In brief Coinkite says a build error meant seeds on its Coldcard hardware wallets were drawn from a software fallback instead of the hardware generator. It believes an attacker used AI on its open-source code, and says its own AI review weeks earlier found nothing. Every current model is affected to some degree, and updating the firmware does not repair a seed already created. Coinkite believes an attacker used AI to find a flaw that has cost owners of its Coldcard hardware wallets tens of millions of dollars in Bitcoin, and says its own AI review of the same code weeks earlier turned up nothing. The hardware wallet manufacturer published an advisory for its Mk3 and a technical breakdown on Thursday, after learning that seeds generated by its devices were far more guessable than intended. COLDCARD Mk3 Security Advisory If you generated a seed on a Mk3 after firmware 4.0.1, your funds may be at risk. Mk4, Q and Mk5 are not affected based on our early analysis. Read the advisory and migrate carefully:https://t.co/3vgPHOjMS7 — COLDCARD (@COLDCARDwallet) July 30, 2026The losses to the flaw, which was exploited early Friday, are estimated at 594 BTC, around $38 million. Funds were drained from roughly 500 wallets inside 25 minutes, with 562 BTC since consolidated into a single address.Coinkite said it has to assume "someone used AI to review previous versions of our firmware" in order to uncover the flaw. The firm said it had run one of the best available models over its own code a few weeks earlier, and the model "did not find this bug or anything serious." Attackers and defenders have the same tools, it wrote, but this time "it did not help us, and only helped the bad guys."What went wrongColdcard's firmware calls a function to fetch randomness, and two implementations of it sat in the codebase with identical signatures: the hardware generator Coinkite wrote, and a software fallback inherited from MicroPython. A preprocessor guard checked only whether a setting was defined, without testing its value, so the build completed against the fallback without complaint. Seed generation had been drawing on it since a March 2021 migration.Every current model is affected to some degree. Coinkite estimates the effective search space for an Mk3 seed at about 40 bits, against the 128 a seed is meant to have. Extra entropy from the secure elements on the Mk4, Q and Mk5 lifts theirs to roughly 72 bits, which the company says materially improves the position without reaching the target. Tapsigner, Opendime and Satscard use different code and are unaffected.What owners must doCoinkite has shipped an emergency hotfix, version 5.6.0 for the Mk4 and Mk5 and 1.5.0Q for the Q. Updating does not repair a seed already created on affected firmware. Owners need a new seed generated on patched hardware, and the company recommends a strong BIP-39 passphrase, at least 99 dice rolls, or both. Mk3 owners, whose model is out of support, are pointed to a separate migration path. 1/ Earlier today, our Bitcoin engineering and security teams at Block began investigating reports of non-Bitkey wallets being drained. To proactively protect our customers, we began investigating immediately. Here’s what we found 🧵 — Max Guise (@max_guise) July 31, 2026A seed created on an affected Coldcard stays weak after being restored to another brand's device, a point rival hardware wallet manufacturer Trezor made while telling its own users their funds are safe. Block, which published an independent analysis on Friday, said none of its products are affected, and its hardware lead Max Guise urged anyone exposed to move funds as soon as they safely can.Daily Debrief NewsletterStart every day with the top news stories right now, plus original features, a podcast, videos and more.
$38M in Bitcoin Drained by Coldcard Key Flaw Its Maker Thinks AI Found
Full Article
Original Source
Read the full article at Decrypt →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.