Coinkite Releases Fixed Firmware After Coldcard Bug Linked to 1,000 BTC Theft

iconNS3
Share
AI summary iconSummary
BTC news today: Coinkite released updated firmware for Coldcard devices after a flaw in private-key generation led to the theft of over 1,000 BTC. The bug impacted Coldcard MK3 users who created 12- or 24-word seeds on firmware 4.0.1–4.1.9 without using dice rolls or a BIP 39 extra passphrase. Fixed firmware is now available for Mk3, Mk4, Mk5, and Coldcard Q. Coinkite warned that updating firmware does not fix existing seeds—users must create new wallets and transfer funds to new addresses. BTC update required for affected devices.

Key Point

Coinkite released fixed firmware for Coldcard devices after a critical private-key generation bug affected Bitcoin hardware wallets. Coinkite said the worst affected users are Coldcard MK3 users whose 12- or 24-word seeds were generated on firmware 4.0.1 through 4.1.9 without dice rolls or a BIP 39 extra passphrase. Coinkite said fixed firmware is now available for Mk3, Mk4, Mk5, and Coldcard Q devices. Coinkite said updating firmware does not repair existing seeds, so affected users need to create a new wallet and send funds onchain to new addresses. Industry experts believe AI was used in the breach.

Why it matters: Weak seed generation can directly threaten self-custody security because attackers may be able to reconstruct keys before users migrate funds.

Market Sentiment

Bearish, Stress-on, Tech-driven, De-risking.

Reason: More than a thousand bitcoins are believed to have been stolen, which points to direct self-custody risk.

Similar Past Cases

In 2022, the Ronin Bridge hack totaled over $600 million, and Sky Mavis raised $150 million to reimburse affected users. (Axios) The difference is that the Ronin case involved bridge infrastructure, while the Coinkite case centers on hardware-wallet seed generation.

Ripple Effect

Weak key generation can spread through the self-custody market by forcing users to rotate wallets and reassess vendor code. If follow-up advisories widen the affected set, then wallet migration pressure may rise across similar self-custody products. If migrations happen through public transactions that reveal multisig scripts, then attackers may gain a time window to compete for funds.

Opportunities & Risks

Opportunities: When fixed firmware is installed and a new wallet is created, then controlled migration to new addresses is a potential risk-reduction signal. If private transaction handling is available for sensitive multisig moves, then using private routing can reduce exposure during migration.

Risks: If users keep seeds generated by vulnerable firmware, then firmware updates alone do not remove key risk. If multisig scripts are revealed before confirmation, then delaying public exposure or using private routing can reduce front-run risk.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.