Hardware wallet maker Coinkite has shipped emergency firmware for its Coldcard devices following what researchers are calling the largest hardware wallet exploit in crypto's history. Attackers drained roughly 1,816 BTC — north of $116 million — from more than 5,200 addresses by exploiting a firmware flaw that traced back five years to a March 2021 release.
The bug was a build configuration error that caused affected devices to generate wallet seeds using a weak software-based random number generator instead of the device's dedicated hardware entropy source. According to research published by TRM Labs, that flaw collapsed the effective strength of affected keys from a designed 128 bits down to as little as 40 bits on the oldest devices — weak enough to brute-force with modern computing power, and without ever requiring physical access to the wallet itself. Attackers moved fast once the weakness was found: in the first wave alone, 1,082 BTC was pulled from 1,196 addresses in roughly 41 minutes.
Manual Entropy Now Required for Every New Seed
Coinkite's fix, which shipped July 31, closes the loophole by taking seed randomness out of the software's hands entirely. Every new Coldcard seed now requires the owner to physically supply the entropy: 65 key presses at unpredictable intervals, 50 rolls of a six-sided die, or 128 coin flips. Anyone who generated a seed on a Coldcard between March 2021 and the July 31 patch should treat that seed as potentially compromised and migrate funds to a freshly generated one — a population of affected users that, given the flaw's five-year window, is likely far larger than the roughly 5,200 addresses actually drained so far.
Part of a Bigger Reckoning Over AI-Assisted Auditing
The Coldcard incident has become a reference point for a broader push to harden Bitcoin's software stack using AI-assisted code review. A volunteer effort often referred to as Bitcoin's "red team" — a group of roughly 25 developers — has now scanned 501 projects across the ecosystem looking for similar classes of bugs, building directly on lessons from the Coldcard case. That work follows the same trajectory as the wider volunteer effort to AI-proof Bitcoin software after the exploit, which was already underway before the scale of the Coldcard flaw became fully clear. One notable finding from that scanning effort: bugs turned up by AI tools built in China were catching classes of vulnerabilities that some Western AI tools reportedly weren't configured to look for, a gap researchers say has real implications for how the industry vets its own supply chain of hardware and software.
Related: Volunteer 'Red Team' Races to AI-Proof Bitcoin Software After $130M Hack
For Coldcard users specifically, the message from both the company and outside researchers is unambiguous — check when your seed was generated, and if it falls in the affected window, don't wait to migrate.