Crypto

Coinkite Rebuilds Coldcard Security After $130 Million AI-Driven Bitcoin Heist

Firmware update mandates manual entropy after cryptographic flaw compromises thousands of Bitcoin wallets

Hardware wallet manufacturer Coinkite has deployed an emergency overhaul of its Coldcard operating software after algorithmic weaknesses in key generation facilitated the theft of approximately $130 million in Bitcoin.

Investigators traced the primary breach to a software defect introduced in 2021 that severely degraded cryptographic entropy during seed generation. On affected hardware, security margins dropped from standard 128-bit protection to roughly 40 bits, allowing automated systems to reconstruct private keys without requiring physical access to the devices.

The update mandates immediate firmware migrations for Coldcard Mk4, Mk5, and Q devices to versions 5.6.1 or 1.5.1Q. The release follows a three-week emergency audit conducted alongside external security researchers and artificial intelligence systems, including Kimi, to eliminate critical vulnerabilities across the platform’s core architecture.

Exploitation began systematically in July, when automated scripts drained 594 BTC—valued at $38 million—from approximately 500 air-gapped wallets in less than half an hour. Coinkite reported that attackers likely leveraged large language models to audit historical open-source code repositories and isolate the entropy degradation.

On-chain monitoring by Galaxy Research documented the escalation across three separate attack waves. By mid-August, losses climbed past 1,778 BTC across 4,585 discrete blockchain addresses, pointing to a highly coordinated, programmatic offensive designed to systematically sweep compromised key spaces.

To prevent algorithmic key reconstruction, the new firmware eliminates automated standalone seed generation. Users must now introduce physical entropy by inputting at least 65 key presses, 50 dice rolls, or 128 coin flips, which the system combines with device-level randomness.

Coinkite also discarded its legacy Yasmarang backup pseudo-random number generator, replacing it with SHA-256 Hash_DRBG alongside active monitoring routines to intercept hardware-level generator failures. The company warned that any customer who initialized keys on firmware versions released between 2021 and July 2026 must generate entirely new seeds and transfer their holdings immediately.

The engineering review uncovered secondary attack vectors beyond entropy generation. Engineers added validation checks to stop execution if a partially signed Bitcoin transaction is modified over USB connections between user review and final cryptographic signing.

Additional protections were applied to Delta Mode, firmware validation routines, and internal wallet backup workflows. Industry executives noted that the breach underscores systemic risks facing hardware storage as automated code analysis tools lower the barrier for finding cryptographic flaws.

“We’re treating this as a serious reminder of how the whole security model of a hardware wallet lives or dies on randomness,” Ledger CTO Charles Guillemet said, noting that the exploit exposed the severe costs of implementation failures in cryptographic systems.

Parallel automated threats recently forced swap service Boltz to halt operations after AI-assisted attacks overwhelmed developer patching cycles, while a volunteer Bitcoin Red Team used autonomous agents to uncover thousands of potential flaws across open-source codebases. Coinkite confirmed that federal law enforcement agencies are actively investigating the wallet thefts while fund migrations continue.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button