Loading prices…
🩸BEARISH

Coldcard Ships Firmware After $114M Bitcoin Theft

The patch tightens the RNG and signing flow, but seeds from affected firmware between 2021 and July 2026 still need replacement. AI-assisted auditing is the broader industry signal here.

Coldcard Ships Firmware After $114M Bitcoin Theft
Coldcard Ships Firmware After $114M Bitcoin Theft
Coldcard Ships Firmware After $114M Bitcoin Theft
Coldcard Ships Firmware After $114M Bitcoin Theft

Coinkite released new firmware for its Coldcard hardware wallets three weeks after disclosing the randomness flaw that enabled attackers to steal more than $114 million in bitcoin. The update hardens transaction approval, USB data handling and firmware validation, but compromised devices still need new seeds and fund migration.

Why it matters

The scale of the theft, more than $114 million drained from bitcoin holders, makes it one of the largest hardware-wallet incidents on record. Coinkite replaced its backup random number generator, swapping the Yasmarang algorithm for one built on SHA-256, and now requires physical randomness for new seeds: 65 unpredictable key presses, 50 die rolls or 128 coin flips. The device re-checks transactions immediately before signing so a compromised USB host cannot alter a payment after on-screen approval.

Market impact

The bigger industry signal is the role AI played. Coldcard said it used Kimi and other frontier models to audit the entire system, finding flaws unrelated to the original bug. Bybit reported AI-assisted auditing finds high-severity issues at three to five times the rate of manual review. The volunteer Bitcoin Red Team filed 4,962 findings against 390 projects in 24 hours, including 85 critical issues. Coldcard owners should install v5.6.1 (Mk4/Mk5) or v1.5.1Q from Coinkite's official downloads page; anyone with a seed generated on affected firmware must generate a new one and move funds.

Related tokens
$BTC

Frequently asked questions

  1. What firmware versions did Coinkite release for the Coldcard?

    Coinkite shipped v5.6.1 for the Mk4 and Mk5 devices and v1.5.1Q for the newer Q model, both available from the official downloads page alongside a new public status page that lists which releases are fixed and what migration steps apply.

  2. Does installing the Coldcard update fix an already-compromised wallet?

    No. The patch hardens the device against future attacks, but anyone whose seed was generated on affected firmware between 2021 and July 2026 still has to generate a new seed on safe firmware and migrate funds across to the new wallet.

  3. Why does Coldcard now require physical randomness for new seeds?

    The original theft exploited a flaw in the device's on-board random number generator. Coinkite replaced Yasmarang with a SHA-256-based RNG and now requires owners to supply randomness by hand via 65 key presses, 50 die rolls, or 128 coin flips so no software is involved in producing the seed.

  4. How did AI help catch the bugs in the Coldcard firmware?

    Coinkite said it used Kimi and other frontier models to audit the entire system, not just the faulty randomness code. The review surfaced issues in transaction approval, USB data handling and firmware validation that were unrelated to the original bug.

  5. Are other bitcoin and crypto projects using AI-assisted security reviews too?

    Yes. Bybit said AI-assisted auditing found high-severity flaws at three to five times the rate of manual review and helped block roughly $700M in suspicious withdrawals in H1, the volunteer Bitcoin Red Team filed 4,962 findings in its first 24 hours, and dozens of firms including Coinbase, Block, BitGo and Blockstream…

Source attribution
Aggregated from CoinDesk · Verified · Last refreshed 1h ago
Open original →