Article may be outdated

This article is 14 days old. Some details may have changed since publication.

CoinDesk·4 min read·medium

Coldcard ships firmware after $114 million bitcoin theft; says AI helped catch more bugs

S
Shaurya Malwa
Coldcard ships firmware after $114 million bitcoin theft; says AI helped catch more bugs
AI Summary

Coldcard has released a firmware update following a $114 million bitcoin theft caused by a randomness generation flaw. The company utilized AI-assisted code reviews to identify and patch vulnerabilities, while mandating that users generate new seeds using physical randomness.

Why it matters

This incident highlights the critical security risks in hardware wallets and the growing role of AI in auditing complex cryptographic systems.

Dive DeeperCreate a free account to unlock

The company said the review behind it was AI-assisted, naming Kimi and other frontier models among the tools used to examine not just the faulty randomness code but the whole system.

That review found problems unrelated to the original bug in the way transactions are approved, how data is handled over USB and how firmware updates are validated.

Installing the update does not make an existing compromised wallet safe. Anyone whose seed, or the master key that controls a wallet's coins, was created on affected firmware between 2021 and July 2026 still has to generate a new one and move their money across.

New seeds now work differently. Every one requires the owner to supply the randomness by hand, either 65 key presses at unpredictable intervals, 50 rolls of a six-sided die, or 128 coin flips.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologycryptobusiness

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in