Coldcard ships firmware after $114 million bitcoin theft; says AI helped catch more bugs
Three weeks of review turned up problems unrelated to the flaw that cost users $114 million, but updating still does not make a compromised wallet safe.

Three weeks of review turned up problems unrelated to the flaw that cost users $114 million, but updating still does not make a compromised wallet safe.

Coinkite, the Canadian company behind the Coldcard hardware wallet, has released new firmware weeks after disclosing the flaw that let attackers drain more than $114 million from bitcoin holders.
The company said the review behind it was AI-assisted, naming Kimi and other frontier models among the tools used to examine not just the faulty randomness code but the whole system.
That review found problems unrelated to the original bug in the way transactions are approved, how data is handled over USB and how firmware updates are validated.
Installing the update does not make an existing compromised wallet safe. Anyone whose seed, or the master key that controls a wallet's coins, was created on affected firmware between 2021 and July 2026 still has to generate a new one and move their money across.
New seeds now work differently. Every one requires the owner to supply the randomness by hand, either 65 key presses at unpredictable intervals, 50 rolls of a six-sided die, or 128 coin flips.
Không có cửa hậu mã hóa, không có sự thỏa hiệp. Một nền tảng tài chính và xã hội phi tập trung dựa trên công nghệ blockchain mang lại quyền riêng tư và tự do cho người dùng.
© 2024 QQlink® Nhóm R&D. Mọi quyền được bảo lưu.
