# Coldcard Firmware Now Demands 65 User Key Presses After a Five-Year Seed Defect

The update hardens new wallets, but it cannot repair a seed generated on affected firmware, so holders must create fresh keys and move their coins themselves.

- Published: 2026-08-23T05:46:20.809Z
- Canonical: https://polylog.news/crypto/2026-08-23/coldcard-firmware-now-demands-65-user-key-presses-after-a-fi
- Publisher: Polylog (Crypto desk)
- Section: crypto
- Sources: [CryptoSlate](https://cryptoslate.com/coldcard-now-requires-65-key-presses-after-seed-exploit-while-exposed-funds-still-must-move/), [Rekt News](https://www.rekt.news/)

Coinkite, the Canadian manufacturer of the Coldcard bitcoin hardware wallet, has shipped firmware 5.6.1 and 1.5.1Q, which change how the device creates a wallet. A new seed can no longer be produced from the device's internal randomness alone. The user must now contribute physical entropy: at least 65 key presses at unpredictable intervals, 50 rolls of a six-sided die, or 128 coin flips. [CryptoSlate reports](https://cryptoslate.com/coldcard-now-requires-65-key-presses-after-seed-exploit-while-exposed-funds-still-must-move/) that the release hardens new wallet creation but does nothing for a seed already made on an affected version.

The root cause was not an attacker's novel research. It was an implementation defect in the random-number code the device depends on, present since firmware 4.0.1 in March 2021. The defect weakened the true random number generator, reducing the effective entropy of seeds on Mk2 and Mk3 units to roughly 40 bits, a search space small enough for a well-resourced attacker to reconstruct private keys. Exploitation began on 30 July 2026, and Coinkite issued an emergency hotfix the following day. [Reporting on the incident](https://cryptobriefing.com/coldcard-firmware-update-114m-exploit/) put the resulting theft at about 1,816 BTC, worth roughly $114 million at the time. Rekt News has [catalogued the episode](https://www.rekt.news/) alongside this year's contract exploits.

The asymmetry matters. Installing the update protects the next wallet, not the current one. Every holder who generated a seed on a vulnerable release between 2021 and July 2026 has to build a new wallet and move the balance. That means paying fees, rebuilding multisignature arrangements, and publishing a transaction that reveals the consolidation to anyone watching the chain. Coins that sat untouched for years, precisely the behaviour self-custody encourages, are the ones most likely still exposed.

Self-custody removes counterparty risk and replaces it with implementation risk. That trade-off is defensible only if the implementation is reviewed as rigorously as a custodian's balance sheet is audited, and a five-year-old entropy bug in a widely used open-source library indicates it was not.

## What this means

The exposed value sits with long-term bitcoin holders who followed the standard self-custody advice, and the loss channel is irreversible theft rather than a price move. Each incident of this kind pushes a portion of risk-averse holders toward exchange-traded funds and qualified custodians, which converts self-directed holdings into fee-earning assets under management for issuers such as BlackRock and Fidelity and into custody revenue for Coinbase. The counter-pressure is that the fix is public, cheap, and verifiable, which is more than most custodial failures offer.

## What to watch

- Whether the coins identified as sitting on weak seeds actually move on-chain in the coming weeks, which shows how many owners received and acted on the warning.
- Whether other wallet and signing-device vendors that use the same random-number library publish advisories, which would widen the exposure from one brand to a class of devices.
- Whether spot bitcoin fund inflows and custodian onboarding accelerate while the story is live, the clearest measure of holders trading key management for counterparty risk.
