Coldcard now makes users add randomness. Invisible wallet trust is officially over.
The fix turns seed generation from a hidden hardware promise into a user-facing ceremony, and old seeds don't get saved by updating.

CryptoVibe Desk · coldcard · bitcoin · wallets

- →Coldcard firmware 5.6.1 and 1.5.1Q now require user entropy for new seeds after a July RNG weakness disclosure.
- →The real change is design, not only code: users must now help create randomness before trusting new wallet secrets.
- →Watch whether Coldcard users actually rotate affected seeds, because firmware updates do not repair secrets already made from weak randomness.
- seed → A seed is the secret backup phrase that controls a crypto wallet's funds.
- entropy → Entropy means unpredictability, which makes a secret hard for someone else to guess.
- RNG → An RNG is a random number generator, the part that creates unpredictable data for wallet secrets.
- PSBT → A PSBT is a Bitcoin transaction file that can be reviewed and signed before broadcast.
Coldcard changed how new wallet seeds get made. On August 20, Coinkite released firmware 5.6.1 for Mk4 and Mk5, and 1.5.1Q for Q. The changelog says newly generated master seeds, Temporary Seeds, and CCC key C now require user-supplied entropy.
That means dice rolls, coin flips, or keyboard mashing now sit in the seed path. The device still uses its own randomness sources. User input gets mixed in on top. The tradeoff is friction for visibility.
This is the right kind of ugly fix. Coldcard's July advisory says versions from 2021 to July 2026 produced poor entropy. It also says secrets made during that period should be regenerated and funds moved on chain immediately. Updating the device does not repair an old seed. If your bag was born on affected firmware, the problem is already in the secret.
At the mechanism level, this was not a hardware RNG dying in production. Coinkite's disclosure history says `rng_get()` resolved to MicroPython's Yasmarang software PRNG. It should have pointed to the board-specific hardware path. That is a build integration problem.
The numbers explain why this is not cosmetic. Coinkite's advisory says Mk3 affected entropy was about 40 bits. For Mk4, Mk5, and Q, it says affected entropy could be as low as about 72 bits. The target was 128 bits. That gap is the only number that matters.
Firmware 5.6.1 also changes the surrounding guardrails. The changelog says key mashing requires at least 65 presses. It also says staged transaction bytes are re-verified before signing. If a changed PSBT reaches the signer, the device aborts. That matters because review and signature must bind to the same bytes.
The broader pattern is familiar to anyone who has shipped security code. Randomness cannot be a hidden dependency with no user-visible failure mode. It is like cache invalidation, except the stale value is your money's root secret.
An AI-assisted review also produced 85 candidate findings. Coinkite says issues were fixed, rejected, accepted, or tracked elsewhere by June 26. That does not prove the device is broken. It proves wallet security is mostly boring state handling until it isn't.
The new model is cleaner, for now. Coldcard moved seed generation away from implicit hardware trust and toward mandatory user entropy. That makes the ceremony slower. It also makes the failure harder to hide.
Coinkite is leaving the riskiest work outside the device flow: affected-seed migration. Old secrets remain weak after firmware 5.6.1 and 1.5.1Q install, so docs are not enough.
By September 30, watch whether Coinkite publishes a measurable migration prompt or telemetry-free upgrade notice that clearly separates updated firmware from regenerated seeds.
Primary links and supporting reads used by the desk for this story.
Forward this.











