Coinkite, the Canadian company behind Coldcard hardware wallets, has released new firmware after a randomness flaw enabled attackers to steal more than $114 million in bitcoin from affected users. The update addresses multiple security issues uncovered during an AI-assisted review, though installing it does not make compromised wallets safe—affected users must still generate new seeds and migrate their funds.

Market Context

The Coldcard breach represents one of the largest single incidents affecting hardware wallet holders in recent memory, striking at a critical trust point in bitcoin self-custody. The theft occurs amid heightened scrutiny across the crypto security ecosystem, where multiple major players including exchanges like Coinbase, Block, BitGo and Blockstream have signed open letters requesting AI labs provide early model access to open-source security researchers.

Analysis

The underlying vulnerability stemmed from a flawed random number generator algorithm called Yasmarang that Coldcard devices used when creating wallet seeds between 2021 and July 2026. Coinkite's post-incident review employed frontier AI models including Kimi to audit not just the randomness code but its entire system, uncovering additional problems in transaction approval logic, USB data handling and firmware validation procedures.

The company has replaced Yasmarang with a random number generator built on SHA-256, the same hashing function bitcoin itself uses. Beyond the core fix, Coldcard now re-checks transactions immediately before signing to prevent compromised computers at the USB port from altering payment details after user approval on screen. Signature modes that leave parts of transactions editable post-signing are now blocked by default.

The shift toward AI-assisted security auditing is gaining momentum across the bitcoin ecosystem. The voluntary Bitcoin Red Team, a collective of sixteen developers, filed 4,962 findings against 390 projects in its first 24 hours of operation, including 85 critical and 635 high-severity issues. Crypto exchange Bybit reported that AI-assisted auditing found high-severity flaws at three to five times the rate of manual review, helping block $700 million in suspicious withdrawals during the first half of this year.

Key Numbers

- $114 million: Total bitcoin stolen through the randomness flaw

- 2021-2026: Time period affected firmware was active

- 5,000+ findings: Issues filed by Bitcoin Red Team against crypto projects in 24 hours

- 85 critical severity issues found in initial AI-assisted review

- $700 million in suspicious withdrawals blocked by Bybit with AI assistance

- 3-5x: Rate at which AI finds high-severity flaws versus manual auditing

What to Watch

Coldcard owners using Mk4 and Mk5 devices should install firmware version 5.6.1 immediately, while Q model users need version 1.5.1Q—available only from Coinkite's official downloads page. Users whose seeds were generated on affected firmware must generate new seeds using physical randomness methods: either 65 key presses at unpredictable intervals, 50 rolls of a six-sided die, or 128 coin flips. Law enforcement investigations continue as Coindite assists authorities working to identify those responsible for the thefts.

The broader rollout of AI-assisted security reviews in crypto may set new standards for protocol audits, with BTCPay Server also disclosing vulnerabilities discovered through similar methods. A 3 BTC bounty remains active for the return of funds drained from BTCPay's Lightning nodes.