Bitcoin losses from Coldcard firmware vulnerability reach $70 million
A firmware flaw in Coldcard hardware wallets has resulted in the theft of approximately $70 million in bitcoin, highlighting the escalating security risks posed by artificial intelligence in code analysis.
A firmware vulnerability in Coldcard hardware wallets has led to the theft of 1,082.65 bitcoin, valued at roughly $70 million. Galaxy Research reported that 1,196 addresses were completely drained in a concentrated burst of transactions on July 30.
The stolen funds were moved between 01:10:20 and 01:51:26 UTC. Galaxy Research noted that the transaction pattern indicates a single attacker, though the transfers mimic legitimate user activity. This distinction is critical for market participants, as it means future exploits could target any Coldcard-generated address without leaving a unique forensic signature.
The emergency advisory from Coinkite followed multiple online reports from users discovering that their bitcoin was being drained. The crypto hardware maker initially warned that seeds generated on Coldcard Mk3 devices running firmware version 4.0.1 or later were compromised.
Coinkite subsequently expanded this advisory to include specific firmware versions for the Mk4, Mk5, and Coldcard Q models. The company released emergency firmware updates for all affected devices to patch the security flaw.
Coinkite chief executive Rodolfo Novak issued an apology and accepted complete responsibility for the failure. He acknowledged that the company's internal review process failed to identify the firmware bug before it could be exploited by malicious actors.
Novak also raised concerns about the role of artificial intelligence in the breach, describing the event as a sober reality of the new AI paradigm. He warned that AI-assisted code review allows attackers to identify and exploit latent bugs in public code faster than traditional human security experts.
Galaxy Research mapped the flow of the stolen assets using a pattern identified by engineers at Block and shared by Clay Garrett. The research firm emphasized that while the current blockchain pattern captures a single attacker, it does not capture the mechanics of the attack itself.
To mitigate further losses, Coinkite instructed users to install the updated firmware and generate a new cryptographic seed. The manufacturer also advised customers to test the new wallet with a minor transaction and retain their old backup until the transfer is fully verified.