Coinkite shipped new firmware for its Coldcard hardware wallets on Aug. 21 after a randomness flaw enabled attackers to drain more than $114 million in bitcoin from 709 addresses.
"Anyone whose seed was created on affected firmware between 2021 and July 2026 must generate a new one and move their funds," Coinkite said in its security update blog post. Installing the update does not make an existing compromised wallet safe.
The AI-assisted review, which used frontier models including Kimi, found problems unrelated to the original bug in how transactions are approved, how data is handled over USB, and how firmware updates are validated. The device now re-checks a transaction immediately before signing, so a computer compromised at the USB port cannot alter a payment after the owner has approved it on screen. Signature modes that leave parts of a transaction editable after signing are blocked by default.
New seeds now require physical randomness — 65 key presses at unpredictable intervals, 50 rolls of a six-sided die, or 128 coin flips — because a die or coin produces results no software can predict. Underneath, Coinkite replaced the backup random number generator entirely, swapping the Yasmarang algorithm for one built on SHA-256, the hashing function bitcoin itself uses.
Coinkite is asking Mk4 and Mk5 owners to install version 5.6.1 and Q model owners to install 1.5.1Q from its official downloads page only. The company has also launched a public status page listing which releases are fixed and what migration steps apply. Law enforcement is still investigating the thefts.
AI-assisted security sweep across bitcoin
Coldcard is the fifth bitcoin or crypto outfit in three weeks to say publicly that AI has changed how security work gets done. BTCPay Server, free software merchants run to accept bitcoin payments, was hit this month when attackers drained Lightning nodes belonging to its users through a flaw it had just patched. The project is offering a bounty of up to 3 BTC for the return of the money and has paid 0.42 BTC to the researchers who found the flaw.
A volunteer effort called the Bitcoin Red Team, a collective of 16 developers, filed 4,962 findings against 390 projects in its first 24 hours, including 85 critical and 635 high-severity issues. Crypto exchange Bybit, which lost roughly $1.46 billion to North Korea's Lazarus Group in February 2025, said this week that AI-assisted auditing found high-severity flaws at three to five times the rate of manual review and helped it block $700 million in suspicious withdrawals across the first half of the year.
Dozens of bitcoin firms including Coinbase, Block, BitGo and Blockstream signed an open letter on Aug. 10 asking AI labs to give open-source security researchers early access to their most capable models.
The Coldcard incident highlights a growing tension in bitcoin self-custody: hardware wallets are only as secure as the code running on them, and the same AI tools that help attackers find vulnerabilities are now being deployed by defenders. For affected users, the path forward is clear — migrate to new seeds and update firmware — but the broader lesson is that even trusted cold storage devices require ongoing security scrutiny.
This article is for informational purposes only and does not constitute investment advice.