Market desk Bitcoin Ethereum Altcoins DeFi Stablecoins Markets & Trading

Coldcard Releases Security Overhaul Following $130 Million Bitcoin Exploit

Coinkite has issued new firmware for Coldcard hardware wallets after a seed-generation vulnerability resulted in over $130 million in Bitcoin thefts.
2 weeks ago 33 views
Coldcard Releases Security Overhaul Following $130 Million Bitcoin Exploit

Hardware wallet manufacturer Coinkite has released a comprehensive security update for its Bitcoin devices following a seed-generation flaw that exposed users to substantial thefts. In a blog post, the company urged users of Coldcard Mk4, Mk5, and Q devices to upgrade to firmware versions 5.6.1 or 1.5.1Q.

The security overhaul follows a three-week review conducted with outside security researchers and artificial intelligence models. The investigation was triggered after attackers in July began draining air-gapped Coldcard wallets by exploiting a firmware flaw dating back to 2021. The vulnerability reduced entropy in certain wallet seeds, making private keys easier to guess and lowering security levels significantly.

By mid-August, tracking by Galaxy Research and subsequent reports indicated that the exploit had resulted in roughly $130 million in stolen Bitcoin across multiple attack waves. Coinkite suggested that attackers may have utilized AI to examine older versions of its open-source firmware to uncover the vulnerability.

To address the entropy issue, the updated firmware now requires users to incorporate external randomness when generating new wallet seeds. Users must supply this randomness through a minimum of 65 key presses, 50 dice rolls, or 128 coin flips, which the device then combines with its internal random generation systems. Coinkite also replaced its Yasmarang backup pseudo-random number generator with SHA-256 Hash_DRBG and added checks to monitor hardware random number generator failures.

Additionally, the security overhaul addresses functions beyond seed generation:

  • Transaction Signing: Coldcard now checks partially signed Bitcoin transactions (PSBTs) immediately before signing to prevent compromised USB-connected computers from altering transactions after user review.
  • USB Data Handling: Data access via USB has been tightened.
  • Backups and Modes: The update hardens Delta Mode and changes how the device handles wallet backups.

Coinkite advised that users who generated seeds on affected firmware versions between 2021 and July 2026 must create a new seed using the updated software and transfer their funds. The company noted that law enforcement investigations into the thefts remain ongoing.

Market snapshot

Top cryptocurrency prices

Explore all prices
Market prices will appear after the next scheduled refresh.