Coldcard flaw drained 594 BTC as Coinkite says attacker may have used AI to spot bug

Coldcard flaw drained 594 BTC as Coinkite says attacker may have used AI to spot bug

N
News Editor
2026-07-31 09:02:01
Coinkite says a flaw in Coldcard firmware made seeds generated on affected devices far easier to guess than intended, leading to losses estimated at 594 BTC, or about $38 million. The company published a security advisory for the Mk3 and a technical explanation after learning that wallet seeds created by certain firmware versions had far less entropy than expected. The exploit was used early Friday, and roughly 500 wallets were drained within 25 minutes. Coinkite said 562 BTC has since been consolidated into a single address. The company believes it has to assume someone used AI to review earlier versions of its firmware and uncover the issue. Coinkite said it had run one of the best available models against the same code a few weeks earlier, but the model did not identify the bug or any serious issue. Its technical note says the problem came from a preprocessor guard that checked whether a setting existed, but not its value, allowing the build to use a weaker software fallback for randomness. Coinkite said Mk3 seeds had an effective search space of about 40 bits instead of the intended 128 bits, while Mk4, Q, and Mk5 were lifted to roughly 72 bits through added entropy from secure elements. The firm has released emergency fixes, but said users must generate entirely new seeds on patched hardware and move funds.

Coinkite says an attacker may have used AI to uncover a Coldcard firmware flaw that has already cost users an estimated 594 BTC, roughly $38 million. The hardware wallet maker also said it had run one of the best available AI models over the same code a few weeks earlier, and that review “did not find this bug or anything serious.”

Coldcard flaw drained 594 BTC as Coinkite says attacker may have used AI to spot bug 2

The company published a security advisory for the Coldcard Mk3 and a technical breakdown on Thursday after learning that seeds generated by its devices were much easier to guess than intended.

594 BTC lost, about 500 wallets drained in 25 minutes

In its advisory, Coinkite said funds may be at risk for users who generated a seed on a Mk3 running firmware later than version 4.0.1. Based on its early analysis, the company initially said Mk4, Q, and Mk5 were not affected in the same way, though its broader technical explanation later said every current model was affected to some degree.

According to Coinkite, the flaw was exploited early Friday. The company estimated losses at 594 BTC, or around $38 million. Roughly 500 wallets were drained within 25 minutes, and 562 BTC has since been consolidated into a single address.

Coinkite said it now has to assume that “someone used AI to review previous versions of our firmware” and found the weakness that way. The company wrote that attackers and defenders have access to the same tools, but this time “it did not help us, and only helped the bad guys.”

How the bug happened

In the technical breakdown, Coinkite said Coldcard firmware calls a function to fetch randomness. Two implementations with identical signatures existed in the codebase: a hardware random generator written by Coinkite and a software fallback inherited from MicroPython.

The problem came from a preprocessor guard that checked only whether a setting was defined, not what value it held. That let the build complete against the fallback implementation without throwing an error. As a result, seed generation had been drawing on that fallback path since a migration in March 2021.

Coinkite said all current models were affected to some extent. For the Mk3, the company estimated the effective search space for a seed at about 40 bits, far below the intended 128 bits. For the Mk4, Q, and Mk5, added entropy from secure elements raised the figure to roughly 72 bits. Coinkite said that materially improves the situation, but still does not meet the target.

Tapsigner, Opendime, and Satscard use different code and are not affected, according to the company.

What users need to do

Coinkite has released emergency hotfixes: version 5.6.0 for the Mk4 and Mk5, and version 1.5.0Q for the Q. The company said updating a device does not repair a seed that was already created on affected firmware.

Users need to generate a new seed on patched hardware. Coinkite recommends using a strong BIP-39 passphrase, at least 99 dice rolls, or both. Mk3 owners, whose device is no longer supported, have been directed to a separate migration path.

The company also said a weak seed generated on an affected Coldcard remains weak even if it is later restored to a device made by another manufacturer.

Responses from Trezor and Block

Trezor made the same point while telling its own users their funds were safe: restoring an affected Coldcard seed to another brand’s device does not remove the weakness.

Block published an independent analysis on Friday and said none of its products were affected. Max Guise, Block’s hardware lead, said the company’s Bitcoin engineering and security teams began investigating reports earlier Friday that non-Bitkey wallets were being drained, and urged anyone exposed to move funds as soon as they safely can.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
660

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.