Reviewed by our automated publish checklist (fact-grounding, duplicate detection, and SEO completeness checks) before going live — not a human editor. See editorial policy.
CoinBatmi feature visual — market neutral — Coldcard now requires 65 key presses after seed exploit, while exposed funds still must move
The 65-press barrier
Coldcard's new firmware demands 65 physical key presses to generate a single wallet. That is the first number any user sees after updating to 5.6.1 or 1.5.1Q, five times the previous 12-press flow. Coinkite shipped the change to close a seed-generation flaw that could leak entropy on affected devices.
The fix works for new wallets. It does nothing for the keys already in circulation.
What the exploit actually broke
The vulnerability lay in the hardware random-number generator during seed creation. On firmware 5.0.0 through 5.6.0 (Mk4) and 1.0.0 through 1.5.0Q (Mk3), an attacker with physical access or supply-chain interception could reduce the effective entropy of a 24-word seed. Coinkite's advisory confirms the flaw was in the RNG seeding path, not the BIP-39 derivation itself.
Patching the RNG for future seeds is a one-line firmware change. Recovering entropy that already left the device is not possible in software.
Why 65 presses changes the threat model
The 65-press requirement forces users to verify each word of the generated seed on the device screen before confirming. That raises the bar for evil-maid attacks during initial setup, an adversary now needs sustained physical control for minutes, not seconds. But it adds friction for every legitimate user, every time they initialize a Coldcard.
The Mk4's keypad is not designed for high-frequency entry; early adopters report hand fatigue and mispresses after the 40th confirmation. Coinkite has not published usability telemetry for the new flow.
Who holds the bag
Anyone who generated a seed on vulnerable firmware holds a key that may have reduced entropy. The only remediation is on-chain migration: create a new wallet on patched firmware, then send every UTXO to the new addresses. Coinkite has not issued a migration tool, a deadline, or a key-rotation policy.
The burden falls entirely on the user to recognize the risk, build a new wallet, and pay the network fees to move funds. For multisig participants, every cosigner must rotate simultaneously, a coordination problem the firmware does not solve.
What could force a timeline
Three events would change the calculus: a public proof-of-concept that extracts seeds from compromised devices, a documented theft traced to the RNG flaw, or a Coinkite advisory that sets a hard deprecation date for old firmware. Absent those, the 65-press wall is a forward-looking control, effective for new users, invisible to the installed base.
Frequently Asked Questions
+Does the 65-key press update fix my existing Coldcard wallet?
No. Firmware 5.6.1 and 1.5.1Q only harden new wallet creation. Seeds generated on vulnerable firmware remain at risk and must be migrated manually.
+How do I know if my seed was created on affected firmware?
Check the firmware version displayed at boot. Mk4 devices running 5.0.0 through 5.6.0 and Mk3 devices on 1.0.0 through 1.5.0Q are in the vulnerable range.
+What happens if I don't migrate my funds?
The seed stays in your device with potentially reduced entropy. If an attacker later demonstrates practical exploitation, funds sent to addresses derived from that seed could be stolen.
Reader desk
Discuss the signal
Verified readers · 2 comments per post / 24h
Checking your session…
No comments yet. Be the first verified reader to add context.
Preferences such as your theme stay on your device. Google Analytics runs under Consent Mode and only measures fully when you choose Accept all. We run no advertising trackers. See the Privacy Policy.
Reader desk
Discuss the signal
Verified readers · 2 comments per post / 24h
No comments yet. Be the first verified reader to add context.