星球日报
星球日报|Aug 20, 2026 15:29
[Existing Mnemonics Cannot Be Fixed Through Updates, Coldcard Advises Affected Users to Regenerate Mnemonics and Migrate Assets] Odaily Planet Daily reports that Coldcard has released the latest firmware versions 5.6.1 (Mk4/Mk5) and 1.5.1Q (Q). This update follows a three-week security review after the emergency patch on July 31, focusing on addressing security risks stemming from previous mnemonic generation attacks. Each newly generated mnemonic must incorporate at least one user entropy source, including at least 65 irregular key presses, 50 physical dice rolls, or 128 physical coin tosses, combined with fresh entropy provided by STM32 TRNG, SE1, and SE2. The new firmware also introduces staged PSBT verification immediately before signing, strengthens USB connection and firmware update boundaries, improves the Delta Mode isolation mechanism, fixes active wallet backup issues, enhances random number generator initialization and fault checks, adjusts default SIGHASH settings, and includes multiple security and correctness improvements. Coldcard stated that this update aims to further reduce the risk of device attacks. The official reminder notes that the updated firmware cannot fix mnemonics generated by previously affected firmware. If a user's mnemonic falls within the scope of this security advisory, they should first update their device, then generate and verify a completely new mnemonic, and migrate funds to a new wallet. Coldcard recommends all Mk4, Mk5, and Q users promptly update their devices and verify the signature of the downloaded firmware.
+4
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads