An attacker drained 594 BTC, about $38 million, from roughly 500 Coldcard hardware wallets in 25 minutes by exploiting a flaw in how the devices generate seed phrases. Coinkite, the wallet's maker, believes the attacker used AI to find the bug — weeks after its own AI review of the identical code found nothing.
An attacker drained 594 BTC, about $38 million, from roughly 500 Coldcard hardware wallets in 25 minutes. Coinkite, the Canadian maker of the Coldcard hardware wallet, said 562 BTC of the haul was later consolidated into a single address. The company believes the same attacker used artificial intelligence to find the underlying flaw, after its own AI review of the identical code weeks earlier turned up nothing.
How the theft unfolded
The sweep hit 500 single-signature addresses across four consecutive blocks, from 960188 to 960191, moving 1,324 UTXOs. No multisig or Taproot wallets were among the victims, and evidence pointed to weak private keys generated when the wallets were created.
An AI on both sides
Coinkite said it has to assume an attacker used AI to review earlier versions of its firmware to uncover the flaw, after running one of the best available models over its own code just weeks earlier without result. Attackers and defenders have the same tools, the company said, but this time "it did not help us, and only helped the bad guys."
What went wrong
The bug traces to a preprocessor guard that checked only whether a setting was defined, not its value, letting Coldcard build seed phrases from a software fallback instead of its hardware random-number generator — a defect present since a March 2021 firmware migration. Coinkite estimates the effective search space at about 40 bits for Mk3 seeds, against a 128-bit target; Mk4, Mk5 and Q keep roughly 72 bits thanks to onboard secure elements. Bitcoin Core contributor instagibbs said he recreated the vulnerable seed on a newly initialized Mk3. Tapsigner, Opendime and Satscard run different code and are unaffected.
What owners must do
Coinkite has shipped hotfix firmware 5.6.0 for Mk4 and Mk5 and 1.5.0Q for Q, but updating does not repair a seed already generated on the old code. Owners need a fresh seed on patched hardware plus a strong BIP-39 passphrase, or at least 99 dice rolls; Mk3, now out of support, is pointed to a separate migration path. Rival maker Trezor said a weak seed stays weak even after being restored to another brand's device, while Block — which published its own analysis and said none of its products are affected — had its hardware lead urge exposed users to move funds as soon as they safely can.
Sources: Decrypt, CryptoSlate, CryptoPotato
Trading involves risk.