A three-week security audit uncovered several vulnerabilities unrelated to the flaw behind the $114 million bitcoin theft. However, Coinkite stressed that installing the latest firmware alone will not secure a wallet that has already been compromised.
Coinkite, the Canadian company that develops the Coldcard hardware wallet, has rolled out new firmware several weeks after disclosing the vulnerability that enabled attackers to drain more than $114 million worth of bitcoin.
The company said artificial intelligence assisted the latest security review. Kimi and other advanced AI models were used to inspect the original randomness vulnerability and evaluate the broader Coldcard system.
Researchers identified additional issues involving transaction authorization, USB data handling and firmware-update verification.
The firmware upgrade does not restore security to wallets that were already compromised. Users whose seed phrases, or master keys controlling their bitcoin, were generated using affected firmware between 2021 and July 2026 must create a fresh seed and transfer their funds.
The new seed-generation process requires users to contribute physical randomness. Owners can provide it through 65 unpredictable button presses, 50 rolls of a six-sided die or 128 coin flips.
Coinkite uses physical randomness because the results of dice rolls and coin flips cannot be predicted by software. The vulnerability responsible for the theft stemmed from the device’s automated method of generating randomness.
The company has also replaced the backup random-number generator, removing Yasmarang and adopting a SHA-256-based system. SHA-256 is the hashing algorithm used by Bitcoin.
Coldcard now performs another transaction check immediately before signing. The change is intended to stop a compromised computer connected through USB from modifying a transaction after the user has approved it on the device. Signature options that allow certain transaction details to remain editable after signing are now disabled by default.
Coinkite said authorities are continuing to investigate the thefts and identify those responsible. The company said it remains available to support the investigation.
Owners of Coldcard Mk4 and Mk5 devices should install firmware 5.6.1, while Q model owners should use version 1.5.1Q. Coinkite advised users to download the software only from its official downloads page. It has also launched a public status page showing which firmware releases contain fixes and what migration procedures affected users need to follow.
AI Takes a Bigger Role in Crypto Security
Coldcard is now the fifth bitcoin or crypto company in three weeks to publicly discuss how AI is changing the way security vulnerabilities are discovered and addressed.
BTCPay Server, an open-source platform that lets merchants process bitcoin payments independently, was targeted this month after attackers exploited a vulnerability involving users’ Lightning nodes. The project is offering a bounty of up to 3 BTC for recovered funds and has paid 0.42 BTC to researchers who discovered the flaw. It has also advised merchants to keep funds in cold storage and regularly transfer excess balances out of hot wallets, particularly as AI-driven security threats evolve.
On Aug. 10, dozens of Bitcoin companies, including Coinbase, Block, BitGo and Blockstream, signed an open letter urging AI developers to give open-source security researchers early access to their most capable models.
The Bitcoin Red Team has become one of the most visible initiatives in this area. The volunteer group, made up of 16 developers working across multiple time zones, reported 4,962 vulnerabilities across 390 projects within its first 24 hours. The findings included 85 critical and 635 high-severity issues, with its work also contributing to the research behind BTCPay Server’s recent patch.
Bybit, which lost approximately $1.46 billion in a February 2025 attack attributed to North Korea’s Lazarus Group, said AI-assisted audits identified high-severity vulnerabilities at three to five times the rate of manual reviews. The exchange also said AI helped stop roughly $700 million in suspicious withdrawals during the first half of the year.