Coldcard Firmware Bug Fuels AI-Assisted Bitcoin Theft — More Than 1,300 BTC (~$89M) Drained

AI Market Summary
Reports of an ongoing Coldcard Mk3 firmware entropy flaw enabling remote seed reconstruction and the theft of ~1,367 BTC across thousands of addresses is a major negative for Bitcoin self-custody confidence. The incident highlights latent supply-chain/software risks in hardware wallets and may spur immediate user fund migrations, elevated on-chain activity, and heightened counterparty/security scrutiny. Mentions of AI-assisted exploitation amplify concerns about accelerating offensive capabilities.
Impact level
● High
Affected assets
BTC/USDT-0.03%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Morning Minute — Tyler Warner (opinions are my own; not necessarily Decrypt's). Coldcard, a hardware wallet long trusted by serious Bitcoin holders, is now tied to what appears to be one of the largest self-custody thefts on record. What happened Attackers have been siphoning Bitcoin from Coldcard Mk3 wallets without ever gaining physical access to the devices. Investigators say this is not a phishing campaign. The root cause is a firmware vulnerability. According to reports, a Coldcard firmware update released in March 2021 introduced a software fallback for seed generation that bypassed the device's hardware random number generator. That design change reduced entropy sharply, with effective key strength falling from the intended 128 bits to roughly 40 bits, making seeds far more guessable. With private keys reconstructable from weakened entropy, funds held in offline setups—including wallets stored in places like safety deposit boxes—could still be swept. One Canadian victim reported losing 18.25 BTC, saying the most painful part was that he "did everything right." Scale and timeline The thefts began last week and accelerated quickly. Initial estimates of around $38 million climbed as analysts identified additional activity. Galaxy Research now reports about 1,367 BTC stolen—roughly $88.6 million—spread across 4,585 addresses, executed in three distinct sweep waves. The firm flagged another wave on Saturday. Galaxy says the exploit appears to be ongoing and expects all vulnerable devices could eventually be drained if users don't act. The firm has provided roughly 600 suspected attacker addresses to federal investigators. Researchers estimate a potential fourth wave could raise total losses toward $114 million. They also note that some of the newest sweeps may be preventable by front-running transaction settlement in the mempool. AI's role—and why it matters Coinkite, the maker of Coldcard, said it must assume the attacker used AI to comb the open-source firmware for weaknesses. Coinkite added that its own AI-assisted code review conducted weeks earlier did not catch the bug. Alex Thorn, Galaxy's head of research, characterized the sweep behavior as programmatic and "probably orchestrated with a large language model." Market observers see a troubling pattern: over a short period, AI has been associated with cracking cryptographic candidates, enabling sandbox escapes, and now supporting large-scale wallet drains. For the crypto industry, that sharpens questions about how AI is shifting the balance between offense and defense—and what it means for the core promise of self-custody. What users should do Owners of Coldcard Mk3 devices—or any potentially affected units—should consult Coinkite's official channels for guidance and firmware advisories before taking action. Treat funds on any potentially vulnerable device as at risk until a clear patch or migration path is confirmed. Consider moving coins only after verifying updates and following manufacturer instructions. If you're unsure, seek expert help. This story is still developing. I'll continue to track updates as investigators and the vendor respond.