The latest firmware introduces mandatory user entropy for every new wallet creation. Owners are now required to provide randomness directly through at least 65 key presses, 50 private dice rolls, or 128 physical coin flips. This input supplements the device's internal random-number generator, ensuring that no single component dictates the security of the resulting seed. Coldcard emphasizes that these inputs must remain strictly private, as any recorded sequence could potentially be used to reconstruct the wallet.
Updating the device does not retroactively secure existing wallets created under previous firmware versions. Affected users—specifically those with Mk2, Mk3, Mk4, Mk5, or Q models generated before recent security patches—must move their funds to a completely new, independently verified wallet. Importing old seed phrases into updated firmware fails to mitigate the original weakness. While a BIP-39 passphrase adds a layer of security, it does not resolve the underlying entropy defect, necessitating a full migration.

Comments (0)
No comments yet. Be the first!