
Coinkite Releases Fixed Firmware After Coldcard Bug; AI Likely Involved In The Breach
Bitcoin Magazine Coinkite Releases Fixed Firmware After Coldcard Bug; AI Likely Involved In The Breach Over a thousand bitcoins are believed to have been stolen so far in a hack that started to be discussed on social...
Bitcoin 1 Minute
Here is the latest from the digital-asset markets: Bitcoin Magazine Coinkite Releases Fixed Firmware After Coldcard Bug; AI Likely Involved In The Breach Over a thousand bitcoins are believed to have been stolen so far in a hack that started to be discussed on social media in the afternoon of July 30th. Coinkite, one of the most reputable hardware wallet manufacturers, was revealed to have a critical bug in the way it generated secure private keys for its Bitcoin hardware wallets. Industry experts believe AI was used in the breach.
Coldcard MK3 devices with firmware version 4. 1 (March 2021) through 4. 9 are the worst affected.
Market Dynamics
12- or 24-word seeds generated by the device that did not include user-generated dice rolls or a BIP 39 extra passphrase are vulnerable. Users who fit this category, who have bitcoins in an MK3 Coldcard and did not use the dice roll feature for extra entropy or the extra passphrase, should consider themselves at risk and move their coins as soon as possible from the wallets. Bitcoin Magazine technical writer Shinobi has published a guide on the topic, and Coinkite has also published a guide and advisory.
The vulnerability was a specific line of code in the firmware, a low-level software codebase that controls the hardware. This firmware appears to be upgradable. The Coinkite advisory was updated this morning, advising users to upgrade device firmware for all three chips, MK3, MK4 and MK5 devices, including the Coldcard Q:“Updated July 31, 2026 at 9:33 a.
EDT: Fixed firmware is now available. Mk4 and Mk5 users must update to version 5. Q users must update to version 1.
Market Impact
For Mk3, update to version 4. ” Coinkite also explained in their advisory that updating the firmware does not mean that the private and public keys generated by the vulnerable firmware before it are now secure; those keys remain vulnerable as they were effectively created with a weak password. After the firmware is updated, a new wallet needs to be created, and the funds need to be sent onchain to the new addresses to secure the funds.
Coinkite wrote:“Updating the firmware does not change or repair an existing seed. If your seed was generated before the fixed firmware version for your model, follow the migration guidance below unless the independent dice-entropy exception applies to you. ” Some Multisignature Wallets May Be At Risk Peter Todd, Core contributor and cybersecurity engineer, today addressed specific edge cases for multi-signature wallets that use a threshold of Coldcards to secure funds.
“Example case: you have a 2-of-3, with 2 Cold Cards, and a 3rd uncompromised device. If you move your funds, the moment your script is revealed for the first time – previously hidden behind the address hash – the attacker now knows enough to use the compromised 2 cold card keys to steal your funds. ” The transaction that reveals the multisig script might be unconfirmed, giving hackers enough time to create a competing transaction with a higher fee.
This shift continues to shape the digital-asset landscape, with analysts examining its near-term effects.




