cryptd.in

Alternative LinkedIn pour les talents crypto-compatibles

Coinkite Releases Fixed Firmware After Coldcard Bug; AI Likely Involved In The Breach

Bitcoin Magazine

Coinkite Releases Fixed Firmware After Coldcard Bug; AI Likely Involved In The Breach

Over a thousand bitcoins are believed to have been stolen so far in a hack that started to be discussed on social media in the afternoon of July 30th. Coinkite, one of the most reputable hardware wallet manufacturers, was revealed to have a critical bug in the way it generated secure private keys for its Bitcoin hardware wallets. Industry experts believe AI was used in the breach.

Coldcard MK3 devices with firmware version 4.0.1 (March 2021) through 4.1.9 are the worst affected. 12- or 24-word seeds generated by the device that did not include user-generated dice rolls or a BIP 39 extra passphrase are vulnerable. 

Users who fit this category, who have bitcoins in an MK3 Coldcard and did not use the dice roll feature for extra entropy or the extra passphrase, should consider themselves at risk and move their coins as soon as possible from the wallets. Bitcoin Magazine technical writer Shinobi has published a guide on the topic, and Coinkite has also published a guide and advisory

The vulnerability was a specific line of code in the firmware, a low-level software codebase that controls the hardware. This firmware appears to be upgradable. The Coinkite advisory was updated this morning, advising users to upgrade device firmware for all three chips, MK3, MK4 and MK5 devices, including the Coldcard Q:

“Updated July 31, 2026 at 9:33 a.m. EDT: Fixed firmware is now available. Mk4 and Mk5 users must update to version 5.6.0 or later. Q users must update to version 1.5.0Q or later. For Mk3, update to version 4.2.0 or later.”

Coinkite also explained in their advisory that updating the firmware does not mean that the private and public keys generated by the vulnerable firmware before it are now secure; those keys remain vulnerable as they were effectively created with a weak password. After the firmware is updated, a new wallet needs to be created, and the funds need to be sent onchain to the new addresses to secure the funds. Coinkite wrote:

“Updating the firmware does not change or repair an existing seed. If your seed was generated before the fixed firmware version for your model, follow the migration guidance below unless the independent dice-entropy exception applies to you.”

Some Multisignature Wallets May Be At Risk

Peter Todd, Core contributor and cybersecurity engineer, today addressed specific edge cases for multi-signature wallets that use a threshold of Coldcards to secure funds. “Example case: you have a 2-of-3, with 2 Cold Cards, and a 3rd uncompromised device. If you move your funds, the moment your script is revealed for the first time – previously hidden behind the address hash – the attacker now knows enough to use the compromised 2 cold card keys to steal your funds.”

The transaction that reveals the multisig script might be unconfirmed, giving hackers enough time to create a competing transaction with a higher fee. Fortunately, such cases have a solution: the MARA mining pool can help in this case with their private mempool mining service, Slipstream; “because they promise to keep your transaction – and thus pubkeys – secret until they’re already in a block. Dramatically reducing the ability of the attacker to steal the funds,” said Todd. He added that “If you’ve already reused addresses, this isn’t relevant, and you should just try to move your funds ASAP. But if you haven’t, MARA may be able to help.”

Beyond The Immediate Crisis

NVK, one of the co-founders of Coldcard, published a long post on X with an initial analysis beyond the basic security steps needed to secure funds. In it, he wrote that the company is “committed to working with affected users who want to pursue a police report, insurance claim, or their own investigation”, including “a written incident summary specific to your loss and any transaction data we can share”. 

Beyond the immediate crisis, NVK pointed to a broader tech shift as the hacking capabilities of AI begin to change previous cybersecurity dynamics and expectations. In the blog post he wrote: 

“To every other developer: we believe this is a sober reality of the new AI paradigm. AI-assisted code review can now find latent bugs at a speed that is outpacing even the industry’s most seasoned experts. If your firmware is open-source or has ever been public, assume it’s already being read by attackers and defenders alike.”

The hack and over 70 million dollars in estimated stolen funds in the past 24 hours are an effective bounty paid to hackers who are now likely auditing every wallet codebase available for vulnerabilities. While the Bitcoin and broader crypto industry has generally operated under the assumption that hackers will test their code, the development of AI models optimized for cybersecurity accelerates these processes. 

Industry experts gathered in a long X Spaces public call last night, discussing the topic for many hours. Beyond the immediate recommendations and answering questions to Bitcoin users throughout the long Spaces, analysis of what is likely to follow in the coming weeks was also discussed. Other wallet providers are likely to get probed, and especially open source projects which generate private key material will be tested. 

The X Spaces was not recorded, likely to preserve the privacy of everyone in the call; however, initial sentiment suggests companies will need to be auditing their code with the latest frontier models, as a matter of survival. The latest cybersecurity-oriented AI models by Anthropic, OpenAI, Moonshot’s Kimi K3 and others are already available to the public. Many companies in the Bitcoin industry already use these to test the integrity of the code, but some might not be, and the race to find vulnerabilities in wallet-facing code will certainly continue, especially in the following weeks.

Ultimately, today we grieve lost coins, and a state of introspection and careful review occurs. Beyond this now historic hack will be an open source self-custody industry and infrastructure that is likely to be orders of magnitude more secure, with very hard lessons learned. After all, every hacker with an AI agent is likely testing defenses now. 

Multi-vendor, Multi-key Wallets and Covenants

Future high sovereignty wallets, be it at the retail or corporate level, are likely to not depend on any single vendor. Multisignature wallets, when well done, can distribute vulnerability risks across different code bases, teams and hardware. 

User-generated entropy was also a major theme in the X Spaces discussed earlier, with dice roll-generated entropy brought up regularly as a solution. Coldcards, as well as other hardware wallets like Foundation Devices, guide users on how to add their own entropy properly; many dice need to be rolled, ideally north of a hundred individual rolls. Once done, however, dice rolls represent a non-software source of randomness for wallets that also separates users from the edge-case risks in software- or hardware-generated entropy.

Covenants a popular soft fork among a certain niche in the Bitcoin industry have also started to be brought up as further step to strengthen the self-custody industry. This upgrade to the Bitcoin consensus which might be hard fought if achieved at all, could give users important smart contract capabilities, such a wallet that can only send to a white list of addresses, something not possible in Bitcoin script today. 

This post Coinkite Releases Fixed Firmware After Coldcard Bug; AI Likely Involved In The Breach first appeared on Bitcoin Magazine and is written by Juan Galt.


Commentaires

Laisser un commentaire

Votre adresse e-mail ne sera pas publiée. Les champs obligatoires sont indiqués avec *

Derniers fils

Catégories populaires

Recherche sur le site web

Histoires populaires

Tags

#AlexeyPertsev (1) #BidenCryptoBan (1) #BidenElection (1) #BinanceVsCoinbase (1) #Bitcoin (456) #BitcoinETF (3) #BitcoinFondamentaux (1) #itcoinHandling (1) #BitcoinPrix (5) #BitcoinPriceLevel (1) #BitcoinPump (1) #BitcoinReserve (1) #BitcoinSurge (1) #BitcoinTop (1) #Bitfinex (1) #Bitwise (1) #BracebridgeCapital (1) #BRC20Tokens (1) #BTCacquisition (1) #BullishPrediction (1) #BullishSentiment (1) #ChineseMining (1) #CPIPreview (1) #CryptoAsset (2) #CryptoBattle (1) #CryptoBoom (1) #CryptoExpert (1) #CryptoInsights (1) #CryptoMania (1) #CryptoMarket (4) #CryptoPrediction (1) #CryptoPredictions (1) #CryptoRégulation (2) #CryptoTakeoff (1) #CryptoTiming (1) #CryptoTips (1) #CryptoTreasury (1) #CryptoIncertitude (1) #DerivativeJump (1) #Dogecoin (74) #DogecoinGains (1) #DogecoinVolume (1) #utchCourt (2) #ECommerce (1) #ElSalvadorBitcoin (1) #Ethereum (74) #EthereumPain (1) #EPrix de l'argent (1) #ExpertOpinion (1) #FedRateCut (1) #FiatMonnaie (1) #Fimpact financier (1) #FinancierConfidentialité (1) #FirmShutdown (1) #FrozenAccounts (1) 1TP5FondsIllicites (1) #InflationData (1) 1TP5Investissement (1) 1TP5Perte d'investissement (1) #JapaneseFirm (1) #Action juridique (1) #Impact juridique (1) #Législation (1) #LightningNetwork (1) #MAnalyse de marché (3) #MSurveillance du marché (1) #MPrévision du marché (1) #MPrédictions de marché (1) #MProjection du marché (1) #MMarketSupport (1) #MVolatilité du marché (1) #M Mariage (1) #MemeCoin (5) #MemeCoins (2) #MinerProfitabilité (1) #M Blanchiment d'argent (2) #MtGox (4) #Corée du NordCrypto (1) #NovogratzPrédiction (1) #PriceMilestone (1) #P PrixPrédiction (2) #PriceQuestion (1) #PriceSurge (1) #PrisonSentence (1) #QuantAnalysis (1) 1TP5Pression réglementaire (1) #SECAntiCrypto (1) #ShibaInu (6) #SocialBuzz (1) #TAnalyse technique (1) #Toncoin (3) #TornadoCash (3) #TornadoCashDev (1) #TornadoCashDeveloper (1) #UKCrypto (1) #UPotentiel (1) #USCongress (1) #WyomingLand (1) #XRPPrix (1) #XRPupswing (1)

Liens utiles

Liens que j'ai trouvés utiles et que j'ai voulu partager.