
Coinkite launched a brand new safety improve to strengthen seed phrase technology by requiring user-supplied entropy blended with improved machine randomness.
Coinkite introduced firmware 5.6.1 for Coldcard Mk4 and Mk5 gadgets and 1.5.1Q for the Coldcard Q in a Thursday weblog publish.
The discharge requires newly generated seeds to incorporate user-supplied entropy by not less than 65 keypresses with unpredictable timing, 50 rolls of a six-sided die or 128 coin flips. That enter is mixed with randomness from a number of machine sources, together with its safe parts and {hardware} random-number generator (RNG).
The mixed randomness is used to create the pockets’s seed phrase and is meant to maintain its personal keys unpredictable even when one of many machine’s entropy sources fails.
Coinkite advised customers to improve instantly, emphasizing that current seed phrases stay susceptible even after upgrading and should be changed with new seeds earlier than migrating funds.
Confirmed losses from the Coldcard exploit reached 1,778 Bitcoin (BTC), price about $112 million, in response to an Aug. 14 report by Galaxy Analysis. This makes the Coldcard hack the third-largest cryptocurrency exploit of 2026, in response to information aggregated by DefiLlama.
Coldcard provides transaction and USB safeguards
The corporate’s July 31 firmware replace had already mounted the seed-generation failure for newly created wallets. Thursday’s launch follows three weeks of broader safety evaluation and likewise provides safeguards round USB information dealing with, transaction signing and {hardware} randomness.
Coinkite stated the replace addresses a theoretical assault involving a compromised laptop USB port by re-verifying transactions instantly earlier than signing. The firmware additionally introduces further {hardware} RNG checks and a boot-time check designed to confirm that the pockets is utilizing its supposed {hardware} path.
Associated: Cybersecurity agency unveils crypto phishing marketing campaign concentrating on 885,000 telephone numbers
Different adjustments limit USB downloads to the machine’s most up-to-date output and require an encrypted session, whereas sure Bitcoin signature hash modes that permit transaction outputs to stay modifiable are actually blocked by default.
Coinspect launches weak-seed detection software
Different firms are additionally launching software program to establish wallets doubtlessly uncovered by weak seed technology.
Blockchain safety firm Coinspect revealed Unlukey, a free public software for figuring out pockets addresses generated from weak seed phrases. The primary iteration of the software goals to breed identified weak seed technology and test whether or not public addresses belong to the affected dataset, Coinspect stated in a Friday X publish.
Weak seed phrase technology was one of many predominant vulnerabilities that led to the Coldcard exploit. TRM Labs stated {that a} firmware bug from March 2021 weakened seed randomness on some Coldcard wallets, decreasing key power from 128 bits to 40 bits and making them “brute-forceable with out bodily entry.”
Journal: Contained in the ‘faux police raid’ that pressured a $1M Bitcoin switch















