Coldcard released firmware version 3.1.6 on June 14, 2020, correcting assertion errors triggered by certain transaction sizes. The update was the hardware wallet’s second follow-up in two days after a larger release introduced a defense against a cross-wallet vulnerability involving SegWit transactions and Partially Signed Bitcoin Transactions, or PSBTs.

The narrow June 14 development was a bug fix rather than a newly disclosed security flaw. Its significance came from the sequence around it: software intended to strengthen transaction verification had moved through versions 3.1.4, 3.1.5 and 3.1.6 between June 12 and June 14. For users relying on a hardware device to verify Bitcoin payments independently of a potentially compromised computer, signing reliability was part of the security boundary—not merely a convenience feature.

Three releases in three days

Coldcard’s official release history says version 3.1.4, dated June 12, added detection and blocking for a recently reported BIP-143 attack involving replayed SegWit inputs. It also added transaction-ID display during finalization, BIP-85 deterministic entropy exports and several unrelated interface and keypad changes.

Version 3.1.5 followed on June 13. According to the same record, signing a PSBT from a MicroSD card while asking the device to finalize the transaction could fail with a “HexWriter” error. Version 3.1.6 then arrived on June 14 to clear an assertion error affecting some specific transaction sizes. The release notes describe 3.1.6 as a correction to the preceding correction but do not identify the exact byte boundaries, transaction structures or number of affected users.

A contemporaneous Bitcointalk post recorded version 3.1.6 becoming available on June 14 and advised users who had installed the previous day’s release to update again. That forum post independently corroborates the public timing, although Coldcard’s repository remains the authoritative record for the software change.

Why PSBT verification mattered

The security issue motivating version 3.1.4 had been publicly described on June 3 by both Trezor and Coldcard manufacturer Coinkite. Under the reported attack, malware controlling transaction data could misstate the values of SegWit inputs and induce a user to sign two apparently similar transactions. The malware could then combine signatures so that additional bitcoin became a miner fee.

The attack required several conditions. The signing device had to receive misleading input information, the user had to authorize two transactions, and the attacker needed control over the surrounding software flow. Coinkite said an attacker would not profit directly unless it could also capture the resulting miner fees. Those constraints made this a conditional attack, not evidence that funds had been stolen from every affected wallet.

Coldcard’s June 12 mitigation checked the claimed SegWit input amounts and reported mismatches. The June 13 and June 14 releases addressed operational problems encountered after that broader update. The available records support describing version 3.1.6 as a signing-reliability fix within the mitigation rollout; they do not establish that 3.1.6 changed the underlying BIP-143 defense itself.

What the June 14 record establishes

The verified event is that Coldcard dated firmware 3.1.6 to June 14, 2020, and attributed it to transaction-size-dependent assertion errors. The record does not quantify how many devices installed the release, how frequently the error occurred or whether any attempted payment was delayed. No loss total, market-price movement or blockchain-wide effect can be attributed to the update from the cited evidence.

The episode nevertheless illustrated an institutional constraint of self-custody: a hardware wallet can isolate private keys, but safe operation also depends on transaction parsing, host-wallet compatibility, firmware distribution and users recognizing when another update is required.

Later context

Coinkite’s later security-disclosure history classifies the June 2020 BIP-143 issue as cross-wallet and says the reported attack class was blocked in firmware 3.1.4. It reports finding no public evidence of a Coldcard loss from that issue. That assessment is later context, not a fact established on June 14, 2020.

Primary sourceColdcard official Mk3 firmware release history

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.