Coldcard security flaw: AI-linked key theft totals 1,128 BTC, Coinkite warns

A major Coldcard security flaw has been linked to a large-scale Bitcoin theft. Coinkite, the maker of Coldcard hardware wallets, says the bug may have been discovered with AI-assisted code review, but it has not provided proof that AI was responsible. Reportedly affected are recovery seeds generated on certain Coldcard models (especially Mk3 with firmware 4.0.1 and later variants of Mk3, plus some Mk4/Mk5/Q devices before emergency firmware fixes). The issue weakened the wallet’s entropy during seed generation, potentially reducing effective randomness from the intended 128 bits to about 40 bits (some newer devices closer to ~72 bits). That lower randomness makes offline seed reconstruction more feasible, enabling attackers to derive private keys and sweep funds. The theft became public when hundreds of single-signature Bitcoin addresses were drained in a short window. Totals tracked by “Coldcard Sweep Watch” reached about 1,128.4717 BTC (roughly $71.1M at ~$63,044/BTC), later updating slightly higher to 1,128.6633 BTC. Most funds were consolidated into a large holding address. Coinkite’s CEO Rodolfo Novak apologized and stated users with affected seeds must install corrected firmware, create new seeds, and move funds to addresses controlled by the new seed. The company also said users may reduce risk if they added at least 50 independent dice rolls during seed creation, used a strong BIP-39 passphrase, or relied on multisig. Overall, the Coldcard security flaw underscores that even open-source firmware can contain subtle build-time configuration errors that persist for years—while AI can lower the effort required to find such weaknesses.
Neutral
Impact on traders is likely neutral. Short-term: even though ~1,128 BTC is meaningful, the theft is hardware-wallet-specific and does not represent a systemic Bitcoin protocol failure. Similar incidents (e.g., past wallet-specific seed/entropy or signing bugs) typically trigger localized fear around custody, but the broader BTC market usually absorbs the shock unless large centralized holdings or core infrastructure are affected. Medium/long-term: the narrative about AI-assisted code review can increase scrutiny and audit activity across wallet vendors, potentially improving security standards over time. However, until investigations confirm attribution, uncertainty can keep pressure on hardware-wallet users (and create short-lived volatility in risk sentiment). Net: limited market reach (wallet maker and affected seed cohorts) suggests no sustained directional move for the whole crypto market, but it may mildly affect sentiment around self-custody and security tooling.