Close Menu
    Facebook X (Twitter) Instagram
    Cloud Tech ReportCloud Tech Report
    • Home
    • Crypto News
      • Bitcoin
      • Ethereum
      • Altcoins
      • Blockchain
      • DeFi
    • AI News
    • Stock News
    • Learn
      • AI for Beginners
      • AI Tips
      • Make Money with AI
    • Reviews
    • Tools
      • Best AI Tools
      • Crypto Market Cap List
      • Stock Market Overview
      • Market Heatmap
    • Contact
    Cloud Tech ReportCloud Tech Report
    Home»Crypto News»Altcoins»Coldcard now requires 65 key presses after seed exploit, while exposed funds still must move
    Altcoins

    Coldcard now requires 65 key presses after seed exploit, while exposed funds still must move

    August 23, 2026
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Coldcard now requires 65 key presses after seed exploit, while exposed funds still must move
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email
    murf


    Coinkite, the maker of the Coldcard Bitcoin hardware wallet, released new standard firmware on Aug. 20 that forces users to add physical randomness whenever they generate a seed.

    Owners who generate a seed after installing the current fixed release can use the hardened process. Owners still relying on a seed produced by affected firmware must generate another seed and transfer the funds unless that wallet meets the dice-roll exception.

    During standard seed creation, every seed combines fresh device entropy with one required human input source: at least 65 key presses made at unpredictable intervals, 50 rolls of a physical six-sided die, or 128 physical coin flips. The requirement reduces reliance on the wallet’s random-number generator alone.

    Coldcard’s current security status recommends version 5.6.1 for Mk4 and Mk5 devices and 1.5.1Q for Q devices. The advisory’s exposure list is wider and track-specific. Coinkite’s official migration guidance covers Mk2 and Mk3 firmware 4.0.1 through 4.1.9; Mk4 and Mk5 standard firmware before 5.6.0 and Edge firmware before 6.6.0X; and Q standard firmware before 1.5.0Q and Edge firmware before 6.6.0QX.

    bybit

    Block’s independent technical analysis uses a broader Mk2 and Mk3 boundary that includes version 4.0.0. Owners of that release should not treat the vendor boundary as proof of safety.

    Related Reading

    A flaw in Coldcard seed generation lets attackers recreate private keys from the press of a button

    Installing fixed firmware does not change an old seed. Unless the advisory’s dice exception applies, Coinkite’s migration guide tells affected users to generate a genuinely new seed, verify its backup and wallet fingerprint, confirm a receiving address on the device, send a small test transaction, and then transfer every balance tied to the old seed. Cloning or restoring the wallet does not create a new seed.

    The Daily Brief

    The signal, before the noise.

    Start your day with the crypto stories moving markets, decoded by CryptoSlate’s editors.

    One email. Everything that matters.

    Free to join. Unsubscribe any time.

    Whoops, looks like there was a problem. Please try again.

    You’re on the list. Your next Daily Brief is on its way.

    Migration is not required for this RNG flaw when the user added at least 50 fair, independent and private physical die rolls through the affected workflow and never recorded or exposed the sequence. Fewer rolls, or uncertainty about those conditions, means the user should migrate.

    Block traced the original defect to code that could route requests to a deterministic MicroPython fallback because a feature flag defined as zero was treated as present. Mandatory human input adds outside entropy to new standard seeds, limiting damage if device randomness fails again. It cannot retroactively add entropy to a seed that already exists.

    Flowchart showing when Coldcard users need only hardened seed creation and when affected seeds require an on-chain fund migration

    Coldcard treats the mixed flow differently from the advanced Dice Rolls Only option. That mode excludes hardware randomness and requires 50 rolls for a 12-word seed or 99 for a 24-word seed.

    The firmware package reaches signing and data paths too. It binds USB review to a staged PSBT checksum, rechecks transaction bytes before signing, blocks SIGHASH_SINGLE modes by default, restricts USB downloads to the current encrypted-session result, and validates firmware file length. It adds persistent RNG-fault stops, a boot-time hardware-RNG linkage check, more Delta Mode isolation, and active-wallet backup behavior.

    Related Reading

    CryptoBandits malware lets criminals use your USB drive to access crypto wallets – Microsoft warns

    The status page lists targeted source review, a real-device RNG-path test, and a reproducible build and dice-path trace, but Coldcard says they do not amount to a full audit of every fixed binary. Coinkite says some customers suffered severe losses and law enforcement is investigating, but it has not published a verified victim count or loss total.



    Source link

    quillbot
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Trump’s Hyperliquid Name-Drop Sends HYPE Charging Toward Record Highs

    August 22, 2026

    Binance To Remove Seven Spot Trading Pairs Including SUI And LTC Markets

    August 21, 2026

    Gnosis’ $136 rally masks a coming 350,000-token liquidity shock

    August 20, 2026

    Ripple- and Coinbase-funded PAC Spends $2M in Florida Race with Little Mention of Crypto

    August 19, 2026

    Bitcoin turned $10,000 into $870,000 in a decade where 87% of active stock funds failed to beat passive rivals

    August 18, 2026

    This public company quit solar for a $5 million Bitcoin bet, now it has just $166,000 in cash

    August 17, 2026
    aistudios
    Latest Posts

    The Only 4 Ways to Make Money With AI Videos in 2026

    August 23, 2026

    Top 6 AI Certifications That Can Make You Rich in 2026

    August 23, 2026

    AI vs. REAL FOOD ✨ Can These Hacks Actually Work?

    August 23, 2026

    Coldcard Firmware 5.6.1 Forces User Entropy Into Every New Seed After $100M Exploit

    August 23, 2026

    MiCA Is Coming For DeFi Vaults, But Regulation Will Be Difficult

    August 22, 2026
    bybit
    LEGAL INFORMATION
    • Privacy Policy
    • Terms Of Service
    • Social Media Disclaimer
    • DMCA Compliance
    • Anti-Spam Policy
    Top Insights

    Coldcard now requires 65 key presses after seed exploit, while exposed funds still must move

    August 23, 2026

    Local’s access to global crypto platforms could end under Nigeria’s proposed capital floor

    August 23, 2026
    Customgpt
    Facebook X (Twitter) Instagram Pinterest
    © 2026 CloudTechReport.com - All rights reserved.

    Type above and press Enter to search. Press Esc to cancel.

    bitcoin
    Bitcoin (BTC) $ 77,436.00
    ethereum
    Ethereum (ETH) $ 2,455.26
    tether
    Tether (USDT) $ 0.999829
    xrp
    XRP (XRP) $ 1.51
    bnb
    BNB (BNB) $ 697.67
    usd-coin
    USDC (USDC) $ 0.999873
    solana
    Solana (SOL) $ 95.01
    tron
    TRON (TRX) $ 0.343769
    hyperliquid
    Hyperliquid (HYPE) $ 80.03
    figure-heloc
    Figure Heloc (FIGR_HELOC) $ 1.00