Coinkite released new Coldcard firmware after a seed-generation flaw exposed users to more than $100 million in Bitcoin thefts.
Coldcard now requires users to add randomness through key presses, dice rolls, or coin flips when generating new seeds.
A three-week review also uncovered issues involving transaction signing, USB connections, backups, and other wallet functions.
Coldcard maker Coinkite has released a security overhaul for its Bitcoin hardware wallets after a seed-generation flaw allowed attackers to steal more than $100 million in Bitcoin.
In a blog post on Thursday, Coinkite urged Coldcard Mk4, Mk5, and Q users to upgrade to firmware 5.6.1 or 1.5.1Q. The release follows a three-week review of Coldcard’s systems that included outside security researchers and AI models including Kimi.
Myriad: Bitcoin price next move? Click to make your prediction.
“We are grateful to the security researchers who went above and beyond over the past weeks, reporting issues, reproducing edge cases, and reviewing our fixes,” the company wrote. “Their work put this firmware under intense, sustained scrutiny and made this release stronger.”
In July, attackers began draining Bitcoin from air-gapped Coldcard wallets after exploiting a firmware flaw dating to 2021 that generated some wallet seeds with too little randomness, making their private keys easier to guess. The first attack drained 594 BTC, worth about $38 million, from roughly 500 wallets in 25 minutes.
Coinkite suggested that the attackers may have used AI to examine older versions of its open-source firmware and uncover the flaw.
By early August, Galaxy Research had tracked roughly $88.6 million stolen across 4,585 addresses and said the attacks appeared deliberate, programmatic, and potentially orchestrated using a large language model.
The research company continued tracking losses and by August 14 said attackers had stolen more than 1,778 BTC, worth roughly $112 million at the time, across three major attack waves and dozens of smaller incidents.
All told, the Coldcard exploit has now resulted in roughly $130 million in stolen Bitcoin and raised questions about entropy—the randomness used to generate wallet keys. On some affected devices, the flaw reduced security from 128 bits of entropy to roughly 40 bits, making wallet seeds easier for attackers to guess without physical access to the device.
Coinkite said it fixed issues involving transaction signing, USB data handling, firmware validation, Delta Mode, and wallet backups. Coldcard now also requires users to add randomness when generating a wallet seed using at least 65 key presses, 50 dice rolls, or 128 coin flips, which the device combines with its own randomness.
The hardware wallet maker also replaced its Yasmarang backup pseudo-random number generator with SHA-256 Hash_DRBG and added checks intended to catch failures in the hardware random number generator. Users who may have generated seeds on affected versions between 2021 and July 2026 must create a new seed using updated firmware and move their Bitcoin, the company said.
More than seed generation
Coldcard now checks a partially signed Bitcoin transaction, or PSBT, immediately before signing it. Previously, a compromised computer connected over USB could theoretically change a transaction after the user reviewed it but before the Coldcard signed it.
The updated firmware stops the signing process and displays a warning if the transaction has changed. Coinkite described the issue as theoretical and did not say it had been exploited.
Coinkite also tightened USB data access, hardened Delta Mode, and changed how Coldcard handles wallet backups.
While AI has played a role in patching vulnerabilities, it also plays a role on both sides of cybersecurity and cryptography.
Myriad: Will Strategy hold over 1M BTC? Click to make your prediction.
“We’re treating this as a serious reminder of how the whole security model of a hardware wallet lives or dies on randomness,” Ledger CTO Charles Guillemet told Decrypt. “Cryptography is hard and implementing it securely is harder. This week’s Coldcard incident made that visible in the most expensive way possible.”
Earlier this month, swap service Boltz suspended operations after saying AI-assisted attackers were finding bugs faster than its developers could fix them. A volunteer Bitcoin Red Team also used AI agents to identify thousands of potential vulnerabilities across hundreds of Bitcoin projects.
Coinkite said the investigation into the thefts remains ongoing as affected customers continue moving funds to new wallets.
“Law enforcement authorities continue investigating the thefts and are working to identify those responsible,” Coinkite said. “We remain available to assist, and authorities are keeping us informed of material developments,” adding that the company “remain committed to supporting every customer working through their migration until it’s done.”
Daily Debrief Newsletter
Start every day with the top news stories right now, plus original features, a podcast, videos and more.
The FSNN News Room is the voice of our in-house journalists, editors, and researchers. We deliver timely, unbiased reporting at the crossroads of finance, cryptocurrency, and global politics, providing clear, fact-driven analysis free from agendas.
We and our selected partners wish to use cookies to collect information about you for functional purposes and statistical marketing. You may not give us your consent for certain purposes by selecting an option and you can withdraw your consent at any time via the cookie icon.
Cookies are small text that can be used by websites to make the user experience more efficient. The law states that we may store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies, we need your permission. This site uses various types of cookies. Some cookies are placed by third party services that appear on our pages.
Your permission applies to the following domains:
https://fsnn.net
Necessary
Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Statistic
Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
Preferences
Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
Marketing
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.