Coinkite has issued a new firmware update for the Coldcard hardware wallet after disclosing a seed-generation flaw linked to more than $114 million in reported Bitcoin thefts. The core problem wasn’t just software, it was how some wallet seeds could be predicted, because the device created them with faulty randomness. Coinkite says its update removes the vulnerable behavior and adds broader hardening fixes, but also warns: simply updating the firmware doesn’t fix old seeds created before the patch. If a seed was generated with an affected release, the risk remains even after the update.

The details matter because of how hardware wallets work. A seed is the recovery phrase backing crypto holdings. The flaw meant some seeds could be more predictable than users believed, and if that seed stays in use, the exposure may remain. Coinkite’s guidance is two-part: update the firmware, then create a completely new seed and migrate funds if the old seed may have been exposed. The company also says users creating a new seed should add manual entropy, extra randomness from dice rolls or coin flips, including at least 50 independent, private rolls.

The company says it’s working with law enforcement, but the immediate focus is on user practice. The software fix protects against the vulnerable behavior going forward, but the real challenge is whether existing users take the hard step of replacing any seed created under affected firmware and starting over.