Coinkite pushes urgent Coldcard firmware update after $130M Bitcoin heist Coldcard maker Coinkite has rolled out a major security overhaul for its Bitcoin hardware wallets after a seed-generation flaw was exploited to steal roughly $130 million in BTC. The company is urging owners of Coldcard Mk4, Mk5 and Q devices to update immediately to firmware 5.6.1 or 1.5.1Q. What happened - In July attackers began draining air-gapped Coldcard wallets by exploiting a firmware bug dating to 2021 that sometimes produced wallet seeds with far too little randomness. On at least one early wave attackers drained 594 BTC (about $38M) from roughly 500 wallets in 25 minutes. - Research firms tracked the thefts as they escalated. Galaxy Research reported about $88.6M stolen across 4,585 addresses, then by August 14 recorded roughly 1,778 BTC (~$112M at the time) across several major waves and many smaller incidents. Coinkite now says the exploit has resulted in approximately $130M in stolen Bitcoin. - The root issue: on some affected devices the entropy used for seed generation fell from a cryptographically secure ~128 bits to roughly 40 bits, making private keys feasible to guess remotely without physical access. Response and fixes - Coinkite conducted a three-week system review with outside security researchers and AI tools (including a model named Kimi) and released firmware updates that close multiple avenues of attack. - Key fixes include: replacing the Yasmarang pseudo-random generator with SHA-256 Hash_DRBG, adding hardware RNG failure checks, and tightening seed-generation procedures so user-supplied randomness is required (at least 65 key presses, 50 dice rolls, or 128 coin flips, combined with device entropy). - The update also patches issues in transaction signing (Coldcard now checks a PSBT immediately before signing and will warn or halt if it’s been altered), USB data handling, firmware validation, Delta Mode hardening, and wallet backup handling. - Coinkite thanked external researchers for intensive scrutiny that strengthened the release. The role of AI - Coinkite suggested attackers may have used AI to analyze older open-source firmware to uncover the flaw. Security firms said the attacks appeared deliberate and programmatic; some researchers believe large language models were used to find and exploit the vulnerability. - The incident underscores how AI accelerates both vulnerability discovery and patching. Ledger CTO Charles Guillemet called the episode “a serious reminder of how the whole security model of a hardware wallet lives or dies on randomness.” What users must do - If you generated a seed on an affected Coldcard build between 2021 and July 2026, Coinkite advises creating a new seed with the updated firmware and migrating funds to a new wallet immediately. - All Mk4, Mk5 and Q users should upgrade to firmware 5.6.1 or 1.5.1Q as soon as possible. Wider context and ongoing investigation - The episode has renewed focus on entropy quality in hardware wallets and on the speed with which AI can surface bugs. Other projects have reported AI-assisted attackers finding bugs faster than developers can patch them; volunteer teams have also used AI agents to scan Bitcoin projects for vulnerabilities. - Coinkite says law enforcement is investigating and the company is assisting affected customers; it remains available to help users migrate funds until the process is complete. Bottom line: If you own a Coldcard Mk4, Mk5 or Q, update the firmware now and, if your seed was created on affected versions, create a fresh seed and move your Bitcoin. The exploit is a stark reminder that high-quality randomness and continual scrutiny are critical to hardware-wallet security. Read more AI-generated news on: undefined/news
