$38M in Bitcoin Drained by Coldcard Key Flaw Its Maker Thinks AI Found
Coinkite says a flaw in Coldcard Mk3 firmware made generated seeds far more predictable than intended, leading to theft of about 594 BTC from roughly 500 wallets in under 25 minutes. It believes attackers may have used AI to spot the bug, after its own AI code review missed it weeks earlier. The issue came from two randomness functions with identical signatures: the build could silently use a MicroPython fallback instead of the hardware RNG because a preprocessor check tested only definition, not value. Mk3 seeds made after firmware 4.0.1 are at risk; Mk4, Q, and Mk5 are partially affected but strengthened by secure-element entropy. Coinkite released emergency firmware fixes, but old seeds remain weak and must be replaced on patched hardware. It recommends a strong BIP-39 passphrase, many dice rolls, or both, and says exposed users should move funds quickly.
