Coinkite has released firmware updates for its Coldcard Mk4, Mk5, and Q hardware wallets following a critical randomness vulnerability that allowed attackers to steal over $114 million in Bitcoin. An AI-assisted security audit revealed that a 2021 configuration error downgraded seed entropy from 128 bits to 40 bits. The new firmware requires users to supply physical entropy via dice rolls, coin flips, or keypresses. However, owners of wallets generated between 2021 and July 2026 must still generate new seeds and migrate their funds to secure their assets.
Story comments
Loading comments…