Technology & InnovationNeutral
63
BTC

Coldcard Wallet Flaw Drains $38M in Bitcoin, AI Suspected

A critical flaw in Coldcard wallets allowed attackers to guess seeds, stealing 594 BTC ($38M) from 500 wallets in 25 minutes. A build error forced software randomness, and AI may have discovered the vulnerability. Users must create new seeds on updated firmware.

DecryptDecrypt Agent

Quick Take

1

Flaw in Coldcard firmware led to guessing seeds, draining $38M in BTC from 500 wallets in 25 minutes.

2

A build error used software randomness instead of hardware, reducing seed entropy to ~40 bits.

3

Coinkite believes AI helped the attacker find the bug, while its own AI review missed it.

4

Affected users must migrate promptly; even restoration on other wallets won't fix weak seeds.

Market Impact Analysis

Neutral

Isolated wallet exploit; unlikely to significantly impact broader crypto markets.

Timeframeshort

Speculation Analysis

Factuality95/100
RumorsVerified
Speculation Trigger60/100
MinimalExtreme FOMO

Key Takeaways

  • Flaw in Coldcard firmware allowed attackers to guess seeds, draining $38M in BTC from 500 wallets within 25 minutes.
  • A build error forced firmware to rely on a weak software random number generator, slashing seed entropy to roughly 40 bits for Mk3 devices.
  • Coinkite suspects AI helped the attacker discover the vulnerability, while its own internal AI review failed to flag the issue.
  • Affected users must immediately generate new seeds on patched firmware—simply restoring on another wallet does not fix the weak seed.
BTC Stolen 594 BTC ($38M) Total drained from affected wallets
Wallets Hit ~500 Drained in just 25 minutes
Entropy Drop ~40 bits (Mk3) Down from the intended 128 bits
Flaw Duration Since March 2021 Seed generation vulnerability active

What Happened

A catastrophic flaw in Coldcard hardware wallets was exploited early Friday, allowing an attacker to drain 594 BTC—worth approximately $38 million—from roughly 500 wallets. The entire heist unfolded in just 25 minutes, with the stolen funds quickly consolidated into a single address. The weakness stemmed from a build error that forced the firmware to generate seeds using a predictable software random number generator instead of the secure hardware module. This reduced the effective seed entropy to as low as 40 bits, making them guessable. Coinkite believes an attacker used artificial intelligence to comb through its open-source code and uncover the vulnerability—the same flaw its own AI review missed just weeks earlier.

The Numbers

The breach drained 594 BTC, consolidating 562 BTC into one address. The attack swept 500 wallets within 25 minutes, pointing to automation. The seed generation flaw, introduced in a March 2021 firmware update, left Mk3 devices with only 40-bit effective entropy—a fraction of the intended 128 bits. Newer Mk4, Q, and Mk5 models fared slightly better at around 72 bits due to extra entropy from secure elements, but still fall short of full security. Coinkite has shipped an emergency hotfix, but the firmware update cannot repair seeds already created.

Why It Happened

A subtle preprocessing error in Coldcard’s codebase lay dormant for years. The firmware included two randomness functions with identical signatures: a hardware generator and a software fallback. A misconfigured preprocessor guard failed to check the value of a setting, causing the build to default to the weak software fallback. Since the March 2021 migration, every seed generated on affected devices relied on this predictable source. Coinkite suspects an adversary used AI to scan the publicly available source code, identify the flaw, and develop an automated exploit—outpacing the company’s own defensive AI review.

Broader Impact

The incident underscores a growing threat: AI-enabled vulnerability discovery in open-source crypto infrastructure. While hardware wallets are designed to be trust-minimized, a single software bug can break that trust. Regulators and users alike may demand more rigorous third-party audits and AI-driven security reviews. For the broader market, the exploit remains isolated to Coldcard, but it could accelerate calls for stronger standards in hardware wallet seed generation.

What to Watch Next

  • Coinkite’s post-mortem: The company will likely release a detailed technical breakdown and may announce new security protocols or audit measures.
  • Movement of stolen funds: With 562 BTC consolidated, exchanges and blockchain analytics firms will track the coins; any attempt to cash out could signal the attacker’s identity.
  • Industry response: Other hardware wallet makers may proactively audit their own firmware for similar issues, potentially leading to widespread security patches.
Source: Decrypt

This article is for informational purposes only and does not constitute financial advice.

SourceRead the full article on Decrypt
Read full article

Always late to trends?

Join for the latest news, insights & more.

Disclaimer: Bytewit is an independent media outlet that delivers news, research, and data.

© 2026 Bytewit. All Rights Reserved. This article is for informational purposes only.

Read Next

Most Read

⚖️
Top StoriesBearish
63

NY AG Seeks $36B From Kalshi Over Illegal Gambling

New York Attorney General Letitia James filed a petition seeking at least $36 billion in damages from prediction market Kalshi, accusing it of illegal gambling. The state alleges Kalshi violated multiple laws, including underage betting, and seeks immediate shutdown. This escalates a federal-state clash over event contracts.

70% confidence
Jul 31, 2026, 10:12 AM UTC · Decrypt
Coldcard Flaw Drains $38M in Bitcoin — AI Suspected | Bytewit