crypto for all
Join
A
A

After the $114 Million Theft, Coldcard Fixes Several Vulnerabilities Discovered With AI

15h05 ▪ 6 min read ▪ by Ghiles A.
Getting informed Cybersecurity
Summarize this article with:

The Canadian hardware wallet is evolving its security after a theft exceeding $114 million. Coldcard releases a new corrected firmware version after an analysis conducted with several AI models. This study was not limited to the initial random number generator. It also examined transactions, USB exchanges, and updates. Affected users must, however, renew their main keys before any fund transfers.

Illustration of Coldcard after a 4 million theft, featuring a hardware wallet, a hacker and AI focused on security.

In Brief

  • $114 million was stolen following a flaw affecting random generation.
  • Coldcard identified several other flaws thanks to an analysis conducted with Kimi and other AI models.
  • The backup generator based on Yasmarang has been replaced by a solution using SHA-256.
  • New seeds now require physical randomness, provided with keys, a die, or a coin.
  • Affected users must generate a new key and transfer their funds because the update alone does not secure a compromised wallet.

A few weeks after the flaw revelation, Coinkite, the Canadian company behind Coldcard, published a new firmware version. The analysis used Kimi and other models to examine the affected code. The work mainly focused on the random number generator but also covered the entire system. This approach allowed identifying several distinct issues.

The company discovered vulnerabilities in transaction approval, USB data management, and update validation. These issues concern different stages of the wallet’s operation. Their identification broadens the scope of the patch released after the theft.

Coinkite replaced the backup random number generator. Yasmarang now gives way to a solution based on SHA-256, the hashing function used by Bitcoin. New seeds also rely on physical randomness provided by the user. This mechanism limits the risk related to a software fault in the generator.

A new method to create seeds

The update is not enough to secure a wallet already compromised. Users whose recovery phrase or main key was created with affected firmware must generate a new key. This rule concerns affected versions from 2021 to July 2026. They must then transfer their funds to this new generation.

To create a new seed, the user must supply a part of the randomness themselves. Coldcard offers three methods to perform this operation. They can press keys 65 times at unpredictable intervals, roll a six-sided die 50 times, or flip a coin 128 times. The principle relies on physical results that are unpredictable by software.

This evolution addresses the nature of the initial problem. The fault concerned the device responsible for producing the randomness necessary for the keys. A die or a coin thus provides a source independent of the software mechanism. Simultaneously, the new firmware strengthens transaction control before signing.

Coldcard strengthens control of transactions and USB port

Coldcard now verifies the transaction immediately before signing it. This check prevents a computer compromised via USB from modifying a payment after its approval on the screen. The device thus adds a control step at the sensitive moment. Users therefore have protection against modification after validation.

By default, the system blocks electronic signing modes that allow modification of some parts of a transaction after signing. This restriction complements changes in payment processing. It reduces the possibilities of modification between displayed approval and actual signing.

Coinkite asks users of Mk4 and Mk5 models to install version 5.6.1. Holders of the Q model must install version 1.5.1Q. AI is playing an increasingly important role in audits. It also published a status page listing the fixed versions and migration steps.

AI takes an increasing place in audits

Coldcard’s analysis comes as several actors highlight the use of AI to search for vulnerabilities. The BTCPay project recently fixed a vulnerability after an attack emptied Lightning nodes. It offered a bounty of up to 3 BTC for fund recovery and paid 0.42 BTC to the involved researchers. The project also recommends keeping funds offline.

Several companies, including Coinbase, Block, BitGo, and Blockstream, signed an open letter on August 10. They ask AI labs to give open-source researchers early access to their most powerful models. This initiative highlights the gap between tools available to attackers and those accessible to researchers.

The Bitcoin Red Team also illustrates this evolution. This collective of sixteen developers identified 4,962 flaws on 390 projects during its first 24 hours, including 85 critical issues and 635 high-severity ones. Its report contributed to the BTCPay patch. Bybit indicated that an AI-assisted audit detected certain flaws three to five times faster than manual checks and helped block $700 million in suspicious withdrawals.

The next step now involves migrating affected devices and renewing keys created with the affected versions. Coldcard will also need to support users during this transition while the theft investigation continues. The patches, resulting notably from enhanced analysis by artificial intelligence, broaden protection to several system components beyond the initial generator. Their effectiveness will therefore depend on applying the new versions and adhering to migration procedures.

Maximize your Cointribune experience with our "Read to Earn" program! For every article you read, earn points and access exclusive rewards. Sign up now and start earning benefits.



Join the program
A
A
Ghiles A. avatar
Ghiles A.

Journaliste et rédacteur web passionné par l’univers des cryptomonnaies et des technologies Web3. J’y traite les dernières tendances et actualités afin de proposer un contenu de haute qualité à un large public du secteur.

DISCLAIMER

The views, thoughts, and opinions expressed in this article belong solely to the author, and should not be taken as investment advice. Do your own research before taking any investment decisions.