Coldcard Pushes New Firmware After $114M BTC Theft as AI Flags Additional Flaws

  • A three-week review uncovered security weaknesses beyond the vulnerability responsible for the $114 million bitcoin theft. Still, Coinkite warned that installing the new firmware will not make a wallet secure if it has already been compromised.
  • Coinkite, the Canadian maker of the Coldcard hardware wallet, has released a firmware update several weeks after revealing the flaw that allowed attackers to steal more than $114 million worth of bitcoin.
  • The company said AI was used throughout the latest security assessment. Kimi and other frontier AI models helped examine both the original randomness flaw and the wider Coldcard software and hardware architecture.
  • The review uncovered additional problems involving transaction approval, USB data processing and firmware-update validation.
  • Users with wallets affected by the original vulnerability cannot simply install the update and regain security. Anyone whose seed or master key was generated using vulnerable firmware between 2021 and July 2026 must create a new seed and move their funds to a new wallet.
  • Coldcard’s updated seed-generation process requires users to add their own physical randomness. They can do so with 65 unpredictable button presses, 50 rolls of a six-sided die or 128 coin flips.
  • The physical approach is designed to eliminate reliance on software-generated randomness. Dice and coin outcomes cannot be predicted by software, unlike the device-generated randomness mechanism that contained the original vulnerability.
  • Coinkite has also replaced its backup random-number generator. The previous Yasmarang algorithm has been removed in favor of a system based on SHA-256, the hashing function also used by Bitcoin.
  • The updated Coldcard now performs a final transaction verification immediately before signing. This is intended to prevent a compromised computer connected via USB from changing transaction details after the user has approved the payment on the device. Signature modes that permit certain transaction fields to remain editable after signing are now disabled by default.
  • Coinkite said law enforcement agencies continue to investigate the thefts and work to identify those responsible. The company said it is cooperating with the investigation.
  • Coldcard Mk4 and Mk5 owners should update to firmware 5.6.1, while owners of the Q model should install version 1.5.1Q. Coinkite urged users to obtain the software only from its official downloads page and has launched a public status page outlining the affected releases, fixes and required migration steps.

AI Emerges as a Crypto Security Tool

  • Coldcard is the latest of five bitcoin and crypto companies in three weeks to publicly describe how AI is changing vulnerability detection and security audits.
  • BTCPay Server, an open-source platform that allows merchants to accept bitcoin payments independently, was hit this month after attackers exploited a flaw involving users’ Lightning nodes. The project is offering up to 3 BTC for the recovery of stolen funds and has paid 0.42 BTC to researchers who identified the vulnerability. It has also advised merchants to keep assets in cold storage and regularly move excess funds from hot wallets, particularly as AI-driven security threats become more prominent.
  • Dozens of Bitcoin companies, including Coinbase, Block, BitGo and Blockstream, signed an open letter on Aug. 10 calling on AI labs to provide open-source security researchers with early access to their most powerful models.
  • The Bitcoin Red Team has become one of the most prominent community-led efforts. The group of 16 developers working across different time zones reported 4,962 issues across 390 projects during its first 24 hours, including 85 critical and 635 high-severity vulnerabilities. Its findings also contributed to the research behind BTCPay Server’s security patch.
  • Bybit, which suffered an approximately $1.46 billion theft attributed to North Korea’s Lazarus Group in February 2025, said AI-assisted audits detected high-severity vulnerabilities at three to five times the rate of manual reviews. The exchange also said AI systems helped block around $700 million in suspicious withdrawals during the first half of the year.