Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
Coldcard ships firmware update after $114 million Bitcoin theft exposed randomness flaw
00

Coldcard ships firmware update after $114 million Bitcoin theft exposed randomness flaw

Aug 21, 2026

Coinkite has released firmware updates for its Coldcard Mk4, Mk5, and Q hardware wallets following a critical randomness vulnerability that allowed attackers to steal over $114 million in Bitcoin. An AI-assisted security audit revealed that a 2021 configuration error downgraded seed entropy from 128 bits to 40 bits. The new firmware requires users to supply physical entropy via dice rolls, coin flips, or keypresses. However, owners of wallets generated between 2021 and July 2026 must still generate new seeds and migrate their funds to secure their assets.

Coldcard randomness vulnerability

  • ▪A configuration mistake in Coinkite's 2021 Coldcard firmware quietly downgraded its randomness source, reducing seed entropy from 128 bits to as few as 40 bits
  • ▪The reduced entropy in Coinkite's Coldcard firmware allowed attackers to guess private keys and drain wallets without requiring physical access to the devices

Bitcoin theft losses

  • ▪Attackers stole more than $114 million in Bitcoin from Coldcard hardware wallet holders due to the device's randomness flaw
  • ▪Galaxy Research reported on August 14, 2026, that confirmed losses from the Coldcard exploit reached 1,778 Bitcoin, valued at approximately $112 million
  • ▪According to DefiLlama data, the Coldcard hack represents the third-largest cryptocurrency exploit of 2026

Firmware security update

  • ▪Coinkite released firmware version 5.6.1 for Coldcard Mk4 and Mk5 devices and version 1.5.1Q for the Coldcard Q model to address security vulnerabilities
  • ▪The new Coldcard firmware re-checks transaction contents immediately before signing to prevent a compromised computer from tampering with payments post-approval
  • ▪Coinkite replaced its backup random number generator algorithm, Yasmarang, with a new generator built on the SHA-256 hashing function
  • ▪Coinkite's updated firmware blocks certain Bitcoin signature hash modes by default that would otherwise leave transaction outputs editable after signing

Manual entropy requirement

  • ▪The new Coldcard firmware requires users to supply physical randomness by hand to generate new wallet seed phrases
  • ▪To generate a seed, Coldcard users must provide manual entropy through either 65 key presses at unpredictable intervals, 50 rolls of a six-sided die, or 128 coin flips

AI-assisted code auditing

  • ▪The cryptocurrency exchange Bybit reported that AI-assisted auditing identified high-severity flaws at three to five times the rate of manual reviews
  • ▪Coinkite utilized AI frontier models, including Kimi, to audit its entire system and identify vulnerabilities beyond the original randomness bug

Seed migration procedures

  • ▪Installing the new Coldcard firmware update does not secure existing compromised wallets generated on affected firmware between 2021 and July 2026
  • ▪Coldcard owners with wallets generated on affected firmware must generate a new seed phrase on the patched firmware and migrate their funds to the new address

3 sources

Cointelegraph
Coldcard Security Upgrade Strengthens Seed Phrase Generation
View source article
Bankless
Coldcard Ships Deeper Security Fix Following Bitcoin Heist
View source article
CoinDesk
Coldcard ships firmware after $114 million bitcoin theft, says AI helped catch more bugs
View source article

Story comments

Loading comments…

Related entities

Bitcoin

Topics

Crypto hacksCryptography & hashingBitcoin security & risksBitcoin wallets & custodyHardware wallet security