NewsCryptoColdCard Bitcoin Exploit Surpasses $100 Million in Losses, CoinKite CEO Warns of AI-Driven Security Threats

ColdCard Bitcoin Exploit Surpasses $100 Million in Losses, CoinKite CEO Warns of AI-Driven Security Threats

Author: BitcoinKE·

Key Takeaways

  • Attackers exploited a random number generation flaw in certain ColdCard wallet firmware versions to steal over 2,000 BTC worth more than $100 million without physically tampering with devices.
  • The vulnerable firmware had been publicly available since March 2021, remaining undetected for over two years before the coordinated attacks were identified.
  • CoinKite CEO Rodolfo Novak warned that AI-assisted code review now enables both attackers and defenders to discover latent software vulnerabilities faster than seasoned industry experts.
  • Blockchain intelligence firm Galaxy identified three separate waves of attacks targeting ColdCard users and cautioned that a potential fourth wave could push total losses to approximately $130 million.
  • The incident demonstrates that hardware wallets' offline design alone cannot protect users from vulnerabilities embedded in firmware, cryptographic libraries, and key-generation processes.
ColdCard Bitcoin Exploit Surpasses $100 Million in Losses, CoinKite CEO Warns of AI-Driven Security Threats

The maker of ColdCard Bitcoin hardware wallets has issued a warning that malicious actors are increasingly likely to leverage artificial intelligence to identify even the smallest software vulnerabilities, following a series of attacks that resulted in the theft of over $100 million in cryptocurrency.

ColdCard, produced by Canadian firm CoinKite, is a Bitcoin-only hardware wallet favored by privacy-focused users for its open-source firmware and air-gapped design. The incident has renewed concerns about the security of hardware wallets—physical devices designed to store the private keys required to access cryptocurrency. Such wallets have long been considered safer than keeping digital assets on exchanges, as they can remain disconnected from the internet.

However, users of certain ColdCard wallets recently had their funds drained in a coordinated series of attacks. The attackers appear to have exploited a weakness in the way specific versions of the wallet generated cryptographic keys. The devices themselves were not physically tampered with, nor were they connected to the internet. Instead, the flaw caused the wallets' algorithms to produce insufficiently random numbers, which allowed attackers to deduce some of the keys. Random number generation flaws are a well-documented class of cryptographic vulnerability: a similar issue affected Bitcoin wallets on Android in 2013, when the platform's flawed random number generator allowed attackers to steal funds from wallets generated on affected devices.

Rodolfo Novak, CEO of CoinKite, described the incident as evidence of a shifting cybersecurity landscape.

"We believe this is a sober reality of the new AI paradigm," Novak wrote in an apology addressing the flaw. "AI-assisted code review can now find latent bugs at a speed that is outpacing even the industry's most seasoned experts."

Novak warned that developers should operate under the assumption that publicly available firmware can be scrutinized by both attackers and defenders alike.

CoinKite initially urged customers to update the affected firmware—originally released in March 2021—and transfer their Bitcoin to new wallets generated with fresh recovery seeds. The fact that the vulnerable firmware had been available for over two years before the attacks were identified highlights the challenge of detecting subtle cryptographic flaws in widely deployed code. The company stressed the urgency of the situation and advised users to migrate their funds while the attacks were still active.

Within days, blockchain intelligence firm Galaxy reported that it had identified three separate waves of attacks targeting ColdCard users. The attacks resulted in the theft of over 2,000 BTC, valued at more than $100 million at the time of reporting. Galaxy subsequently warned of a possible fourth wave, estimating that total losses could potentially reach approximately $130 million.

The incident underscores a fundamental risk associated with hardware wallets: keeping private keys offline does not eliminate vulnerabilities in the software used to generate or protect those keys. It also challenges the widely held assumption that self-custody is inherently safer than centralized cryptocurrency storage. The episode comes amid broader scrutiny of hardware wallet security across the industry, following years of debate over supply chain risks, firmware transparency, and the adequacy of third-party security audits.

The ColdCard exploit points to a broader transformation in cybersecurity. As AI systems become increasingly proficient at reviewing code and identifying subtle vulnerabilities, flaws that may have gone undiscovered for years could become significantly easier for attackers to locate and exploit. The episode is likely to intensify existing industry discussions about formal verification methods, continuous auditing practices, and responsible disclosure frameworks for hardware wallet firmware.

For cryptocurrency users and wallet developers, the episode reinforces that security depends not only on keeping devices offline, but also on the integrity of the firmware, cryptographic libraries, and key-generation processes that underpin them.