Coldcard firmware update adds 65-key-press protection for new wallets
Firmware 5.6.1 and 1.5.1Q harden wallet creation after seed exploit, but existing seeds remain exposed.

Coldcard, a Bitcoin hardware wallet, has released firmware updates 5.6.1 and 1.5.1Q that change how new wallet seeds are generated. The updates introduce a 65-key-press confirmation process designed to mitigate a recently disclosed seed exploit.
According to the manufacturer, the new firmware hardens the creation of new wallets, but it cannot repair a seed that was generated on an affected release. Users who created wallets on vulnerable firmware are still advised to move their funds to a new wallet.
What the exploit affected
Details of the exploit were not fully described in the announcement, but the firmware change indicates it involved the seed generation process. The extra 65 key presses are intended to add a physical randomization step that prevents certain predictable outcomes.
Coldcard's guidance is clear: wallets created before the update on compromised versions should be considered at risk. Funds from those wallets need to be transferred to a newly created wallet using the patched firmware.
The firmware updates are available for download from Coldcard's official channels. Users should verify the integrity of the firmware before installing it.