After $114 million theft, Coldcard fixes several flaws discovered with AI
Summarize this article with:

Canadian hardware wallet upgrades its security after theft exceeding $114 million. Coldcard releases new patched firmware version after analysis with multiple AI models. This study was not limited to the initial random number generator. It also looked at transactions, USB exchanges and updates. However, affected users must renew their master keys before any transfer of funds.

Illustration of Coldcard after a $114 million theft, with a hardware wallet, a hacker and an AI dedicated to security.

In brief

  • $114 million was stolen following a flaw affecting random generation.
  • Coldcard identified several other vulnerabilities through analysis conducted with Kimi and other AI models.
  • The Yasmarang-based backup generator has been replaced with a solution using SHA-256.
  • New seeds now require physical randomness, provided with keys, a die or a coin.
  • Affected users should generate a new key and transfer their funds, as updating alone does not secure a compromised wallet.

Coldcard fixes a flaw linked to randomness

A few weeks after the flaw was revealed, Coinkite, the Canadian company behind Coldcard, published a new firmware version. The analysis used Kimi and other models to examine the affected code. The work mainly focused on the random number generator, but it also covered the entire system. This approach identified several distinct issues.

The company discovered flaws in transaction approval, USB data management and update validation. These issues concern different stages of wallet operation. Their identification broadens the scope of the patch released after the theft.

Coinkite replaced the fallback random number generator. Yasmarang now leaves room for a solution based on SHA-256, the hash function used by Bitcoin. The new seeds also rely on a contribution of physical randomness provided by the user. This mechanism limits the risk linked to a generator software fault.

Start your crypto adventure with MEXC
This link uses an affiliate program

A new method for creating seeds

Updating is not enough to secure an already compromised wallet. Users whose recovery phrase or master key was created with affected firmware must generate a new key. This rule concerns versions affected from 2021 to July 2026. They must then transfer their funds to this new generation.

To create a new seed, the user must provide some randomness themselves. Coldcard offers three methods for doing this. He can press keys 65 times at unpredictable intervals, roll a six-sided die 50 times, or make 128 coin flips. The principle is based on physical results unpredictable by the software.

This development responds to the nature of the initial problem. The defect concerned the device responsible for producing the randomness necessary for the keys. A die or a piece therefore offers a source independent of the software mechanism. At the same time, the new firmware strengthens the control of transactions before their signature.

Coldcard strengthens control of transactions and USB port

Coldcard now verifies the transaction immediately before signing it. This check prevents a computer compromised via USB from modifying a payment after it is approved on screen. The device thus adds a control step at the sensitive moment. Users therefore have protection against modification after validation.

Electronic signature methods that allow certain parts of a transaction to be modified after signing are blocked by default. This restriction complements the payment processing changes. It reduces the possibility of modification between the displayed approval and the actual signature.

Coinkite requires users of Mk4 and Mk5 models to install version 5.6.1. Q model owners should install version 1.5.1Q. The company recommends obtaining these versions from its official page. It also published a status page listing patched versions and migration steps.

AI is taking a growing place in audits

Coldcard’s analysis comes as several players highlight the use of AI to find vulnerabilities. The BTCPay project recently fixed a vulnerability after an attack that drained Lightning nodes. He offered a bounty of up to 3 BTC for the return of funds and paid 0.42 BTC to the affected researchers. The project also recommends keeping funds offline.

Several companies, including Coinbase, Block, BitGo and Blockstream, signed an open letter on August 10. They ask AI laboratories to give open source researchers early access to their most powerful models. This initiative highlights the gap between the tools available to attackers and those accessible to researchers.

The Bitcoin Red Team also illustrates this evolution. This collective of sixteen developers identified 4,962 flaws on 390 projects during its first 24 hours, including 85 critical problems and 635 high severity ones. His report contributed to the BTCPay fix. For its part, Bybit said an AI-assisted audit detected certain vulnerabilities three to five times faster than manual checks and helped block $700 million in suspicious withdrawals.

The next step now involves migrating the affected devices and renewing the keys created with the affected versions. Coldcard will also need to support users during this transition, while the investigation into the thefts continues. The fixes, resulting in particular from an analysis reinforced by artificial intelligence, extend the protection to several components of the system, beyond the initial generator. Their effectiveness will therefore depend on the application of new versions and compliance with migration procedures.

Maximize your Tremplin.io experience with our ‘Read to Earn’ program! For every article you read, earn points and access exclusive rewards. Sign up now and start earning benefits.

Similar Posts