Coinkite released new firmware for its Coldcard hardware wallets on Thursday, three weeks after disclosing a seed-generation failure that allowed attackers to drain more than $114 million in bitcoin.
The Canadian company said the review behind the release was assisted by AI tools, naming Kimi and other frontier models among the systems used to examine the full stack rather than only the faulty randomness path.
New seed creation now requires user-supplied entropy
Under the update, every newly generated seed must include entropy provided by the user. Coinkite said users must complete one of the following:
- at least 65 key presses with unpredictable timing;
- 50 rolls of a physical six-sided die; or
- 128 coin flips.
Coinkite also changed its backup random number generator, replacing the Yasmarang algorithm with one built on SHA-256.
Mk4 and Mk5 owners are advised to install version 5.6.1, while Q owners should install version 1.5.1Q.
The update does not secure already compromised wallets
Coinkite said installing the new firmware does not make an existing compromised wallet safe. Anyone whose seed was created on affected firmware between 2021 and July 2026 still needs to generate a new seed on fixed firmware and move funds to it.
The company added that its July 31 hotfix had already corrected seed generation for newly created seeds. This release, it said, gives affected users a more thoroughly reviewed base for migration.
Review found additional issues beyond the original bug
The broader review identified problems unrelated to the original vulnerability, including the way transactions are approved, how data is handled over USB, and how firmware updates are validated.
With the new release, the device re-verifies a staged transaction immediately before signing. That means a computer compromised at the USB port cannot change a payment after the owner has already approved it on the device screen.
Signature modes that leave later outputs editable are now blocked by default.
Security status page goes live as theft probe continues
Coinkite has launched a public security status page that lists the current fixed-release matrix and migration guidance. The company also said law enforcement is still investigating the thefts and working to identify those responsible.
Bitcoin Red Team cites AI-driven findings after the exploit
Following the Coldcard exploit, volunteer group Bitcoin Red Team, made up of 16 developers working across time zones, said it has used AI tools to file at least 4,900 findings across 390 projects. Those findings include at least 85 critical issues and 635 high-severity issues.

