What changed, and why it matters
This commit is a routine version bump for the COLDCARD firmware release process. It updates version strings in two build makefiles (from 5.6.2 to 5.6.3 for Mk, and from 1.5.2Q to 1.5.3Q for Q) and finalizes the release date and changelog entries. There are no code changes, no bug fixes, and no security-relevant modifications in the diff itself.
No security action needed for this commit. Review the actual commits that introduced the bugfixes and features mentioned in the changelog if assessing security relevance of the release.
Security signals we found
No strong security signals were identified.
Evidence from the diff
The commit modifies three files: releases/Next-ChangeLog.md, stm32/MK-Makefile, and stm32/Q1-Makefile. The makefiles only change VERSION_STRING values. The changelog updates release dates and removes placeholder ‘tbd’ entries. No source code, cryptographic, protocol, or security logic is altered. The security-relevant items listed in the changelog (external contributor firmware warning, JSON message-signing crash fix, unintended master seed replacement fix) are descriptions of previously committed changes, not changes introduced by this commit.
Changed components
release metadatabuild configuration (Makefile version strings)changelog documentationInspect captured patch +11 / −11
### releases/Next-ChangeLog.md
@@ -2,18 +2,19 @@
This lists the new changes that have not yet been published in a normal release.
-**In an attempt to avoid constant rebasing, please leave a blank line between
+**In an attempt to avoid constant rebasing, please leave a blank line around
your addition and anything else already in this file.**
# Shared Improvements - Both Mk and Q
- Enhancement: Warn before installing firmware signed by an external contributor
or downgrading from the currently installed firmware. Thanks to Huzaifa Jawaid for his suggestion.
-- New Feature: Codex32 (BIP-93) secrets and Shamir secret sharing. Generate or import Codex32 wallets,
- split the active wallet into two to nine Shamir shares with **Shamir Split**, and restore it with **Shamir Recover**.
- Word wallets split as `cw1`, raw master seeds as `ms1`, and extended-key wallets as `cx1`.
- CW1 and CX1 are COLDCARD extensions that require explicit support in recovery software.
+- New Feature: Codex32 (BIP-93) secrets and Shamir secret sharing. Generate or import Codex32
+ wallets, split the active wallet into two to nine Shamir shares with **Shamir Split**, and
+ restore it with **Shamir Recover**. Word wallets split as `cw1`, raw master seeds as `ms1`,
+ and extended-key wallets as `cx1`. CW1 and CX1 are COLDCARD extensions that require
+ explicit support in recovery software.
- Bugfix: Fix device crash when message-signing input is valid JSON but not an
object (NFC / QR / SD `.json` file). Thanks to [@Amiga500](https://github.com/Amiga500).
@@ -30,16 +31,15 @@ your addition and anything else already in this file.**
# Mk Specific Changes
-## 5.6.3 - 2026-09-xx
+## 5.6.3 - 2026-09-30
-- tbd
+- All of the above.
# Q Specific Changes
-## 1.5.3Q - 2026-09-xx
+## 1.5.3Q - 2026-09-30
- Bugfix: Prevent unintended master seed replacement when scanning seed words
or an extended private key from Ready To Sign or the Key Teleport retry screen.
-- tbd
### stm32/MK-Makefile
@@ -19,7 +19,7 @@ LATEST_RELEASE = $(shell ls -t1 ../releases/*-mk-*.dfu ../releases/*-mk4-*.dfu |
# Our version for this release.
# - caution, the bootrom will not accept version < 3.0.0
-VERSION_STRING = 5.6.2
+VERSION_STRING = 5.6.3
# keep near top, because defined default target (all)
include shared.mk
### stm32/Q1-Makefile
@@ -16,7 +16,7 @@ BOOTLOADER_DIR = q1-bootloader
LATEST_RELEASE = $(shell ls -t1 ../releases/*-q1-*.dfu | head -1)
# Our version for this release.
-VERSION_STRING = 1.5.2Q
+VERSION_STRING = 1.5.3Q
# Remove this closer to shipping.
#$(warning "Forcing debug build")Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.