Coinkite, the maker of the Coldcard Bitcoin {hardware} pockets, launched new customary firmware on Aug. 20 that forces customers so as to add bodily randomness every time they generate a seed.
House owners who generate a seed after putting in the present mounted launch can use the hardened course of. House owners nonetheless counting on a seed produced by affected firmware should generate one other seed and switch the funds except that pockets meets the dice-roll exception.
Throughout customary seed creation, each seed combines recent gadget entropy with one required human enter supply: at the least 65 key presses made at unpredictable intervals, 50 rolls of a bodily six-sided die, or 128 bodily coin flips. The requirement reduces reliance on the pockets’s random-number generator alone.
Coldcard’s present safety standing recommends model 5.6.1 for Mk4 and Mk5 gadgets and 1.5.1Q for Q gadgets. The advisory’s publicity record is wider and track-specific. Coinkite’s official migration steering covers Mk2 and Mk3 firmware 4.0.1 by means of 4.1.9; Mk4 and Mk5 customary firmware earlier than 5.6.0 and Edge firmware earlier than 6.6.0X; and Q customary firmware earlier than 1.5.0Q and Edge firmware earlier than 6.6.0QX.
Block’s impartial technical evaluation makes use of a broader Mk2 and Mk3 boundary that features model 4.0.0. House owners of that launch shouldn’t deal with the seller boundary as proof of security.
Putting in mounted firmware doesn’t change an previous seed. Except the advisory’s cube exception applies, Coinkite’s migration information tells affected customers to generate a genuinely new seed, confirm its backup and pockets fingerprint, verify a receiving deal with on the gadget, ship a small take a look at transaction, after which switch each steadiness tied to the previous seed. Cloning or restoring the pockets doesn’t create a brand new seed.
Migration is just not required for this RNG flaw when the person added at the least 50 honest, impartial and personal bodily die rolls by means of the affected workflow and by no means recorded or uncovered the sequence. Fewer rolls, or uncertainty about these situations, means the person ought to migrate.
Block traced the unique defect to code that would route requests to a deterministic MicroPython fallback as a result of a function flag outlined as zero was handled as current. Obligatory human enter provides outdoors entropy to new customary seeds, limiting harm if gadget randomness fails once more. It can not retroactively add entropy to a seed that already exists.
Coldcard treats the blended circulation in another way from the superior Cube Rolls Solely choice. That mode excludes {hardware} randomness and requires 50 rolls for a 12-word seed or 99 for a 24-word seed.
The firmware package deal reaches signing and information paths too. It binds USB evaluation to a staged PSBT checksum, rechecks transaction bytes earlier than signing, blocks SIGHASH_SINGLE modes by default, restricts USB downloads to the present encrypted-session end result, and validates firmware file size. It provides persistent RNG-fault stops, a boot-time hardware-RNG linkage examine, extra Delta Mode isolation, and active-wallet backup conduct.
The standing web page lists focused supply evaluation, a real-device RNG-path take a look at, and a reproducible construct and dice-path hint, however Coldcard says they don’t quantity to a full audit of each mounted binary. Coinkite says some prospects suffered extreme losses and regulation enforcement is investigating, however it has not revealed a verified sufferer depend or loss complete.



