Coldcard Releases New Firmware After $114M Bitcoin Theft, Citing AI Bug Detection
2 hours ago
A three-week security review uncovered several issues separate from the vulnerability responsible for the $114 million bitcoin theft. However, Coinkite warned that installing the latest firmware does not make a previously compromised wallet secure.
Coinkite, the Canadian firm behind the Coldcard hardware wallet, has released a new firmware version weeks after revealing the vulnerability that allowed attackers to steal more than $114 million in bitcoin.
The company said AI played a role in the three-week review, with Kimi and other advanced models used to assess the original randomness vulnerability as well as the wider Coldcard system.
The audit uncovered additional weaknesses involving transaction approval, USB data processing and the way firmware updates are verified.
Updating the firmware will not protect a wallet that has already been compromised. Users whose seeds, or master keys controlling their funds, were generated on vulnerable firmware between 2021 and July 2026 must create a new seed and transfer their assets.
Coldcard’s new seed-generation process requires users to provide their own physical randomness. Owners can do this through 65 unpredictable key presses, 50 rolls of a six-sided die or 128 coin flips.
Physical randomness is used because the outcome of a coin flip or dice roll cannot be predicted by software. The vulnerability behind the theft, by contrast, involved the device’s own automated random-number generation process.
Coinkite also completely replaced the backup random-number generator, removing Yasmarang and switching to a system based on SHA-256, the same hashing algorithm used by Bitcoin.
The updated device now performs a final transaction check immediately before signing. This is designed to prevent a compromised computer connected through USB from modifying a payment after the user has verified it on the device’s display. Signature modes that allow certain transaction details to remain changeable after signing are also disabled by default.
Coinkite said law enforcement agencies are continuing to investigate the thefts and identify the perpetrators, with the company cooperating with the investigation.
Coldcard Mk4 and Mk5 owners are being instructed to install firmware version 5.6.1, while Q model users should install version 1.5.1Q. Coinkite urged users to obtain the updates only through its official downloads page. The company has also created a public status page detailing fixed releases and the migration procedures required for affected users.
How AI Is Changing Security Audits
Coldcard is the fifth bitcoin or crypto company in three weeks to publicly highlight AI’s growing role in security research.
BTCPay Server, an open-source platform that allows merchants to process bitcoin payments themselves, was targeted this month after attackers exploited a vulnerability affecting users’ Lightning nodes. The project is offering up to 3 BTC for the recovery of stolen funds and has paid 0.42 BTC to researchers who identified the vulnerability. It has also advised merchants to use cold storage and regularly move excess funds out of hot wallets, particularly amid the rapid adoption of AI in security work.
On Aug. 10, dozens of Bitcoin companies, including Coinbase, Block, BitGo and Blockstream, signed an open letter calling on AI companies to provide open-source security researchers with early access to their most advanced models.
The Bitcoin Red Team, a volunteer group of 16 developers operating across different time zones, has emerged as the most prominent effort. The group submitted 4,962 findings across 390 projects during its first 24 hours, including 85 critical and 635 high-severity vulnerabilities. Its research also contributed to the report that led to BTCPay Server’s patch.
Bybit, which suffered a roughly $1.46 billion theft attributed to North Korea’s Lazarus Group in February 2025, said AI-assisted security reviews uncovered high-severity vulnerabilities at three to five times the rate of conventional manual audits. The exchange also said AI tools helped prevent approximately $700 million in suspicious withdrawals during the first half of the year.
More Stories
Bitcoin Clears Key Resistance, but Analysts Debate Whether a Bull Run Has Begun
Bitcoin Breaks $77K as Strongest Week Since 2023 Lifts Altcoins
Treasury Isn’t Doing QE or YCC, but Bitcoin Is Still Surging. Here’s Why