Coldcard Flaw Drains $38M in Bitcoin; Coinkite Says AI Found Bug

Get the Finance newsletter
Daily finance — markets, central banks, M&A, the prints that move money. Free.
- Coinkite disclosed that a firmware build error on its Coldcard hardware wallets let seeds be drawn from a software fallback inherited from MicroPython instead of the hardware generator — a flaw dating to a March 2021 migration.
- The exploit drained roughly 594 BTC (~$38 million) from about 500 wallets within 25 minutes, with 562 BTC since consolidated into a single address.
- Coinkite said it believes an attacker used AI to review its open-source firmware, noting that its own AI code review weeks earlier "did not find this bug or anything serious."
- Every current Coldcard model is affected to some degree: the Mk3's effective seed search space is roughly 40 bits (versus a 128-bit target), while the Mk4, Q, and Mk5 reach about 72 bits via their secure elements.
- Coinkite shipped emergency firmware (v5.6.0 for Mk4/Mk5, v1.5.0Q for Q) but warned that updating does not repair seeds already created on affected firmware; Mk3 owners are directed to a separate migration path.
- Trezor told users a seed generated on a flawed Coldcard stays weak even after restoration to another device, while Block confirmed its products are unaffected and its hardware lead Max Guise urged exposed users to move funds.
Why it matters: Roughly 500 Coldcard users lost a combined $38 million in 25 minutes because a build error silently defaulted to a software fallback since March 2021, leaving every current model compromised at the seed level. Firmware updates do not repair seeds already generated, so affected owners must create new seeds on patched hardware or migrate entirely. The episode highlights an asymmetry in AI-assisted code review: Coinkite's own scan missed the bug; the attacker's didn't.



