Coldcard ships firmware after $114 million bitcoin theft; says AI helped catch more bugs

Three weeks of review turned up problems unrelated to the flaw that cost users $114 million, but updating still does not make a compromised wallet safe.
Coinkite has released new firmware for its Coldcard hardware wallets after a randomness flaw enabled attackers to steal more than $114 million in bitcoin, but compromised wallets still require new seeds and fund migration.
The company used AI tools, including frontier models, to audit its entire system, leading to fixes in transaction approval, USB data handling and firmware validation, and it now requires users to generate seeds with physical randomness such as dice rolls or coin flips.
The Coldcard update comes amid a broader shift toward AI-assisted security across the bitcoin ecosystem, with projects like BTCPay Server, major exchanges and the volunteer Bitcoin Red Team reporting that AI-driven reviews are uncovering critical bugs at far higher rates than manual audits.
Coinkite, the Canadian company behind the Coldcard hardware wallet, has released new firmware weeks after disclosing the flaw that let attackers drain more than $114 million from bitcoin holders.
The company said the review behind it was AI-assisted, naming Kimi and other frontier models among the tools used to examine not just the faulty randomness code but the whole system.
That review found problems unrelated to the original bug in the way transactions are approved, how data is handled over USB and how firmware updates are validated.
Installing the update does not make an existing compromised wallet safe. Anyone whose seed, or the master key that controls a wallet's coins, was created on affected firmware between 2021 and July 2026 still has to generate a new one and move their money across.
New seeds now work differently. Every one requires the owner to supply the randomness by hand, either 65 key presses at unpredictable intervals, 50 rolls of a six-sided die, or 128 coin flips.
Physical randomness is used because a die or a coin produces results no software can predict, while the flaw that caused the theft was in the device generating randomness by itself, as CoinDesk previously explained.
Underneath, Coinkite replaced the backup random number generator entirely, swapping an algorithm called Yasmarang for one built on SHA-256, the hashing function bitcoin itself uses.
The device now re-checks a transaction immediately before signing it, so a computer compromised at the USB port cannot alter a payment after the owner has approved it on screen. sSgnature modes that leave parts of a transaction editable after signing are now blocked by default.
Law enforcement is still investigating the thefts and working to identify those responsible, the company said, and it remains available to assist.
Coinkite is asking owners of its Mk4 and Mk5 devices to install version 5.6.1, and owners of the newer Q model to install 1.5.1Q, from its official downloads page only. It has also launched a public status page listing which releases are fixed and what migration steps apply.
How AI is helping catch bugs
Coldcard is the fifth bitcoin or crypto outfit in three weeks to say publicly that AI has changed how security work gets done.
BTCPay Server, free software merchants run themselves to accept bitcoin payments, was hit this month when attackers drained Lightning nodes belonging to its users through a flaw it had just patched. The project is offering a bounty of up to 3 BTC for the return of the money and has paid 0.42 BTC to the researchers who found the flaw, while telling merchants to keep funds in cold storage and move excess out of hot wallets regularly, "especially during this period of rapid, AI-driven change."
Dozens of bitcoin firms including Coinbase, Block, BitGo and Blockstream signed an open letter on Aug. 10, as CoinDesk reported , asking AI labs to give open-source security researchers early access to their most capable models.
A volunteer effort has been the most visible of the three. The so-called Bitcoin Red Team, a collective of sixteen developers working across time zones, filed 4,962 findings against 390 projects in its first 24 hours, including 85 critical and 635 high-severity issues, and produced the report behind BTCPay's patch.
Crypto exchange Bybit, which lost roughly $1.46 billion to North Korea's Lazarus Group in February 2025, said this week that AI-assisted auditing found high-severity flaws at three to five times the rate of manual review, and helped it block a mammoth $700 million in suspicious withdrawals across the first half of the year.
1 Zcash jumps 48% to over $800 as Grayscale spot ETF push adds to ‘next bitcoin’ buzz 45 min ago
2 How a Treasury buyback tweak helped bitcoin surge 25% to nearly $80,000 in days 1 hr ago
3 Crypto advocates join in suing Illinois over digital asset tax 8 hrs ago
4 Pass the Clarity Act 11 hrs ago
5 Ethena's ENA token surges 48%, but altcoin season will have to wait 14 hrs ago
6 Analysts split on whether Bitcoin's surge past key levels signals a new bull run 18 hrs ago
7 The hard truth is that the Clarity Act is an anti-crypto bill 18 hrs ago
8 Bitcoin faces $80,000 test as thinner weekend liquidity looms 18 hrs ago
9 Nomura-backed Laser Digital wins Japan's first crypto approval in four years 19 hrs ago
10 Bitcoin tops $77,000 as best week since 2023 pulls altcoins along for the ride 20 hrs ago
Anvil: The Missing Collateral Layer
