COLDCARD Firmware Update 5.6.2 & 1.5.2Q: Verifiable Seed Mixing; Continued Security Review; and EDGE 6.6.1X/6.6.1QX
COLDCARD firmware 5.6.2 for Mk4/Mk5 and 1.5.2Q for Q restore visibility into the device-generated input used during seed creation and add a standalone tool for independently checking dice-roll or coin-flip mixing.
The release also includes changes from our continuing review of transaction validation, USB communications, Virtual Disk handling, firmware upgrades, temporary wallets, Delta Mode, and other security boundaries.
Given the volume of security reports coming to us and appearing across Bitcoin hardware and software projects, our recommendation for the next while is simple: treat every applicable COLDCARD firmware release as a critical update and upgrade promptly.
We strongly recommend that all COLDCARD Mk4, Mk5, and Q users install 5.6.2 for Mk4/Mk5 or 1.5.2Q for Q from our official firmware downloads page.
We are grateful to @drk1wi, @hitechhayekian, @Amiga500, Huzaifa Jawaid, “FreeZ Agent,” “Rety,” @KirillCherikov, @instagibbs, Karma-X, Shiny (@bigshiny0), Mike Rahel (@itooshatonamask), Mars (@Marsmensch), and PortlandHODL for reporting issues, contributing code, reproducing edge cases, sharing ideas, and independently reviewing the remediation. We also thank @danilotg and @spaceainot for post-incident implementation, testing, release, tooling, and disclosure-policy work. Each finding still has to be reproduced and evaluated within its actual scope, but this scrutiny is making COLDCARD stronger.
Thank you for the many messages of support since the fixes shipped. COLDCARDs are in stock, and we’re working to keep up with the increased demand. We appreciate your patience while we get orders out. Development continues: we’ll keep improving the product and releasing new firmware.
We’ll keep publishing concrete, inspectable changes as this work proceeds.
View and Verify Seed Mixing
Every newly generated master seed, Temporary Seed, and generated CCC Key C still requires one user-sourced entropy method:
- at least 65 key presses with unpredictable timing;
- at least 50 rolls of a physical six-sided die; or
- at least 128 physical coin flips.
The standard workflow combines that input with fresh device entropy from the STM32 TRNG, SE1, and SE2.
The new View TRNG Words menu item displays 24 BIP-39 words encoding the full 256-bit device-generated input before the user’s key presses, dice rolls, or coin flips are mixed in. All 256 bits participate in the calculation, including when creating a 12-word wallet. On Q, the 24-word grid begins on a fresh screen so the words remain together.
This restores visibility that existed in the earlier dice-roll workflow but was inadvertently absent from firmware 5.6.1 and 1.5.1Q.
The firmware source now also includes the public-domain, dependency-free
verify_seed_mix.py
tool. It can independently recompute a final 12- or 24-word seed from the
displayed TRNG words and the complete dice-roll or coin-flip sequence. It does
not support key-mashing input. This complements
rolls.py,
first published in October 2020, which performs the corresponding offline
calculation for 24-word seeds created through the separate Dice Rolls Only
workflow. rolls12.py
covers the 12-word variant.
Keep every part of this process secret. Anyone who obtains the resulting seed—or both the displayed TRNG words and your complete dice-roll or coin-flip sequence—can recreate the wallet and steal its funds. Notes, photographs, clipboard contents, terminal history, logs, and backups may retain this information. Run the verification tool only on an offline computer you trust. The safest approach is to use one complete seed-generation run only to prove the math, never fund that wallet, then discard it and start again. Generate new TRNG words and use fresh, unrecorded rolls or flips for your actual master seed.
USB Communications
- USB ncry v3 adds authenticated encryption with direction-separated keys and replay protection.
- The unused USB CDC/VCP serial interface has been removed from normal operation and keyboard-emulation mode.
Transaction Validation and UTXO Handling
- COLDCARD warns when a transaction’s block-height
nLockTimeis more than ten years beyond the Bitcoin height known to the firmware. - The UTXO cache now retains up to 128 entries across restarts.
- Cancelled PSBTs no longer commit claimed input amounts to the UTXO cache. Amounts are committed only after signing and only for inputs COLDCARD actually signed.
- Single-signature SegWit change amounts are cached during finalization so understated input amounts can be detected instead of silently trusted.
- Duplicate singleton keys in PSBT maps are rejected.
- BIP-322 Proof of Reserves rejects foreign inputs, including inputs disguised with forged key-path metadata or partial signatures.
- P2SH-P2WSH inputs with missing or incorrect redeem scripts are rejected instead of proceeding with an unknown fee.
- PSBTv2 transactions with out-of-range transaction versions are rejected, matching the PSBTv0 parser.
- On Mk4/Mk5, BIP-322 message signing with WIF Store keys requires an unrestricted HSM message-signing policy.
Firmware and Virtual Disk Boundaries
- Signing stops if a Virtual Disk firmware import overwrites the reviewed PSBT. Thanks to Huzaifa Jawaid.
- A pending firmware upgrade is cancelled if its staged image is overwritten before approval. Thanks to Huzaifa Jawaid.
- Cyclic FAT chains in Virtual Disk imports are rejected instead of causing the device to hang.
- Virtual Disk files with FAT metadata inconsistent with their declared size
are rejected. This fixes an integer underflow in
psram_copy_fileandpsram_mmap_filethat could permit out-of-bounds PSRAM writes, reads, or mappings from a compromised USB host. - Firmware images extending beyond the world-checksum-covered flash region are rejected.
Wallet-State and Policy Boundaries
- With an empty master wallet and an active Temporary Seed, imports and backup restores remain temporary instead of becoming master-wallet changes.
- Change Main PIN is hidden while a Temporary Seed or BIP-39 passphrase wallet is active.
- In Delta Mode, attempting to view or activate a duress-wallet secret from the Trick PINs menu wipes the seed instead of revealing it.
- Non-ASCII BIP-39 passphrases are rejected at USB, saved-passphrase, note, and password entry points instead of deriving wallets incompatible with BIP-39-normalizing software.
- Single-Signer Spending Policy now provides a block-height reset from the Last Violation screen after a policy bypass, matching CCC behavior.
Simulator Fix
The COLDCARD simulator no longer crashes during Bless Firmware because of a desynchronized LED pipe, and it now records its firmware-greenlight state correctly.
This is a developer-tooling fix and does not change the security behavior of a physical COLDCARD. Thanks to @hitechhayekian for the report and fix.
Important Seed Reminder
Installing this update does not make an existing vulnerable seed safe.
If your seed may have been generated on affected firmware from 2021 through July 2026, create a completely new seed using fixed firmware and move your funds by following our seed-generation advisory.
The July 31 firmware corrected the seed-generation failure for new seeds. The August 20 release added required user-sourced entropy and further hardening. This release adds verification and additional security work, but it does not change the migration guidance for seeds already generated on affected firmware.
Upgrading alone is not sufficient.
Our team remains heads down reviewing security reports and helping affected users upgrade, create new seeds, and complete their migrations. Support and other contact channels are handling unusually high volumes, so responses may take longer than usual.
Verified guidance remains available on the Security Status page.
How to Update
- Download firmware only from the official COLDCARD downloads page.
- Follow our instructions to verify the SHA-256 hash and PGP signature.
- Install it using the MicroSD upgrade procedure.
- After restarting, select Advanced > Upgrade > Show Version.
- Confirm that the device reports 5.6.2 on Mk4/Mk5 or 1.5.2Q on Q.
- If the July seed advisory applies to you, complete the separate seed migration. Upgrading alone is not sufficient.
The complete standard-release list is available in the firmware changelog.
Security reports can be submitted privately to security@coinkite.com under our responsible-disclosure policy. Customers who need assistance should contact our support team.
EDGE 6.6.1X and 6.6.1QX — August 31, 2026
We also released EDGE 6.6.1X for Mk4 and 6.6.1QX for Q.
EDGE is a separate preview track. It has not been qualified and tested to the same standard as normal releases and is recommended only for developers and early adopters doing experimental work.
These builds are synchronized with the standard release lines through 5.6.1 and 1.5.1Q. Their shared changes include:
- Reject cyclic FAT chains during Virtual Disk imports instead of hanging.
- Abort a pending firmware upgrade if its staged image is overwritten before approval. Thanks to Huzaifa Jawaid.
- Detect and abort signing if a Virtual Disk firmware import overwrites the reviewed PSBT. Thanks to Huzaifa Jawaid.
- Allow uncompressed WIF keys in WIF Store.
- Speed up multisig address generation and PSBT-input verification.
- Use predictable sequential filenames when PSBTs are repeatedly processed through MicroSD or Virtual Disk.
- Prevent USB hosts from enrolling, deleting, listing, or exporting Multisig or Miniscript wallet configurations while Spending Policy mode is active.
- Compact repeated transaction warnings, relative timelocks, and unusual change-path summaries. Individual details remain available in the transaction explorer.
- Generate distinct MuSig2 nonces for different aggregate-key derivations of the same participant set.
- Harden MuSig2 session handling for foreign MuSig2 inputs and differing witness UTXO data.
- Preserve incomplete MuSig2 sessions while waiting for cosigner public nonces.
- Prevent PSBT corruption when the same MuSig2 participant performs multiple signing rounds through Key Teleport.
- Track remaining multisig and Tapscript signers separately for each PSBT input.
- Limit MuSig2 participant lists to 32.
- Generate unique names for multisig wallets created from PSBTs with identical M-of-N parameters.
- Correctly identify consolidations containing zero-value
OP_RETURNoutputs without misclassifying other zero-value external outputs. - Prevent duplicate WIF Store keys and multisig wallets after restart.
- Require HSM policies to explicitly allow a path before signing BIP-322 messages with WIF Store keys.
- Reject foreign inputs in BIP-322 Proof of Reserves transactions.
- Prevent PSBT uploads from being mistaken for partial firmware uploads.
- Reject BIP-388 wallet-policy imports with non-ASCII or non-printable names.
- Reject duplicate singleton keys in PSBT maps.
- Restore View TRNG Words for the complete 256-bit device-generated input before user entropy is mixed.
- Fix the Bless Firmware simulator crash. Thanks to @hitechhayekian.
- Fix invalid signatures on transactions containing both SegWit v0 and Taproot inputs.
- Hide Change Main PIN while a Temporary Seed or BIP-39 passphrase wallet is active.
- Keep imports and backup restores temporary when the master wallet is empty and a Temporary Seed is active.
- Do not misidentify future-version SegWit outputs as Taproot change.
- Reject unsupported Taproot leaf versions during PSBT signing. Only Tapscript
0xc0is supported. - Serialize future even TapLeaf versions correctly.
- Report the correct transaction ID when finalized MuSig transactions contain scriptSigs.
- Remove the unused USB CDC/VCP serial interface from normal operation and keyboard emulation.
See the complete tagged EDGE changelog and verify the firmware through the official downloads page before installing.