Coldcard2026-08-21 12:10:55Coldcard ships firmware after bitcoin theft, says AI helped find more bugsColdcard has shipped a firmware update after a three-week review that followed a bitcoin theft. The company said the review uncovered problems unrelated to the flaw that cost users $114 million. It also said the update does not make a compromised wallet safe again, and that AI helped surface additional bugs during the process.1050
Bitcoin2026-08-20 20:49:28Coldcard breach reignites debate over open source, source-available software in BitcoinA new analysis from Bitcoin Magazine argues that the Coldcard hardware wallet incident exposed a core misconception in Bitcoin software: publicly readable code is not the same thing as open-source software. The article says users lost more than $100 million in bitcoin, over 1,500 BTC, after a critical entropy flaw in Coldcard firmware went unnoticed for roughly five years. That flaw, it argues, showed how software safety depends less on source visibility alone and more on who has the legal and economic incentive to review code closely. The piece draws a sharp distinction between Free and Open Source Software standards and “source-available” licensing. It notes that Coldcard firmware was released under MIT terms plus the Commons Clause, which removes the right to sell the software commercially. Because of that restriction, the article says the software does not meet the Open Source Initiative standard. It contrasts that model with Bitcoin Core, whose MIT-licensed code, public review process, contributor structure, nonprofit funding base, and long-running public discussions are presented as a large-scale example of open-source development working as intended. The article also says AI is changing the security equation on both sides. It cites the volunteer Bitcoin Red Team, backed by OpenSats, which used frontier AI models to scan hundreds of Bitcoin repositories and reported thousands of findings, including dozens rated critical or high severity. At the same time, it argues that AI-generated code is adding strain to maintainers and weakening the old security advantage once associated with closed-source software.1160
Coldcard2026-08-20 15:27:45Coldcard releases new firmware to tighten security and asks affected users to regenerate seed phrases and move fundsBlockBeats reported on Aug. 20 that Coldcard has released firmware 5.6.1 for Mk4/Mk5 devices and 1.5.1Q for Q devices. The update follows an emergency fix on July 31 and three weeks of security review, with the main focus on risks tied to a prior seed-phrase generation attack. Coldcard says each newly generated seed phrase must now include at least one user entropy source, and affected users should update first, generate and verify a new seed phrase, then migrate funds to a new wallet. The company also urged Mk4, Mk5 and Q users to verify the firmware signature before installing the update.1410
Coldcard2026-08-20 15:28:53Coldcard rolls out new firmware after mnemonic generation security reviewColdcard has released firmware 5.6.1 for Mk4 and Mk5 devices and version 1.5.1Q for the Q model, following a three-week security review after an emergency fix. The update is aimed at reducing the risk tied to a previously disclosed mnemonic-generation attack. Under the new rules, every newly generated seed phrase must include at least one source of user-provided entropy, either through at least 65 irregular key presses, 50 physical dice rolls, or 128 physical coin flips. That input is then combined with fresh entropy from STM32 TRNG, SE1, and SE2. The firmware also adds staged PSBT verification immediately before signing, tightens USB connection and firmware-update boundaries, improves Delta Mode isolation, fixes an active wallet backup issue, strengthens random number generator initialization and fault checks, and changes the default SIGHASH setting. Coldcard said the release is meant to cut the risk of device compromise. The company also warned that updating firmware does not repair seed phrases created by affected older firmware. Users covered by the security notice are advised to update first, generate and verify a new mnemonic, then move funds to a new wallet. Coldcard recommended that all Mk4, Mk5, and Q users update promptly and verify firmware signatures before installation.1270
Specter2026-08-20 14:07:36Specter flags Coldcard claim as 73 BTC moved through mixers and into phishing Tornado Cash interfaceOn-chain investigator Specter has raised questions about a claimed Coldcard hack after tracing 73 BTC linked to the case. According to Specter, the person described as a victim said funds were moved from Bitcoin to Ethereum after the incident. But blockchain data showed the 73 BTC, valued at about $4.6 million, had come from the Whirlpool mixer two weeks earlier. Part of the funds was then bridged to Ethereum and deposited through a phishing Tornado Cash interface. Specter said two mixers were used during the transfers. The investigator also said the individual had appeared in Telegram groups tied to private key searching and brute-force cracking. Based on those findings, Specter said the supposed victim may in fact be a threat actor, and that the funds may themselves have been stolen by another threat actor.1030
ChainCatcher2026-08-20 14:07:49Specter says claimed Coldcard hack victim story conflicts with on-chain dataOn-chain investigator Specter said the account given by a supposed victim who claimed to have moved funds from Bitcoin to Ethereum after a Coldcard compromise does not line up with blockchain records. According to Specter’s monitoring, the 73 BTC involved, worth about $4.6 million, had originally come from the Whirlpool mixer two weeks earlier. Part of the funds then moved across chains to Ethereum and was deposited through a phishing Tornado Cash interface. Specter added that two mixers were used during the transfer process. The individual was also found in Telegram groups focused on private key searching and brute-force cracking. Based on those findings, Specter said the claimed victim may in fact be a threat actor, and the funds may themselves have been stolen by another threat actor.1040
BitBox2026-08-18 21:06:52BitBox tells users to update after finding severe firmware vulnerabilitiesBitBox, the Swiss hardware wallet maker, said it has fixed multiple severe security issues in its firmware and told users to update through the official BitBoxApp. The company said there have been no reports of stolen funds and that users should not panic, but it still urged all customers to install the latest firmware carefully. According to BitBox, one flaw could have allowed an attacker to manipulate users into installing firmware that could lead to theft. Another severe issue involved memory corruption in the BitBox Multi edition, which could have enabled arbitrary code execution, malicious firmware installation, and potential fund loss. BitBox said its Bitcoin-only edition was not affected because the relevant code is not present in that firmware. The disclosure comes as the Bitcoin wallet sector is still dealing with fallout from a separate Coldcard firmware bug disclosed by Coinkite. In that case, users were told to move funds after weak seed generation exposed wallets to theft. BitBox said its situation is different: users do not need to migrate funds, only update their device firmware.1180
Metaplanet2026-08-19 13:54:06Metaplanet Plans 2,100 BTC Injection Into Super League as SEC Unveils Proposed Crypto Asset Offering FrameworkWuBlockchain’s daily roundup highlighted a set of major crypto developments spanning corporate treasury expansion, U.S. securities regulation, bitcoin market research, wallet security, and institutional positioning. At the center of the update, Japan-listed bitcoin treasury firm Metaplanet said it reached a definitive agreement with Nasdaq-listed Super League Enterprise to inject 2,100 BTC, valued at about $132.1 million, plus $2.5 million in cash through its U.S. subsidiary. In return, Metaplanet would receive common stock, preferred stock, and warrants, bringing the initial investment to about $134.6 million. After closing, Super League is expected to rename itself Superplanet, Inc., change its ticker to SUPA, and serve as Metaplanet’s U.S. bitcoin treasury platform, with Metaplanet holding about 95.7% of its common shares. The roundup also noted that the U.S. Securities and Exchange Commission has proposed “Regulation Crypto Assets,” a new offering framework for certain crypto-related investment contracts that includes two Securities Act registration exemptions and a conditional safe harbor. Separately, BlackRock and VanEck published fresh assessments of bitcoin’s drawdown and accumulation signals, investigators said the FBI may have identified a suspect in the Coldcard wallet exploit, and CryptoSlate reported that institutional bitcoin ETF holdings rose in the second quarter despite a decline in BTC’s price.1270