check the backup and the fingerprint of the old seed, then install the corrected firmware, delete the old seed on the device, generate and check the new one, and transfer the balances by alternately loading both seeds. This route is trickier, because for a time it does without a second safeguard.
The guide pulls up three warnings expressly. Never destroy the only working copy of a wallet. Abort and transfer nothing if a fingerprint or an address does not match. And do not use the device’s clone or takeover functions as a solution: they copy the affected seed along with everything else.
What you should document during the move
The move leads to movements between your own addresses. For each of them, record the time, the transaction ID and the addresses involved, and keep the note together with the rest of your records. It costs five minutes during the move and spares you the later reconstruction from memory when the path of your balances has to be evidenced.
Independent checks and an open post-mortem: what has not yet been proven
Coinkite lists four external checks on its status page, each with a name, subject and scope. A reviewer with the account @bigshiny0 measured on a real device with Mk4 firmware 5.6.0 that a 32-byte request triggers eight read operations at the hardware random number generator, so the corrected path does indeed reach the component. A second reviewer read the source code across all corrected branches and confirmed that the software substitute had been removed. A third checked the same for the emergency update. A fourth rebuilt release 5.6.0 and compared it byte for byte with the published signed file.
The maker qualifies these proofs himself. The published evidence does not constitute a full independent audit of every corrected firmware file; each only confirms its own scope of review. It is also notable that the checks named refer to 5.6.0, while 5.6.1 is the one currently recommended.
The reckoning is open too. Asked whether the formal technical post-mortem is available, the status page, as of August 15, 2026, answers: no, it is still in progress. Anyone who wants to know how the flaw could go undetected for four years is therefore still waiting.
An assessment, flagged as such: that a maker names the limits of its own evidence this clearly is unusual, and speaks for the account. It does not replace the outstanding report, though, and for the question of whether you go on trusting your device, the post-mortem remains the more important text.
Checking your Coldcard firmware: what to take away
- Check the version number on the device first, not the model. Note the full release including the letter suffix and compare it with the minimum version for your branch: 4.2.0 for the Mk2 and Mk3, 5.6.0 for the Mk4 and Mk5 on the standard track, 1.5.0Q for the Q, 6.6.0X or 6.6.0QX on the Edge track. If your build is below that, download the corrected release from the maker’s address, check the checksum and signature, and install it. If you are thinking about your device anyway, our hardware wallet comparison helps you weigh the models.
- Decide about the seed separately afterwards. If your recovery phrase was generated between March 2021 and July 2026 on an affected release, generate a new seed and move your balances, ideally via the two-device route and with a small test transfer first. Only the narrow dice exception, with at least 50 private, independent rolls, releases you from this. If you take the move as an occasion to reorder your allocation, the software wallet comparison holds the counterparts for everyday use.
- Document the move while it runs. Note the time, transaction ID and addresses for each movement; afterwards it is laborious. A portfolio tracker largely takes this bookkeeping off your hands, and an overview of the common programs is in our comparison of crypto tax tools and portfolio trackers.
You will find the maker’s notice on the release in the Coinkite blog on releases 5.6.1 and 1.5.1Q, and the step-by-step instructions for the move in the Coldcard migration guide.
(As of August 22, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- How to Store a Seed Phrase Safely: What Steel, a Passphrase and Multisig Do for Your Wallet Backup
- Coldcard Losses Near $114 Million as a Fourth Sweep Hits: Why Is Bitcoin Rising Anyway?
- 594 BTC Gone in 25 Minutes: The Coldcard Flaw That Made Seed Phrases Guessable
- Trezor Hack Scare: That STM32 Entropy Email Is a Phishing Attack
- Hot Wallet or Cold Wallet: the Private Key Decides How Safe Your Coins Are
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
September 23, 2026 4:12 AM

How to Set Up a Crypto Wallet: Securing Your Coins in Seven Steps
Your own crypto wallet is set up in twenty minutes, yet a single step decides everything that follows. This guide takes you through wallet type, recovery words and the test amount, and sets out what BaFin and the tax office expect.
September 30, 2026 7:16 AM

Tangem Wallet: The Card Without a Seed Phrase vs the Classic Hardware Wallet
The Tangem Wallet secures crypto with two or three identical cards instead of 24 words. What the sets cost, what the EAL6+ chip delivers and why losing every card is final.
August 22, 2026 4:34 PM

BitBox02: Firmware 9.26.5 Closes Three Security Vulnerabilities. What to Check Now
BitBox released firmware 9.26.5 on August 17, 2026, closing three security vulnerabilities in the BitBox02 and BitBox02 Nova. Existing seeds are not affected according to the manufacturer; an update is due anyway, and with unused devices the order matters.
September 20, 2026 4:15 PM

Crypto Phishing After a Data Breach: The Warning Signs in a Fake Exchange Email
After every major data breach, the number of phishing emails sent in the name of crypto exchanges and wallet manufacturers rises. This article shows you how to recognise such a message, which data a reputable provider never requests by email, and what to do in the first hour after a click.
August 31, 2026 1:22 PM

Cosmostation Wallet Shutdown on September 1: What Cosmos Wallet Users Should Know Now the Deadline Has Passed
Recap as of September 27, 2026: Cosmostation had announced it would discontinue its wallet apps on September 1, 2026, leaving only the export of the recovery phrase and the private key. This article describes the situation before the deadline and how to move Cosmos holdings, including delegated ATOM.
August 25, 2026 10:31 PM

Crypto Wallet Phishing by Letter: Why the QR Code From Your Postbox Wants Your Recovery Phrase
Letters carrying a QR code urge a supposedly urgent wallet update on grounds of quantum resistance and lead to a page that asks for the recovery phrase. The Federal Office for Cybersecurity reported the ploy on August 18, 2026.
September 10, 2026 1:14 PM

Phishing Email From the Real Sender Address: How to Check a Wallet Security Warning
An alleged security warning to wallet customers travelled through the manufacturer's genuine sending channel and passed every technical authenticity check. The test that still holds costs you four minutes.
August 22, 2026 10:29 AM

Bitcoin Fork: What Happens to Your Coins When the Chain Splits
On October 31, 2026 a new chain called ECX splits off from Bitcoin, and every holder is credited automatically. Who actually receives the coins depends on the private keys, on voluntary replay protection and on a tax rule many overlook.
August 22, 2026 4:13 AM

SafePal Data Breach: 39,798 Customers Exposed With Names, Addresses and Phone Numbers
SafePal confirmed a data breach on August 16, 2026: the names, delivery addresses, phone numbers and order details of 39,798 customers were exposed. Seed phrases and private keys were not affected, but the phishing risk is substantial.
August 21, 2026 7:26 PM

Restoring a Seed on Another Manufacturer's Wallet: What BIP39 Guarantees and What It Does Not
Your seed is yours; the device belongs to a company. This article explains what the open BIP39 standard actually guarantees, why a wrong derivation path makes a full wallet look empty, and the test that settles both in twenty minutes.
August 5, 2026 10:33 PM

$130 Million Gone Because the Randomness Was Predictable: Which Hardware Wallet You Can Still Buy
The Coldcard flaw proved the most respected wallet is not the safest. Which vendor has which track record – and why now is the wrong moment to pause your savings plan.
August 24, 2026 1:22 PM

Phantom Wallet Ends Sui and Monad Support: What to Do Before the Deadlines
Phantom Wallet removes Monad from its app on August 26 and Sui on September 24. The balances are not lost, but only one of the two ways out leaves your tax position untouched.
August 20, 2026 4:24 PM

Bitcoin Across Multiple Wallets: How Austria Works Out the Acquisition Cost
Bitcoin spread across several wallets? How Austria works out the acquisition cost and the rolling average price for tax purposes.
September 28, 2026 10:26 AM

Phantom Wallet and Solscan: What a Solana Transfer Really Costs and Where It Fails
A transfer on Solana costs 0.000005 SOL, a new token account ties up 0.00148844 SOL once — both values measured on-chain by us today. This practical guide shows how to set up Phantom, how to get there from the exchange, how to read Solscan and what applies for tax in Germany.
September 17, 2026 4:14 PM

D'CENT App Wallet: How to Tell If Your Recovery Phrase Has to Move Now
Manufacturer IoTrust reports suspicious asset transfers in the D'CENT app wallet and asks users to move their holdings. One question decides the matter: has your recovery phrase ever been entered into the app?
September 2, 2026 7:44 AM

MyDoge Ends Doginals and DRC-20 Support: What Holders Should Know After September 17
Recap as of September 27, 2026: infrastructure provider Maestro had announced it would discontinue its Dogecoin services on September 18, 2026, with MyDoge withdrawing support for Doginals and DRC-20 a day earlier. Our own survey of September 2 showed that nothing about the shutdown could be found on the public pages of those involved.
August 31, 2026 7:20 AM

Browser Extensions as Wallet Thieves: How a Sports App Became a Seed Phrase Collector
In August 2026 the security firm Socket disclosed two separate campaigns: 40 confirmed malicious Firefox extensions and 19 for Chrome and Edge, all of them from the official marketplaces. Nine of them were harmless sports apps that only turned into wallet thieves through an update.
September 25, 2026 4:11 AM

Bitget Hack of $351 Million: What to Check at Your Crypto Exchange Now
Bitget reports unauthorised outflows of around $351.6 million and has suspended withdrawals. For existing customers in Europe, that closes the one route MiCA had left them.
September 13, 2026 10:19 PM

Reporting Duty for Wallet Makers: What Has Applied Since September 11, 2026
Since September 11, 2026, anyone offering a wallet commercially in the EU must report an actively exploited vulnerability within 24 hours and inform the affected users. What Article 14 of the EU Cyber Resilience Act requires, where the limit of interpretation lies, and what you should take from it for your own custody.
September 7, 2026 7:26 PM

Stolen Keys Beat Code Flaws: Why the Private Key Is the Way In for 2026 Crypto Hacks
Compromised private keys overtook smart contract code flaws as the most common attack route for the first time in 2026. What sits behind the shift, and how to check your own setup for its single point of failure.
September 1, 2026 7:27 AM

Clipboard Attack: How Malware Swaps the Wallet Address You Copied
A clipper replaces the receiving address between copying and pasting with the attacker’s, and your wallet’s checksum notices nothing. What Microsoft and the Federal Office for Cybersecurity have documented, and which check really makes the attack come to nothing.
August 23, 2026 4:36 PM

Operation ASTERIX: How a Fake Support Call Delivers a Counterfeit Wallet App
Security researchers analysed an open server on which a phone system, phishing interfaces and cloned wallet programs all came together. The largest list of numbers was the German one.
April 27, 2026 10:30 AM

Win $5,000 in BTC: Tangem Launches Exclusive 2026 Prize Draw
Tangem announces a massive prize draw with $5,000 in BTC and iPhone 17s up for grabs. Secure your crypto and enter today using our exclusive link.
December 22, 2020 3:49 PM

Crypto Wallet Provider Ledger Hacked: Data Leak Results in Phishing Scams
Ledger, a cryptocurrency wallet provider has encountered a data breach. The official Twitter account of the hardware wallet tweeted that they have been alerted to the dump of a client database.
December 28, 2018 3:02 PM

How To Use a Trezor Wallet?
Trezor is a hardware wallet which gives exceptional security for managing Bitcoin and other cryptocurrencies private keys.It incorporates and deposits personal keys securely and enables users to carry trade without an Internet link. Trezor grants its users with numerous benefits, […]
October 2, 2026 7:16 AM

$1.26 Billion in Three Months: Crypto Hacks Hit Their 2026 High
The security firm CertiK counts around $1.26 billion in damage from 247 incidents for the third quarter of 2026. September was the worst month of the year with 99 cases, and this is the background and what it means for your custody.
September 30, 2026 1:23 PM

NEAR Intents Blocks $50 Million From the Bitget Hack: Why THORChain Let the Swaps Through
A cross-chain protocol says it stopped more than $50 million in transfers from the Bitget attack and froze $503,000. The case shows who can halt funds in transit and what that means for your custody.
More from CryptoTicker
