In a shocking turn of events, Coinkite, a leading manufacturer of Bitcoin hardware wallets, has released a critical firmware update to address a vulnerability affecting its Coldcard devices. The company’s quick action comes after a hack that has reportedly resulted in the theft of over a thousand bitcoins, with an estimated value of over $70 million in the past 24 hours.
The vulnerability, which was present in firmware versions 4.0.1 to 4.1.9, primarily impacted Coldcard MK3 devices. Users who generated 12- or 24-word seeds without using the dice roll feature or a BIP 39 extra passphrase are at risk. Coinkite has advised these users to update their firmware and move their funds to new wallets immediately to secure their assets.
The Severity of the Breach
Industry experts believe that artificial intelligence (AI) may have played a significant role in the breach. The specific line of code in the firmware that generated secure private keys was exploited, leading to the creation of weak passwords. This vulnerability was apparently identified and exploited at a speed that outpaced even the most seasoned cybersecurity experts.
Coinkite’s advisory, updated on July 31, 2026, recommends that users of MK3, MK4, and MK5 devices, including the Coldcard Q, upgrade their firmware to the latest versions. For MK4 and MK5 users, the update should be to version 5.6.0 or later, while Q users need to update to version 1.5.0Q or later. MK3 users should update to version 4.2.0 or later.
Multisignature Wallets at Risk
Peter Todd, a core contributor and cybersecurity engineer, highlighted a specific risk for multisignature wallets. In a 2-of-3 setup where two Coldcards are used, if the multisig script is revealed, attackers could use the compromised keys to steal funds. Todd suggested that users can mitigate this risk by using MARA mining pool’s private mempool mining service, Slipstream, which keeps transactions secret until they are in a block.
Beyond the Immediate Crisis
NVK, one of the co-founders of Coldcard, acknowledged the severity of the situation and committed to working with affected users on police reports, insurance claims, and investigations. He also emphasized that the incident underscores a broader shift in the tech landscape, where AI is changing the dynamics of cybersecurity.
“AI-assisted code review can now find latent bugs at a speed that outpaces even the most seasoned experts,” NVK wrote in a post on X. “We believe this is a sober reality of the new AI paradigm, and all developers should assume their code is being read by attackers and defenders alike.”
The Future of Wallet Security
Industry experts gathered in a long X Spaces public call to discuss the implications of the breach. The consensus is that other wallet providers will likely face increased scrutiny, and especially open-source projects that generate private key material will be thoroughly tested. The development of AI models optimized for cybersecurity is accelerating this process, and companies will need to adapt quickly to stay ahead.
Future high-sovereignty wallets, whether for retail or corporate use, are likely to rely on multi-vendor, multi-key setups. User-generated entropy, such as dice rolls, will become a standard practice to add an extra layer of security. Additionally, the concept of covenants, a soft fork that could introduce smart contract capabilities to Bitcoin, is gaining traction as a potential solution to strengthen the self-custody industry.
Ultimately, the industry will emerge from this crisis with more robust security measures and a deeper understanding of the evolving threat landscape. The lessons learned from this hack will likely lead to a more secure and resilient self-custody ecosystem.
