Coinkite’s Coldcard 5.6.1 (Mk4/Mk5) and 1.5.1Q (Q) are the new recommended standard firmware, not a restore spell for old seeds. The company published that on 20 August 2026. Bitcoin traded at $77,768, up 7.7% over 24 hours, on our CoinGecko snapshot at 2026-08-22T00:54:57+00:00. Ether was $2,513.63, up 8.6%. The tape is loud. The custody file is quieter, and more important for anyone who generated a seed on affected firmware between 2021 and July 2026.
This is an update to our 2 August read: Coldcard’s weak-seed class was a live self-custody problem, not a rumor. The July 31 hotfix stopped the bad generator for new seeds. The 20 August release is the three-week review layer on top. It still does not repair a seed that already exists.
What happened
Coinkite’s 20 August 2026 blog post, COLDCARD Security Update: Seed Generation, Transaction Integrity, and Data Isolation, tells Mk4, Mk5, and Q users to install 5.6.1 or 1.5.1Q from the official downloads page, then confirm the version under Advanced > Upgrade > Show Version. The post is dated 2026-08-20 in the page’s BlogPosting schema.
The company frames the work as three weeks of review after the 31 July hotfix, including AI-assisted review and outside researchers. It says law enforcement is still investigating the thefts. It does not publish a new loss total in that post. We will not invent one.
A GET of coldcard.com/security/status during this 22 August 2026 run returned machine-readable JSON that lists Mk4/Mk5 5.6.1 and Q 1.5.1Q as current_recommended_releases. The same object still carried page_updated_at and verified_at of 2026-08-17, and it still says updating firmware does not repair an existing affected seed. postmortem_status was in_progress. existing_affected_seed_status was migration_required_unless_advisory_dice_exception_applies.
The July seed-generation advisory remains the migration document. Coinkite repeats, in the 20 August post and in the status JSON, that installing this update does not make an existing vulnerable seed safe.
Context
On 2 August we wrote that Coldcard’s seed-generation failure had turned a hardware-wallet brand into a migration queue. The first public warning sat on Coinkite’s own blog. Galaxy’s early August address tally was in the tens of millions of dollars of bitcoin, not a rounding error. That was the fire. This release is the mop-and-rebuild pass.
The 31 July line (5.6.0 / 1.5.0Q and the Edge and Mk2/Mk3 hotfixes) is still the minimum “fixed” cut in the status JSON. 5.6.1 / 1.5.1Q sit above that cut as the current recommended standard. Coinkite is explicit that 5.6.1 includes work unrelated to the original RNG bug: seed-generation policy, transaction review, USB handling, firmware-update validation, Delta Mode, and backups.
New standard seeds now require one user-sourced entropy method mixed with device entropy: at least 65 key presses with unpredictable timing, 50 rolls of a physical six-sided die, or 128 physical coin flips. The same rule applies to generated Temporary Seeds and generated CCC Key C. Dice Rolls Only stays an advanced path that excludes hardware randomness and needs 50 rolls for 12 words or 99 for 24 words. Holding a key no longer counts as repeated dice rolls.
On signing, Coldcard now re-checks a staged PSBT (a partially signed bitcoin transaction) right before it signs. If a connected host changed the transaction after the on-device review, signing stops and the device shows “Transaction modified.” Coinkite calls that a theoretical USB-host issue, not a claimed live theft path. SIGHASH_SINGLE modes that leave later outputs modifiable are blocked by default.
USB downloads are limited to the latest device result, need an encrypted session, and go stale after new uploads or sessions. Delta Mode now blocks several seed-export routes. Backup, clone, and Key Teleport full backup follow the wallet currently in effect, including a passphrase wallet, and warn before export. A passphrase-wallet backup holds the effective extended private key, not the parent seed words or the passphrase.
The firmware repo now points private reports at a SECURITY.md instead of a public issue. Independent checks listed in the status JSON still describe 5.6.0-era source review, a real-device TRNG test, and a reproducible build. Coinkite’s own caveat is that those checks do not equal a full audit of every binary, including 5.6.1.
Bitcoin’s 22 August bounce does not change that file. A $77,768 print can make a delayed migration feel expensive. It does not make an old seed safer. For the long cycle, see our Bitcoin history page. For the category tape, see Bitcoin news.
Our read
I am updating our 2 August view, not reversing it. Coldcard is still a migration story. 5.6.1 is the floor I want under a new seed on Mk4/Mk5 standard, and 1.5.1Q is the matching Q floor. It is not a patch you sprinkle on a 2021–July 2026 seed and call the wallet done. Our earlier piece, Coldcard weak seeds: Bitcoin cold storage under fire, still holds on that point.
The useful split is three buckets. Bucket one: devices that never generated a seed on affected firmware, or that already migrated, can treat 5.6.1 as the current recommended build and verify the signed file. Bucket two: seeds that used the advisory’s independent-dice exception stay in the exception Coinkite wrote, not in a new exception we invent. Bucket three: everyone else still needs a new seed on fixed firmware and a move. Firmware is the workshop. The seed phrase is the asset.
Required user entropy is the honest part of this release. A hardware wallet that will not let you skip the dice, the keys, or the coin flips is admitting that “the chip rolled the bits” was not enough defense in depth. That is a good product change. It is also a reminder that self-custody fails in the generator more often than in the steel. If you need the operational checklist, our wallet safety guide still starts with verify-then-fund, not trust-the-box.
Falsifiable claim: By 2026-09-05 23:59 UTC, https://coldcard.com/security/status.json will still list Mk4/Mk5 5.6.1 and Q 1.5.1Q under current_recommended_releases, and it will still state that a firmware update does not repair an existing affected seed. If Coinkite withdraws 5.6.1 or 1.5.1Q as the recommended standard, or if a primary Coinkite status/advisory update says an in-place firmware install remediates 2021–July 2026 seeds without migration, this read is wrong.
What to watch next
Watch the status JSON, not the social recap. The recommended version pair, existing_affected_seed_status, and postmortem_status are the three fields that can move without a new blog headline. A formal technical postmortem was still listed as in progress in the JSON we pulled on 22 August 2026.
Watch the signed downloads page. Coinkite’s own install steps are download from coldcard.com/downloads, verify SHA-256 and PGP, install from MicroSD, then confirm 5.6.1 or 1.5.1Q on device. A firmware file from anywhere else is not this story.
Watch migration completion, not price. A 7.7% bitcoin day can pull people back into a wallet they meant to empty. The 20 August post still says support channels are heavy. That is a throughput risk, not a price signal.
Watch whether 5.6.1 gets the same class of independent rebuild that 5.6.0 received. Until that shows up in the status page’s validation list, treat 5.6.1 as Coinkite’s recommended standard plus a three-week internal review, not as a second full public audit.