Coldcard Ships New Firmware After $114 Million Bitcoin Theft, Says AI Helped Catch More Bugs
Key Takeaways
- •Coinkite shipped new Coldcard firmware after a flaw in its randomness generation enabled thefts exceeding $114 million from bitcoin holders.
- •The company said its AI-assisted review, which included the Kimi model, found additional security issues beyond the original randomness bug.
- •Wallet seeds created on affected firmware between 2021 and July 2026 remain compromised and must be replaced by generating a new seed and moving funds.
- •The new firmware requires owners to provide randomness manually when creating seeds, using key presses, dice rolls, or coin flips.
- •Coinkite says the update also re-checks transactions before signing, blocks certain editable signature modes by default, and should be downloaded only from its official site.

Coinkite, the Canadian company behind the Coldcard hardware wallet, has shipped new firmware, weeks after disclosing the flaw that allowed attackers to drain more than $114 million from bitcoin holders. Coldcard is a bitcoin-only device whose core pitch is keeping keys offline — transactions can even be signed with no network connection at all — so a flaw in how the device created those keys struck at the heart of what owners buy it for.
The company said the security review behind the release was AI-assisted, naming Kimi — a large language model from Chinese AI lab Moonshot AI — among the frontier models used to examine not only the faulty randomness code but the entire system. That review surfaced additional problems unrelated to the original bug, affecting the way transactions are approved, how data is handled over USB, and how firmware updates are validated, the checks that determine whether software loading onto the device is genuinely Coinkite's.
Installing the update does not make an already-compromised wallet safe. Anyone whose seed — the master key that controls a wallet's coins — was created on affected firmware between 2021 and July 2026 must still generate a new one and move their funds across.
New seeds now work differently. Each one requires the owner to supply the randomness by hand: either 65 key presses at unpredictable intervals, 50 rolls of a six-sided die, or 128 coin flips. Physical randomness is used because a die or a coin produces results no software can predict, whereas the flaw behind the theft lay in the device generating randomness on its own, as CoinDesk previously explained. Weak randomness has hurt bitcoin users before: in 2013, Google warned that a flaw in Android's random-number generator let attackers calculate private keys and steal funds from wallet apps. Coldcard has long let owners add dice rolls as an optional supplement to its built-in generator; the new firmware makes user-supplied randomness mandatory for every new seed, a break from standard hardware-wallet practice, and whether other makers follow is an open question.
Under the hood, Coinkite replaced the backup random number generator entirely, swapping out an algorithm called Yasmarang for one built on SHA-256, the hashing function bitcoin itself uses.
The device now re-checks a transaction immediately before signing it, so a computer compromised at the USB port cannot alter a payment after the owner has approved it on screen. Signature modes that leave parts of a transaction editable after signing are now blocked by default.
Law enforcement is still investigating the thefts and working to identify those responsible, the company said, adding that it remains available to assist.
Coinkite is asking owners of its Mk4 and Mk5 devices to install version 5.6.1, and owners of the newer Q model to install 1.5.1Q, downloaded from its official downloads page only — an instruction that matters in an industry where fake or tampered wallet downloads have long been used to steal funds. The company has also launched a public status page listing which releases are fixed and what migration steps apply.
How AI is helping catch bugs
Coldcard is the fifth bitcoin or crypto outfit in three weeks to say publicly that AI has changed how security work gets done.
BTCPay Server, the free software that merchants run themselves to accept bitcoin payments, was hit this month when attackers drained Lightning nodes belonging to its users through a flaw it had just patched. The project is offering a bounty of up to 3 BTC for the return of the money and has paid 0.42 BTC to the researchers who found the flaw, while telling merchants to keep funds in cold storage and move excess out of hot wallets regularly, "especially during this period of rapid, AI-driven change."
Source: CryptoNewsNet