
- A three-week security assessment uncovered additional vulnerabilities unrelated to the flaw that led to the $114 million bitcoin theft. Coinkite cautioned, however, that updating the firmware alone will not protect a wallet that has already been compromised.
- Coinkite, the Canadian company behind the Coldcard hardware wallet, has released a new firmware version several weeks after disclosing the vulnerability that enabled attackers to drain more than $114 million in bitcoin.
- AI played a role in the latest review, with Coinkite using Kimi and other advanced models to investigate the original randomness issue and examine the broader security of its devices.
- The audit identified other weaknesses involving transaction authorization, USB data handling and the validation process for firmware updates.
- Users whose wallets were compromised by the original flaw must take additional steps. Anyone who generated a seed or master key on vulnerable firmware between 2021 and July 2026 needs to create a new seed and transfer their funds, as the firmware update cannot reverse an existing compromise.
- Coldcard has changed how new seeds are generated. Users must now provide physical randomness through one of three methods: 65 unpredictable key presses, 50 rolls of a six-sided die or 128 coin flips.
- The company says physical randomness provides an input that software cannot predict. This addresses the type of weakness involved in the original theft, which stemmed from the device’s own automated randomness generation.
- Coinkite also replaced the backup random-number generator, moving away from the Yasmarang algorithm to a SHA-256-based design. SHA-256 is also used by Bitcoin.
- The new firmware adds a transaction verification immediately before signing. This is intended to prevent a compromised USB-connected computer from modifying a payment after the user has confirmed it on the Coldcard screen. Signature modes that allow transaction details to remain editable after signing are now disabled by default.
- The company said law enforcement authorities are still investigating the thefts and attempting to identify the perpetrators. Coinkite said it continues to assist with the investigation.
- Coldcard Mk4 and Mk5 users should install firmware 5.6.1, while Q users should upgrade to 1.5.1Q. Coinkite recommends downloading the updates exclusively from its official downloads page and has published a status page explaining which releases are fixed and which migration steps affected users must complete.
AI Becomes a Bigger Part of Crypto Security
- Coldcard is the latest crypto company to highlight AI’s growing role in security research, joining four other bitcoin and crypto firms that have made similar disclosures over the past three weeks.
- BTCPay Server, an open-source platform for merchants accepting bitcoin payments, was targeted this month after attackers exploited a vulnerability affecting users’ Lightning nodes. The project is offering up to 3 BTC for the recovery of stolen funds and has paid 0.42 BTC to researchers who identified the flaw. Merchants have also been advised to keep funds in cold storage and regularly move excess balances out of hot wallets.
- On Aug. 10, dozens of Bitcoin companies, including Coinbase, Block, BitGo and Blockstream, signed an open letter urging AI developers to provide open-source security researchers with early access to their most capable models.
- The Bitcoin Red Team, a volunteer group of 16 developers working across multiple time zones, has emerged as one of the most prominent efforts. It identified 4,962 issues across 390 projects in its first 24 hours, including 85 critical and 635 high-severity vulnerabilities. Its research also helped produce the report that resulted in BTCPay Server’s patch.
- Bybit, which lost roughly $1.46 billion in a February 2025 attack blamed on North Korea’s Lazarus Group, said AI-assisted audits uncovered high-severity vulnerabilities at three to five times the rate of manual reviews. The exchange also said AI helped prevent approximately $700 million in suspicious withdrawals during the first half of the year.






