$38M in Bitcoin Drained by Coldcard Key Flaw Its Maker Thinks AI Found


The post $38M in Bitcoin Drained by Coldcard Key Flaw Its Maker Thinks AI Found appeared on BitcoinEthereumNews.com.

In brief Coinkite says a build error meant seeds on its Coldcard hardware wallets were drawn from a software fallback instead of the hardware generator. It believes an attacker used AI on its open-source code, and says its own AI review weeks earlier found nothing. Every current model is affected to some degree, and updating the firmware does not repair a seed already created. Coinkite believes an attacker used AI to find a flaw that has cost owners of its Coldcard hardware wallets tens of millions of dollars in Bitcoin, and says its own AI review of the same code weeks earlier turned up nothing.  The hardware wallet manufacturer published an advisory for its Mk3 and a technical breakdown on Thursday, after learning that seeds generated by its devices were far more guessable than intended. COLDCARD Mk3 Security Advisory If you generated a seed on a Mk3 after firmware 4.0.1, your funds may be at risk. Mk4, Q and Mk5 are not affected based on our early analysis. Read the advisory and migrate carefully:https://t.co/3vgPHOjMS7 — COLDCARD (@COLDCARDwallet) July 30, 2026 The losses to the flaw, which was exploited early Friday, are estimated at 594 BTC, around $38 million. Funds were drained from roughly 500 wallets inside 25 minutes, with 562 BTC since consolidated into a single address. Coinkite said it has to assume “someone used AI to review previous versions of our firmware” in order to uncover the flaw. The firm said it had run one of the best available models over its own code a few weeks earlier, and the model “did not find this bug or anything serious.” Attackers and defenders have the same tools, it wrote, but this time “it did not help us, and only helped the bad guys.” What went wrong  Coldcard’s firmware calls a…



Source link

Leave a Comment

Your email address will not be published. Required fields are marked *