Coinkite2026-08-04 20:17:49Coinkite says firmware boundary flaw slipped past human and AI review for yearsCoinkite said a flaw was located at the boundary between two unrelated firmware submodules, rather than in its Bitcoin or cryptographic code, which helped it evade both manual and AI-assisted code review for years. The statement was cited by Bitcoin News in a post on X. After the incident, Coinkite said it tested several frontier AI models, including Kimi K3, Claude Fable, and Codex 5.6. According to the company, none of those models detected the flaw. Coinkite is now urging security-critical projects to conduct dedicated audits of build systems and submodule boundaries. It also warned that AI-assisted development may leave similar blind spots in the Bitcoin ecosystem. The company’s comments focused on where the flaw appeared in the firmware structure and on the limits it observed in both human review and current AI model checks following the incident.1810
Changpeng Zha2026-08-01 21:10:21CZ advises users to spread crypto holdings across multiple wallets after hardware wallet flaw reportBinance founder Changpeng Zhao said in a post on X that crypto holders should spread funds across multiple wallets to reduce risk, warning that hardware wallets may carry vulnerabilities. The issue referenced in the post traces back to a firmware defect from March 2021 that affected random number generation. According to the report cited in the item, the flaw led to the theft of about 1,082 BTC, valued at roughly $70 million, from 1,196 addresses. Although the manufacturer has already released an emergency patch, the guidance highlighted in the report was not limited to installing a firmware update. Users were instead advised to create a new seed and move funds to fresh wallets. The item was carried by Techub and cited CoinDesk as the source.1700
Coldcard2026-07-31 10:35:29Coldcard firmware flaw linked to theft of about 594 BTC from roughly 500 walletsAn attacker drained about 594 BTC, valued in the report at roughly $38 million, from around 500 separate wallets in a 25-minute window between 01:31 and 01:56 UTC on Thursday, according to Unchained. The theft was traced to a flaw in how Coldcard hardware wallets generated keys. A report from Block’s bitcoin engineering and security teams said a build setting caused some Coinkite devices to derive keys from known values — including a unique identifier, timer state and call history — instead of a random number generator. Block said the same weakness also affected paper wallet private keys, seed-splitting masks and device cloning keys. The exposure depends on the firmware running when a wallet was created, not when the device was purchased, and later firmware updates do not fix seeds that were already generated. Block said the issue affected Coldcard Mk3 devices running v4.0.0, released in 2021, as well as later Mk4, Q and Mk5 models. Coinkite said the impact on Mk4, Mk5 and Q was less severe, but still serious, and advised affected users to migrate to a seed created on an unaffected device.1780