Coldcard Firmware Update After $114M Theft Due to Seed-Generation Flaw
ID: 0e31737e-1799-5050-87f5-597dc9fcb8f0
STIX ID: report--0e31737e-1799-5050-87f5-597dc9fcb8f0
Feed Name: ThreatCluster
Coldcard has issued firmware 5.6.1 to address a critical seed-generation vulnerability that was exploited in an attack stealing $114 million (1,816 BTC) from users of Mk4, Mk5, and Q hardware wallets; the update enforces user-provided randomness for seed creation, strengthens transaction integrity checks, and includes other USB and multisig protections, while advising immediate firmware upgrades since previously generated seeds remain compromised and law enforcement is being assisted.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
