Was AI Responsible for Finding the Coldcard Security Flaw?
en
ru
de
es
ar
Latest news
Video
Bitcoin
DeFi
NFT
Ethereum
Altcoins
Blockchain
Mining
Finance
Metaverse
Legal
Security
Analytics
Exchange
Other
GameFi
ICO
More...
Latest news
Video
Bitcoin
DeFi
NFT
Ethereum
Altcoins
Blockchain
Mining
Finance
Metaverse
Legal
Security
Analytics
Exchange
Other
GameFi
ICO
Latest news
Video
Bitcoin
DeFi
NFT
Ethereum
Altcoins
Blockchain
Mining
Finance
Metaverse
Legal
Security
Analytics
Exchange
Other
GameFi
ICO
Back to the list
Was AI Responsible for Finding the Coldcard Security Flaw?
news.bitcoin.com
2 h
A Coordinated Sweep Empties Hundreds of Wallets
The incident became public after roughly 594 $BTC, valued near $38 million at the time, moved from about 500 single-signature bitcoin addresses on July 30. When the news first broke, Bitcoin.com News noted that the transfers occurred within approximately 25 minutes and appeared to target wallets with a shared technical weakness.
Later blockchain reviews expanded the possible scale of the theft. Researchers estimated that between 1,082 and 1,196 addresses may have been affected during a period of about 41 minutes. A custom dashboard called Coldcard Sweep Watch subsequently placed the total at 1,128.4717 $BTC, worth about $71.1 million when bitcoin traded near $63,044.
Image source: Coldcard Sweep Watch dashboard. Screenshot taken at 8:30 a.m. Eastern time on August 1, 2026. Since this screenshot was taken, an hour later at 9:30 a.m., the estimate increased to 1,128.6633 $BTC.
Most of the funds were consolidated into an address holding hundreds of bitcoin, where a large portion remained largely stationary. The affected addresses were linked by one important detail: Their recovery seeds had been created on Coldcard hardware wallets manufactured by Canadian company Coinkite.
A recovery seed is a list of words that controls access to a cryptocurrency wallet. Anyone who can reconstruct or obtain that seed can usually move the wallet’s funds without possessing the physical device.
Coldcard Finds a Broken Randomness System
Coinkite issued an urgent advisory warning that certain seeds generated on Coldcard devices could be weak. Mk3 devices running firmware version 4.0.1, released around March 2021, and later versions were among those facing the greatest risk.
Further analysis widened the concern to seeds created on some Mk4, Mk5, and Q devices before Coinkite released emergency firmware fixes. Tapsigner, Opendime, and Satscard products were reportedly not affected because they use different software.
The flaw involved the process used to generate random data. Secure wallets depend on high-quality randomness so that their recovery seeds cannot be guessed. On the most seriously affected Mk3 devices, researchers estimated that the seed may have contained only about 40 bits of effective randomness instead of the intended 128 bits.
That difference is critical. A properly generated 128-bit seed is considered practically impossible to guess through brute force. A 40-bit seed offers dramatically fewer possibilities, allowing an attacker with enough computing power to test potential seeds offline and compare the resulting addresses with the public Bitcoin blockchain.
Some newer devices may have provided approximately 72 bits of effective randomness because secure hardware added another layer of unpredictable data. That would make the seeds harder to reconstruct, though still much weaker than intended.
One Configuration Error Survived for 5 Years
The problem began with a build-time configuration mistake involving two software functions that performed similar jobs. One function used the device’s hardware-based true random number generator, while the other relied on a weaker software process inherited from MicroPython.
Coinkite intended to disable the MicroPython option. However, a software check looked only at whether a configuration label had been defined, rather than whether its value had been set to zero. As a result, the finished firmware could silently select the weaker function.
Because the two functions had matching formats, the software continued to compile and run without producing an obvious error. The mistake entered the code around a 2021 software migration and remained in publicly available firmware for more than five years.
Updating a device now does not strengthen a seed that was generated under the faulty software. Affected users must create a completely new seed using corrected firmware or another secure device, then move their funds to addresses controlled by that new seed.
Image source: X
Users who added at least 50 independent dice rolls while creating their seed may have supplied enough extra randomness to avoid the weakness. A strong BIP-39 passphrase could also have made reconstruction more difficult, while wallets requiring signatures from several independent devices may have...