Coldcard Firmware Flaw Enables AI-Driven Heist — Over 1,300 BTC (~$89M) Stolen

iconChainGPT
Share
AI summary iconSummary
BTC news today reveals a major breach involving Coldcard hardware wallets, with over 1,300 BTC (~$89M) stolen. Attackers exploited a firmware flaw from a March 2021 update, reducing key strength and enabling private key reconstruction. Galaxy Research tracks three waves across 4,585 addresses, with a fourth possible. Coinkite suspects AI was used to find the flaw. Users are urged to check for BTC update advisories and secure funds on affected devices until a patch is released.

Morning Minute — Tyler Warner (opinions my own; not necessarily Decrypt’s). GM! Top story today: Coldcard, a widely respected hardware wallet for serious Bitcoin holders, is at the center of one of the largest self-custody thefts in crypto history. What happened - Attackers have been systematically draining Bitcoin from Coldcard Mk3 devices without ever touching the physical units. This is not phishing — it’s a firmware vulnerability. - A March 2021 Coldcard firmware update introduced a software fallback for seed generation that bypassed the device’s hardware random-number generator. That collapse in entropy reportedly reduced key strength from the intended 128 bits to roughly 40 bits, making seeds guessable. - Because private keys could be reconstructed from the weakened entropy, coins stored offline — even in a safety deposit box — were swept. One Canadian victim lost 18.25 BTC and wrote that the hardest part was that he “did everything right.” Scale and timeline - The thefts began last week and escalated rapidly. What started as an estimated $38 million loss climbed as researchers traced more activity. - Galaxy Research now reports roughly 1,367 BTC stolen (about $88.6 million) across 4,585 addresses, identified in three waves of sweeps. They flagged a new wave on Saturday. - Galaxy warns the exploit appears ongoing and expects that every vulnerable device will ultimately be emptied unless action is taken. The firm has handed roughly 600 suspected attacker addresses to federal investigators. - Researchers estimate a potential fourth wave could push losses toward $114 million. They also note some of the newest sweeps may be avoidable by front-running transaction settlements in the mempool. AI’s role — and the wider implications - Coinkite, Coldcard’s manufacturer, said it must assume an attacker used AI to comb the open-source firmware for flaws. Coinkite’s own AI-assisted code review weeks earlier didn’t catch this bug. - Alex Thorn, head of research at Galaxy, described the sweep behavior as programmatic and “probably orchestrated with a large language model.” - Observers point out a worrying pattern: in a short span, AI has been linked to cracking cryptographic candidates, sandbox escapes, and now large-scale wallet drains. For many in crypto, that raises hard questions about how AI tools are changing offensive and defensive capabilities — and how they threaten the core promise of self-custody. What users should know (and do) - If you own a Coldcard Mk3 or any device potentially affected, check Coinkite’s official channels for guidance and firmware advisories before taking action. - Treat funds on potentially vulnerable devices as at-risk until the company provides a clear patch or migration path. - Consider moving coins to secure, verified solutions only after confirming updates and following manufacturer instructions — and if uncertain, seek expert help. This story is developing. I’ll keep tracking updates as investigators and the vendor respond.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.