News linked to both this project and an event.
Coldcard has released the latest firmware 5.6.1 (Mk4/Mk5) and 1.5.1Q (Q). This update is based on a three-week security review following the emergency fix on July 31, addressing security risks brought by the previous mnemonic generation attack. Each newly generated mnemonic must now include at least one source of user entropy, including at least 65 irregular keystrokes, 50 physical dice throws, or 128 physical coin flips, combined with fresh entropy provided by STM32 TRNG, SE1, and SE2. The new firmware also adds instant staged PSBT verification before signing, strengthens USB connection and firmware update boundaries, improves Delta Mode isolation mechanisms, fixes active wallet backup issues, enhances random number generator initialization and fault checking, adjusts SIGHASH default settings, and includes multiple security and correctness improvements. Coldcard stated that this update aims to further reduce the risk of device attacks. The official reminder notes that updating the firmware cannot fix existing mnemonics generated by previously affected firmware. If users' mnemonics fall within the scope of this security advisory, they should first update the device, then generate and verify a completely new mnemonic, and migrate funds to the new wallet. Coldcard recommends that all Mk4, Mk5, and Q users update their devices promptly and verify the signature of the downloaded firmware.
Anthropic 宣布其 Opus 5 模型在浏览器智能体场景中几乎免疫提示词注入攻击。在 129 个测试场景中,攻击成功率为零;在 Gray Swan 通用提示词注入测试中,15 次尝试后的成功率从 Opus 4.8 的 5.5% 降至 2.0%。零成功率仅在 Claude Cowork 等产品开启 Auto Mode 时实现,该模式叠加了输入扫描与执行拦截两层防御。提示词注入被视为 AI 智能体面临的最大安全隐患之一,此次改进或标志着该问题在特定场景下得到有效缓解。