Coldcard key-generation flaw prompts emergency firmware fix from Coinkite

Coldcard key-generation flaw prompts emergency firmware fix from Coinkite

N
News Editor
2026-08-01 00:21:24
Bitcoin hardware wallet maker Coinkite has released emergency firmware updates after a security flaw in certain Coldcard devices exposed users to private-key attacks. The issue mainly affected Coldcard MK3 units running firmware versions 4.0.1 through 4.1.9, particularly when users did not add dice-generated entropy or an extra BIP39 passphrase during setup. According to the input, the weakness came from insufficient randomness in key generation, and losses were estimated at more than 1,000 BTC, worth over $70 million. Coinkite said users of MK3, MK4, MK5, and Coldcard Q should upgrade to patched versions immediately, but it also warned that a firmware update cannot repair old keys that were already generated under risky conditions. The company advised users to move funds to fresh on-chain addresses and create new wallets after upgrading. Security engineer Peter Todd also flagged a separate risk for multisig setups involving affected devices, saying certain 2-of-3 configurations could expose enough information for an attacker to intercept funds when scripts are revealed. Co-founder NVK added that AI-assisted code review is changing how quickly attackers can examine open or previously published firmware source code.

Coinkite has issued emergency firmware updates after a security flaw in its Coldcard bitcoin hardware wallets exposed some users to private-key attacks. Based on the input, more than 1,000 BTC is estimated to have been stolen, with total losses put at over $70 million. The weakness was tied to insufficient randomness in private-key generation under certain firmware versions, and experts cited in the input said AI may have been used during the attack process. The company urged affected users to move funds first to protect their holdings.

Coldcard key-generation flaw prompts emergency firmware fix from Coinkite 2

Affected firmware versions and Coinkite's warning

According to the input, the main impact was on Coldcard MK3 devices running firmware versions 4.0.1 through 4.1.9. Users were described as especially vulnerable if, during initial setup, they did not add user-generated dice rolls or an extra BIP39 passphrase.

Coinkite updated its security notice on July 31 Eastern Time and released patched firmware. It told users to upgrade to the following minimum versions:

  • MK3: version 4.2.0 or later
  • MK4 and MK5: version 5.6.0 or later
  • Coldcard Q: version 1.5.0Q or later

The company said a firmware update can reduce risk but cannot repair older keys that were already created under exposed conditions. Because those keys were generated with the randomness available at the time, users were advised to upgrade first, then move funds to fresh on-chain addresses and create a new wallet.

Peter Todd flags multisig exposure

Security engineer Peter Todd warned about multisig setups using affected Coldcard devices. He said that in a 2-of-3 multisig configuration, if two of the signing devices are vulnerable Coldcards, an attacker could obtain enough information to steal funds once a spending transaction reveals the script that had previously been hidden behind the address hash.

He added that transactions revealing a multisig script are more exposed before confirmation. As a mitigation measure, he pointed to bitcoin mining pool MARA and Slipstream's private mempool service, which can keep transaction contents and public keys private until the transaction is included in a block, lowering the chance of interception. For wallets that have already reused addresses, he said users should move funds out quickly.

NVK says AI has changed how open code is reviewed

Coldcard co-founder NVK said AI-assisted code review is changing the internet security environment. In his view, AI models can analyze open-source or previously published software source code faster than humans and spot potential weaknesses earlier.

He also said developers should assume attackers can easily obtain all source code and related material whenever firmware is open source or has been publicly available at any point.

The input says estimated losses from the incident exceeded $70 million, indicating a strong financial incentive for the attacker.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
720

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.