Coldcard firmware update requires 65 presses but cannot fix exposed seeds
Coldcard releases firmware 5.6.1 and 1.5.1Q to harden new wallets, but affected seeds still need to be moved.

Coldcard has released firmware versions 5.6.1 and 1.5.1Q to address a seed-generation exploit. The update strengthens the process for creating new wallets, adding an extra security step that now requires 65 key presses during setup.
However, the company warns that the patch does not repair seeds that were generated on an affected release. Users who may have been exposed must transfer their funds to a wallet created on the updated firmware.
No fix for existing seeds
The vulnerability affected wallet creation on certain earlier firmware versions. While the new releases prevent the issue from occurring on newly initialized devices, any seed produced under the vulnerable code is still at risk.
Coldcard advises affected users to generate a new seed after updating and move all funds to the freshly created wallet. The firmware updates are available through the official update channel.