Coinkite has shipped new firmware for its Coldcard hardware wallets after a randomness flaw let attackers steal more than $114 million in bitcoin. The company says AI tools helped its review team find additional bugs unrelated to the original flaw, but installing the update alone does not secure a wallet that was already compromised.
Coinkite has released new firmware for its Coldcard hardware wallet. The update comes weeks after disclosing the flaw that let attackers drain more than $114 million from bitcoin holders. The company says the review behind the fix was AI-assisted, naming Kimi and other frontier models among the tools used to examine not just the faulty randomness code but the whole system.
That review found problems unrelated to the original bug in how transactions are approved, how data is handled over USB, and how firmware updates are validated. As a result, Coinkite pushed fixes across all three areas alongside the randomness patch.
Compromised wallets still need new seeds
Installing the update does not make an existing compromised wallet safe. Anyone whose seed phrase, the master key that controls a wallet's coins, was created on affected firmware between 2021 and July 2026 still has to generate a new one and move their money across.
New seeds now work differently: every one requires the owner to supply randomness by hand, through either 65 key presses at unpredictable intervals, 50 rolls of a six-sided die, or 128 coin flips. Physical randomness is used because a die or a coin produces results no software can predict, while the flaw that caused the theft was in the device generating randomness by itself.
Underneath, Coinkite replaced the backup random number generator entirely, swapping an algorithm called Yasmarang for one built on SHA-256, the hashing function bitcoin itself uses. The device now also re-checks a transaction immediately before signing it, so a computer compromised at the USB port cannot alter a payment after the owner has approved it on screen.
Coinkite is asking owners of its Mk4 and Mk5 devices to install version 5.6.1, and owners of the newer Q model to install 1.5.1Q, from its official downloads page only.
AI-assisted audits spread across bitcoin security
Coldcard is the fifth bitcoin or crypto outfit in three weeks to say publicly that AI has changed how security work gets done. BTCPay Server was hit this month when attackers drained Lightning nodes belonging to its users through a flaw it had just patched. The project is offering a bounty of up to 3 BTC for the return of the funds and has paid 0.42 BTC to the researchers who found the flaw.
Dozens of bitcoin firms including Coinbase, Block, BitGo and Blockstream signed an open letter on Aug. 10 asking AI labs to give open-source security researchers early access to their most capable models. Separately, the volunteer Bitcoin Red Team, a collective of sixteen developers, filed 4,962 findings against 390 projects in its first 24 hours, including 85 critical and 635 high-severity issues.
Crypto exchange Bybit lost roughly $1.46 billion to North Korea's Lazarus Group in February 2025. It said this week that AI-assisted auditing found high-severity flaws at three to five times the rate of manual review. The reviews also helped it block $700 million in suspicious withdrawals across the first half of the year.
Source: CoinDesk
Trading involves risk.