Key Highlights

  • Coinkite has introduced new firmware for Coldcard after a vulnerability led to over $100 million in Bitcoin thefts.
  • The updated Coldcard now mandates users to introduce randomness via various methods when creating new seeds.
  • A comprehensive review revealed additional issues related to transaction signing, USB connections, and wallet functionalities.

Coinkite, the manufacturer of Coldcard, has implemented significant security updates for its Bitcoin hardware wallets in response to a flaw that enabled the theft of more than $100 million in Bitcoin.

In a blog announcement on Thursday, Coinkite encouraged users of Coldcard Mk4, Mk5, and Q to upgrade to firmware versions 5.6.1 or 1.5.1Q. This update follows a three-week evaluation involving external security experts and AI tools, including Kimi.

Myriad: What’s the next move for Bitcoin? Share your prediction.

“We appreciate the efforts of the security researchers who dedicated significant time to identifying issues, reproducing edge cases, and scrutinizing our fixes,” stated the company. “Their contributions have strengthened this firmware release considerably.”

In July, hackers began siphoning Bitcoin from air-gapped Coldcard wallets, capitalizing on a firmware vulnerability from 2021 that produced wallet seeds with insufficient randomness, thus making private keys more susceptible to guessing. The initial breach resulted in the theft of 594 BTC, valued at around $38 million, from approximately 500 wallets in just 25 minutes.

Coinkite speculated that the attackers might have utilized AI to analyze previous versions of its open-source firmware to discover the weakness.

By early August, Galaxy Research reported tracking about $88.6 million stolen across 4,585 addresses, suggesting that the attacks were systematic, potentially executed using a large language model.

The research firm continued to monitor the situation, stating by August 14 that over 1,778 BTC had been stolen, amounting to roughly $112 million at that time, across three major attack waves and numerous smaller incidents.

Overall, the Coldcard exploit has led to approximately $130 million in Bitcoin theft, raising concerns about entropy, the randomness essential for generating wallet keys. On some impacted devices, the flaw diminished security from 128 bits of entropy to about 40 bits, making it easier for attackers to guess wallet seeds without needing physical access to the device.

Coinkite has addressed issues related to transaction signing, USB data management, firmware validation, Delta Mode, and wallet backups. The updated Coldcard will now require users to introduce randomness through a minimum of 65 key presses, 50 dice rolls, or 128 coin flips, which will be combined with the device's inherent randomness when generating a wallet seed.

The company has also substituted its Yasmarang backup pseudo-random number generator with SHA-256 Hash_DRBG and implemented checks to detect failures in the hardware random number generator. Users who may have created seeds on affected firmware versions from 2021 to July 2026 are advised to generate a new seed with the updated firmware and transfer their Bitcoin, according to the company.

Beyond Seed Generation

Coldcard now verifies a partially signed Bitcoin transaction (PSBT) right before it signs it. In the past, a compromised computer connected via USB could theoretically alter a transaction after the user had reviewed it but before Coldcard finalized the signing.

The new firmware halts the signing process and issues a warning if the transaction has been modified. Coinkite characterized this issue as theoretical and did not indicate it had been exploited.

Additionally, Coinkite has tightened USB data access, reinforced Delta Mode, and revised how Coldcard manages wallet backups.

While AI has played a crucial role in remedying vulnerabilities, it is also a factor in both cybersecurity and cryptography challenges.

Myriad: Will Microstrategy maintain over 1M BTC? Share your prediction.

"This serves as a stark reminder that the entire security framework of a hardware wallet hinges on randomness," stated Ledger CTO Charles Guillemet in an interview with Decrypt. "Cryptography is complex, and ensuring its secure implementation is even more challenging. The recent Coldcard incident has highlighted this in the most costly manner possible."

Earlier this month, the swap service Boltz halted its operations, citing that AI-assisted attackers were identifying vulnerabilities quicker than its developers could address them. A volunteer Bitcoin Red Team also employed AI agents to uncover thousands of potential security flaws across numerous Bitcoin projects.

Coinkite has confirmed that the investigation into the thefts is still ongoing, as affected users continue to transfer their funds to new wallets.

“Law enforcement is actively investigating these thefts and working to identify the perpetrators,” Coinkite stated. “We are here to assist, and authorities are keeping us updated on significant developments,” adding that the company “is committed to aiding every customer through their migration process until it is complete.”

Daily Debrief Newsletter

Start your day with the latest news stories, original features, podcasts, and more.