Coldcard's 65-press fix won't save your old seed
Coinkite's new firmware forces 65 manual key presses for seed generation, but it can't repair seeds made on vulnerable releases. If your Coldcard seed came from affected firmware, you need to move your funds now. Here's why that's the right call.
Sixty-five.
That's how many times Coldcard users will press a button to generate a new Bitcoin seed. No shortcuts. No auto-random. Just you, a button, and a lot of patience.
Coinkite dropped firmware 5.6.1 for the standard Coldcard and 1.5.1Q for the Mark V on Aug 20. The update forces physical randomness into seed generation. Every new wallet needs 65 manual key presses so the device can build entropy from your timing and pressure.
But here's the brutal part: if your seed came from an affected release, this update won't save you. Coinkite can't repair a seed that's already exposed. The only fix is generating a new seed and moving your funds.
The story behind the button mashing
The exploit hit seed generation on older firmware. That's the scariest kind of vulnerability for a hardware wallet. Its whole job is producing a seed that only you can know. If the random number generator was weak, someone could theoretically predict your seed. And if someone can predict your seed, they can drain your wallet whenever they want.
So Coinkite did the only responsible thing: made new seed generation stronger and told affected users to move their money. No spin. No fluff. Just "generate another seed and transfer the funds."
Here's the thing though. That's a massive ask for some people.
Moving Bitcoin means paying fees. Dealing with change addresses. Verifying a new seed backup and praying you don't mess it up. It's annoying. It's tedious. And it's absolutely necessary if your seed was made on a vulnerable release.
My take? Coinkite deserves respect for this. A weaker company would've buried the issue in a changelog and hoped nobody noticed. Instead, they're forcing 65 key presses per wallet and telling you straight: your funds are exposed, move them.
That's real accountability in an industry that doesn't always have it.
What the 65 presses actually mean
Let's talk about the button mashing itself. Physically pressing a button 65 times isn't about making users miserable. It's about injecting entropy that software alone can't guarantee.
Random number generators on computers fail. It's a known problem. If the device's RNG is compromised, every seed it generates is compromised too. But physical randomness? That's harder to attack. Your specific timing, your pauses, your slightly different pressure on each press. That's data a remote attacker can't predict.
So the 65 presses are a feature, not a bug. Get used to them.
But here's the question nobody wants to answer: how many people will actually move their funds? How many will look at the warning, shrug, and keep their Bitcoin on a seed that might be compromised?
That's the real risk here. Not the exploit. The complacency.
Move your Bitcoin. Now.
So here's where we land. If you've a Coldcard and you're not sure when your seed was generated, check. If your seed came from affected firmware, you've one option: create a new wallet with the updated firmware and transfer everything off the old seed.
Don't wait. Don't hope. Don't convince yourself the exploit is theoretical and nobody's targeting you specifically.
JUST IN: the fix isn't optional. Coinkite said exposed funds still must move. A seed made on a vulnerable release is a liability. And the only way to get rid of it's to spend the money into a new wallet.
Sixty-five presses is a small price for knowing your Bitcoin is safe.
This changes things. The market's verdict on Coldcard might be mixed, but on security, they just set a new bar. "Patch your RNG and tell everyone to move funds" is the coldest take in hardware wallets right now.
And honestly? It's the right one.