Coldcard Seed-Generation Flaw Drains $38 Million in Bitcoin, Coinkite Suspects AI-Assisted Attack

3 min read
Coldcard Seed-Generation Flaw Drains $38 Million in Bitcoin, Coinkite Suspects AI-Assisted Attack
PrimeXBT Editorial Team
Reviewed by PrimeXBT

Topics in article

An attacker drained 594 BTC, about $38 million, from roughly 500 Coldcard hardware wallets in 25 minutes by exploiting a flaw in how the devices generate seed phrases. Coinkite, the wallet's maker, believes the attacker used AI to find the bug — weeks after its own AI review of the identical code found nothing.

An attacker drained 594 BTC, about $38 million, from roughly 500 Coldcard hardware wallets in 25 minutes. Coinkite, the Canadian maker of the Coldcard hardware wallet, said 562 BTC of the haul was later consolidated into a single address. The company believes the same attacker used artificial intelligence to find the underlying flaw, after its own AI review of the identical code weeks earlier turned up nothing.

How the theft unfolded

The sweep hit 500 single-signature addresses across four consecutive blocks, from 960188 to 960191, moving 1,324 UTXOs. No multisig or Taproot wallets were among the victims, and evidence pointed to weak private keys generated when the wallets were created.

An AI on both sides

Coinkite said it has to assume an attacker used AI to review earlier versions of its firmware to uncover the flaw, after running one of the best available models over its own code just weeks earlier without result. Attackers and defenders have the same tools, the company said, but this time "it did not help us, and only helped the bad guys."

What went wrong

The bug traces to a preprocessor guard that checked only whether a setting was defined, not its value, letting Coldcard build seed phrases from a software fallback instead of its hardware random-number generator — a defect present since a March 2021 firmware migration. Coinkite estimates the effective search space at about 40 bits for Mk3 seeds, against a 128-bit target; Mk4, Mk5 and Q keep roughly 72 bits thanks to onboard secure elements. Bitcoin Core contributor instagibbs said he recreated the vulnerable seed on a newly initialized Mk3. Tapsigner, Opendime and Satscard run different code and are unaffected.

What owners must do

Coinkite has shipped hotfix firmware 5.6.0 for Mk4 and Mk5 and 1.5.0Q for Q, but updating does not repair a seed already generated on the old code. Owners need a fresh seed on patched hardware plus a strong BIP-39 passphrase, or at least 99 dice rolls; Mk3, now out of support, is pointed to a separate migration path. Rival maker Trezor said a weak seed stays weak even after being restored to another brand's device, while Block — which published its own analysis and said none of its products are affected — had its hardware lead urge exposed users to move funds as soon as they safely can.

Sources: Decrypt, CryptoSlate, CryptoPotato

Trading involves risk.

Most traded markets

XAU / USD
-0.9% 4,127.61
BRENT
+1.35% 73.620
BTC / USD
+0.7% 63,151.2
EUR / USD
-0.12% 1.14269
USTEC
-0.91% 29,428.7
XAU / USD.24
-0.9% 4,127.61
View all markets

Author

PrimeXBT
Our Editorial Team consists of leading experts with a proven record in the fields of trading, cryptocurrencies, blockchain and finance. We thoroughly research the sources of information in order to provide readers with quality content that serves edu...
Read author’s articles
Alert Triangle Risk Disclaimer
Disclaimer: Some past publications may be outdated. We recommend following our news to stay up to date with the latest information. For any questions, feel free to contact our support team via the chat below.
The content provided here is for informational purposes only. It is not intended as personal investment advice and does not constitute a solicitation or invitation to engage in any financial transactions, investments, or related activities. Past performance is not a reliable indicator of future results.
The financial products offered by the Company are complex and come with a high risk of losing money rapidly due to leverage. These products may not be suitable for all investors. Before engaging, you should consider whether you understand how these leveraged products work and whether you can afford the high risk of losing your money.
The Company does not accept clients from the Restricted Jurisdictions as indicated in our website/ T&C. Some services or products may not be available in your jurisdiction.
The applicable legal entity and its respective products and services depend on the client’s country of residence and the entity with which the client has established a contractual relationship during registration.

Today in markets

Browse Crypto News

Register Now

Trading involves risk

Get started in minutes

Our clients love how fast and simple our sign-up is. It takes just a few minutes to get started!

Get Started Get Started
Get started in minutes

Need Help?

Risk Warning:
Trading in leveraged products carries a high level of risk and may not be suitable for all investors.