cryptocurrency widget, price, heatmap
arrow
Burger icon
cryptocurrency widget, price, heatmap
News/Coldcard Ships Security Overhaul After Bitcoin Seed Exploit

Coldcard Ships Security Overhaul After Bitcoin Seed Exploit

Van Thanh Le

Van Thanh Le

PublishedAug 22 2026

UpdatedAug 22 2026

2 hours ago4 minutes read
A blocky robot uses dice entropy with Coinkite hardware security

New firmware changes seed generation as affected users face mandatory wallet migration

TL;DR

  • Coinkite released new Coldcard firmware after a seed-generation flaw allowed attackers to drain Bitcoin from wallets created with insufficient randomness.
  • Updating the device alone does not protect an already compromised seed; affected users must generate a new seed and move their funds.
  • A broader security review also produced changes to transaction signing, USB handling, firmware validation, backups and other wallet functions.

Trade smarter on Jupiter, Solana’s leading DEX built for fast execution and deep liquidity. 

Swap tokens at competitive rates, route across multiple liquidity sources automatically, and access perpetuals, DCA, and advanced trading tools — all in one place!


Coinkite released a major Coldcard security update on Aug. 21, 2026, after a seed-generation vulnerability exposed Bitcoin wallets to theft by producing some private keys with insufficient randomness. The Canadian hardware wallet maker told Coldcard Mk4 and Mk5 owners to install firmware 5.6.1 and Coldcard Q users to install version 1.5.1Q, while warning that users whose seeds were created on affected firmware must generate new seeds and transfer their Bitcoin because installing the patch does not repair an already compromised wallet.

The vulnerability involved entropy, the randomness used to create wallet seeds and ultimately private keys. Some affected Coldcard devices generated seeds with substantially less randomness than intended, reducing security from 128 bits of entropy to roughly 40 bits in certain cases. That smaller search space made private keys easier for attackers to guess without obtaining physical access to the hardware wallet, including devices being operated as air-gapped wallets.

Affected firmware dated back to 2021 and remained relevant through July 2026. Coinkite said users who generated seeds on vulnerable versions during that period must first update their devices, then create entirely new seeds under the corrected firmware and move their Bitcoin to addresses controlled by those seeds. The existing seed remains weak after a firmware upgrade because the underlying private-key material has already been generated.

Theft estimates rose as attacks continued

The first major attack described during the incident drained 594 BTC, worth about $38 million at the time, from roughly 500 wallets in 25 minutes. Coinkite later suggested attackers may have used artificial intelligence to examine historical versions of its open-source firmware and locate the randomness weakness, but that possibility was presented as a theory rather than a confirmed account of the attackers' methods.

Galaxy Research had tracked roughly $88.6 million in stolen Bitcoin across 4,585 addresses by early August 2026. Galaxy Research said the activity appeared deliberate and programmatic and could potentially have been orchestrated using a large language model.

By Aug. 14, Galaxy Research had tracked more than 1,778 BTC, worth roughly $112 million at the time, across three major attack waves and dozens of smaller incidents. The available Aug. 21 loss figures did not match: one total was more than $114 million, while another put cumulative losses at roughly $130 million.

Stage Tracked amount Additional detail
First major attack 594 BTC, about $38 million Roughly 500 wallets affected within 25 minutes
Early August 2026 Roughly $88.6 million Galaxy Research tracked thefts across 4,585 addresses
Aug. 14 More than 1,778 BTC, roughly $112 million Three major attack waves plus dozens of smaller incidents
Aug. 21 More than $114 million One aggregate loss figure available that day
Aug. 21 Roughly $130 million A separate cumulative loss figure available that day

Coldcard adds physical randomness to every new seed

Coinkite changed seed generation so users must now contribute physical randomness rather than relying solely on the device's internal process. A new seed requires at least 65 key presses made at unpredictable intervals, 50 rolls of a six-sided die or 128 coin flips. Coldcard combines that manually produced entropy with randomness generated internally by the device.

Physical inputs were added because a die or coin produces results that software inside the wallet cannot predict. Coinkite also replaced the Yasmarang backup pseudo-random number generator with SHA-256 Hash_DRBG and added checks designed to detect failures in the wallet's hardware random-number generator.

The firmware release followed a three-week review of Coldcard's systems involving outside security researchers and AI tools including Kimi and other frontier models. Coinkite said the work examined more than the randomness code and found additional problems involving transaction approval, USB data handling and firmware-update validation.

“We are grateful to the security researchers who went above and beyond over the past weeks, reporting issues, reproducing edge cases, and reviewing our fixes,” Coinkite said. “Their work put this firmware under intense, sustained scrutiny and made this release stronger.”

Transaction signing and USB protections also change

Coinkite said the new firmware fixes issues involving transaction signing, USB data handling, firmware validation, Delta Mode and wallet backups. Coldcard now rechecks a partially signed Bitcoin transaction, or PSBT, immediately before signing it.

Previously, a compromised computer connected through USB could theoretically modify a transaction after the user reviewed it on the Coldcard but before the hardware wallet produced the signature. The updated firmware stops the signing process and displays a warning if the transaction has changed. Coinkite characterized that issue as theoretical and did not say it had been exploited in the theft campaign.

Signature modes that leave parts of a transaction editable after signing are also blocked by default. Coinkite tightened USB data access, hardened Delta Mode and changed the handling of wallet backups as part of the broader overhaul.

Coinkite also launched a public status page showing which releases have been fixed and which migration steps apply. The company directed owners to obtain the new firmware from its official downloads page.

AI security tools spread across Bitcoin projects

Coldcard became the fifth Bitcoin or crypto organization in three weeks to publicly say AI had changed how security work was being performed. The same period included defensive use of advanced models as well as concerns that attackers could use them to find vulnerabilities faster.

BTCPay Server was hit after attackers drained Lightning nodes belonging to users through a flaw the project had recently patched. BTCPay Server offered a bounty of up to 3 BTC for the return of the funds and paid 0.42 BTC to researchers who discovered the weakness. The project advised merchants to keep funds in cold storage and regularly move excess funds from hot wallets, “especially during this period of rapid, AI-driven change.”

Dozens of Bitcoin companies, including Coinbase, Block, BitGo and Blockstream, signed an open letter on Aug. 10, 2026, asking AI laboratories to give open-source security researchers early access to their most capable models.

The Bitcoin Red Team, a volunteer group of 16 developers working across time zones, filed 4,962 findings involving 390 projects during its first 24 hours. Those findings included 85 critical issues and 635 high-severity vulnerabilities. The group also produced the work behind BTCPay Server's patch.

Bybit, which lost roughly $1.46 billion to North Korea's Lazarus Group in February 2025, said AI-assisted auditing was identifying high-severity flaws at three to five times the rate of manual reviews. Bybit also said the technology helped it block about $700 million in suspicious withdrawals during the first half of 2026.

Swap service Boltz had separately suspended operations after saying AI-assisted attackers were discovering vulnerabilities faster than its developers could fix them. The Bitcoin Red Team likewise used AI agents to identify thousands of potential vulnerabilities across hundreds of Bitcoin projects.

Ledger CTO Charles Guillemet said the Coldcard incident highlighted the importance of wallet entropy. “We're treating this as a serious reminder of how the whole security model of a hardware wallet lives or dies on randomness,” Guillemet said. “Cryptography is hard and implementing it securely is harder. This week's Coldcard incident made that visible in the most expensive way possible.”

Investigation continues as customers migrate funds

Coinkite said law enforcement was continuing to investigate the thefts while affected customers moved Bitcoin into newly generated wallets.

“Law enforcement authorities continue investigating the thefts and are working to identify those responsible,” Coinkite said. “We remain available to assist, and authorities are keeping us informed of material developments.”

Coinkite added that it would “remain committed to supporting every customer working through their migration until it’s done.”

The remediation separates three distinct security issues: the historical entropy vulnerability that was exploited, the need to replace seeds already generated under vulnerable firmware, and the additional wallet weaknesses uncovered during the subsequent security review.

This article has been refined and enhanced by ChatGPT.

cryptocurrency widget, price, heatmap
v 5.14.11
© 2017 - 2026 COIN360.com. All Rights Reserved.