A security flaw affecting several generations of Coldcard hardware wallets has left bitcoin users scrambling to secure their funds after attackers reportedly stole at least 594 BTC, worth roughly $38 million at current prices. The manufacturer, Canadian company Coinkite, has acknowledged the vulnerability and urged affected customers to migrate their funds using newly generated recovery seeds.
The issue affects recovery phrases, commonly known as seed words, that were created on specific Coldcard firmware versions. According to Coinkite, wallets generated on the Mk3 running firmware 4.0.1 or later, as well as certain Mk4, Q, and Mk5 devices before patched firmware was released, may have produced seed phrases with insufficient randomness. If attackers are able to predict those seed words, they can restore the wallet elsewhere and transfer the stored cryptocurrency.
Coinkite has released firmware updates to correct the problem, but the company warned that installing the update alone is not enough to protect existing wallets. Users whose recovery phrases were created using affected firmware must generate an entirely new seed phrase and transfer their bitcoin to a newly created wallet. The company has published migration instructions for customers it believes could be at risk.
The warning also extends beyond Coldcard devices themselves. Security engineers at Block, the company behind the Bitkey hardware wallet, noted that users remain vulnerable if they imported a recovery phrase originally created on an affected Coldcard into another wallet. Because the underlying seed remains unchanged, moving it to different hardware does not eliminate the risk. Several other wallet manufacturers, including Trezor, Blockstream, Foundation and Tangem, have similarly advised customers who previously migrated Coldcard recovery phrases to create new wallets with newly generated seeds.
Coinkite said it was unaware of the underlying problem until recently, describing it as a combination of subtle software bugs that reduced the randomness used during seed generation in certain firmware releases. The company believes an attacker was ultimately able to exploit the weakness by predicting recovery phrases and draining affected wallets.
While discussing how the flaw may have been discovered, Coinkite said it cannot rule out the possibility that artificial intelligence tools helped analyse its publicly available source code. The company stressed that this remains an assumption rather than a confirmed finding. According to Coinkite, it recently used an advanced AI model to review the same codebase, but the model did not identify the vulnerability before it was discovered.
The incident has renewed discussion within the Bitcoin community about the importance of protecting large cryptocurrency holdings with multisignature wallets, which require approval from multiple independent devices before funds can be moved. Security experts have urged affected users not to delay migrating vulnerable wallets, while emphasising that creating a new recovery phrase is the only reliable way to eliminate the risk associated with the compromised seed generation process. The investigation into the attacks remains ongoing.