๐Ÿ“… Rabu, 26 Agustus 2026 ยท --:-- WIB Ikuti kami
Ecosystem โ–ผ
ID โ–ผ
Coldcard Rilis Firmware Baru Pasca Insiden 1.082 BTC - Namun Pemilik Seed Lama Tetap Wajib Kosongkan Dompet

Coldcard Releases New Firmware After 1,082 BTC Incident - But Old Seed Owners Must Still Empty Wallets

Coldcard has finally released firmware 5.6.1 for the Mk4 and Mk5 series, as well as 1.5.1Q for the Q version on August 20. This step was taken following a three-week security audit that followed an emergency fix on July 31.

The update comes as a follow-up to the 1,082 BTC theft incident that exploited a loophole in the device’s seed phrase generation method. The incident highlighted that hardware wallet protection can collapse due to a single code flaw.

However, this patch only works going forward - it cannot fix past errors.

Why Hardware Devices Do Not Guarantee Security

The root cause of this vulnerability stems from a code update in March 2021. Instead of calling the built-in hardware RNG (Random Number Generator) component from the STM32 chip when generating a seed phrase, the wallet’s firmware instead called a deterministic MicroPython fallback system.

The consequence of this incorrect call was costly. Seed phrases on older Mk2 and Mk3 devices were generated with only about 40 bits of effective entropy. Newer releases such as the Mk4, Mk5, and Q are slightly stronger at 72 bits, but both points remain far below the absolute security standard of 128 bits.

With such a low level of entropy, hackers with brute-force computing power could derive private keys and drain the wallets without having to touch the hardware at all. This situation aligns with a recent Bloomberg headline that labeled the incident as a hack on the “Fort Knox of Bitcoin wallets.”

The Only Way to Save Assets

For users of older firmware, updating the software system alone is not enough. Seed phrases that have already been generated with weak entropy cannot be repaired through a firmware update. Even adding a BIP-39 passphrase still does not cover this basic seed vulnerability.

Users who fall into the affected list must take three steps: update the device’s firmware, create a new seed phrase from scratch, and transfer their entire Bitcoin balance to the new wallet.

Vulnerable versions include Mk4 and Mk5 users prior to release 5.6.0 or Edge 6.6.0X, Coldcard Q users prior to version 1.5.0Q or Edge 6.6.0QX, as well as owners of Mk2 and Mk3 models on versions 4.0.1 to 4.1.9.

Going forward, Coldcard is tightening seed generation procedures. In this latest firmware, every new wallet must obtain at least one additional source of entropy from the user. The requirement demands a minimum of 65 random, unexpected keypresses, 50 physical dice rolls, or 128 real coin tosses.

This update also tightens the multi-step PSBT verification process prior to transaction signing, as well as strengthening security limits on USB connections and subsequent firmware updates.

For those of you whose devices are on the affected list, this remote breach threat is not just a test scenario - empty your old wallet before another entity does it first.

Reported from crypto.news.


Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.

Bagikan artikel ini:
๐Ÿ“ฉ KABAR BITCOIN 1 MENIT

Berita kripto harian, langsung ke inbox

Ringkasan 1 menit untuk kamu yang selalu bergerak. Gratis, kapan saja bisa berhenti.

Total
0
Share