Finst

Coldcard Releases Firmware After $114 Million Bitcoin Theft

The update is meant to patch a known vulnerability and add extra checks when signing transactions. Coinkite is advising Mk4, Mk5, and Q users to install the latest firmware.

Coldcard Releases Firmware After $114 Million Bitcoin Theft

Key Takeaways

  • Coldcard released new firmware after a hardware wallet bug helped lead to a $114 million bitcoin theft.
  • The update replaces the random number generator, adds extra transaction checks, and blocks certain signature modes by default.
  • Coinkite is asking users of Mk4, Mk5, and Q models to install the latest versions through official channels.

Coldcard has released new firmware after a bug in the hardware wallet had contributed to a bitcoin theft of $114 million (€97.6 million). Coinkite says the update not only addresses the known vulnerability, but also adds extra checks to reduce mistakes when signing transactions.

What Changed

The main change is in the way Coldcard creates random data for a seed. Where the device previously used a backup random number generator based on Yasmarang, that has now been replaced with a variant that runs on SHA-256, the same hash function also used in Bitcoin. According to Coinkite, the device now checks a transaction again right before signing, so a compromised computer on the USB port can no longer change a payment after the owner has already approved it on the screen.

Signature modes that leave parts of a transaction open after signing are now also blocked by default. Coinkite is asking owners of the Mk4 and Mk5 models to install version 5.6.1 and users of the newer Q model to download 1.5.1Q through official channels. The company has also launched a public status page with information on which releases have been fixed and which migration steps are needed.

AI Is Playing a Bigger Role

Coldcard is now the fifth bitcoin or crypto company in three weeks to say that AI is playing a bigger role in security work. That fits into a broader shift in the industry, where more and more companies are using AI to spot bugs in code and firmware faster.

That trend is especially relevant for hardware wallets, because self-custody only stays safe if the software and the random number generator are truly reliable. The Coldcard case shows that a bug in a relatively small part can have major consequences for users who want to keep their crypto outside a central party. Other security incidents around wallets also show how broad that risk is; in an earlier random number bug in multiple wallets, weak seed phrases were directly exploited.

Why This Matters for Users

For European crypto users, this is especially relevant because hardware wallets are often seen as the standard for self-custody. The case shows that even a well-known crypto company with a strong reputation is not immune to firmware bugs. Coinkite says law enforcement is still investigating the theft and that the company remains available to cooperate.


Disclaimer: This content is for informational purposes only and does not constitute financial, investment, legal, or tax advice. The information provided may be incomplete, inaccurate, or outdated and should not be relied upon as such. Nothing on this website should be considered a recommendation to buy, sell, or hold any cryptocurrency. Investing in crypto-assets involves risk of loss.