InvestNot yet confirmed elsewhere1 publisher3 min readPublished
Coinkite now makes Coldcard owners roll dice, after $130M walked out of air-gapped wallets
A 2021 seed flaw cut entropy from 128 bits to about 40, so no attacker needed to touch the hardware. Every seed generated before July 2026 now has to be replaced.
The Investor · Invest desk

What happened
- Coinkite shipped firmware 5.6.1 and 1.5.1Q and told Coldcard Mk4, Mk5 and Q owners to upgrade after a seed-generation flaw.
- The flaw, present since 2021, cut entropy on some devices from 128 bits to roughly 40, making seeds guessable without touching the hardware.
- Galaxy Research's running count reached more than 1,778 BTC, about $112 million, by August 14, across three major waves and dozens of smaller incidents.
- New seeds now demand at least 65 key presses, 50 dice rolls or 128 coin flips from the user, mixed with the device's own randomness.
Why it matters
- cost The remediation lands on holders who were never touched: five years of seeds have to be regenerated and every balance moved on-chain, at their expense.
- constraint Physical isolation stops exfiltration and nothing else, so the air-gap pitch can no longer stand in for a claim about how the key was generated.
- precedent Vendor-only randomness becomes hard for any wallet maker to defend once a competitor has made dice and coin flips a condition of setup.
- exposure Every archived firmware release a vendor has ever published is now cheap to audit at scale, and one Bitcoin service has already stopped trading rather than keep pace.
Air-gapping protects a seed after it exists; it says nothing about how the seed was born. A wallet that never touches a network still publishes a public key the first time it receives coins, and if the private key behind it came from a pool of roughly 1.1 trillion candidates rather than 2^128, every step of the attack happens off the device [20][8]. Cutting entropy from 128 bits to about 40 shrinks the search space by a factor of around 3 x 10^26 [21]. The physical isolation held. The secret it was guarding did not [8].
The tempo of the first wave says the same thing. Roughly 500 wallets emptied in 25 minutes works out to 20 a minute [22], and those 594 BTC were about a third of everything eventually taken [27], which reads as a list being worked through rather than a search being run. Galaxy Research called the campaign deliberate and programmatic, possibly orchestrated with a large language model [5]. Coinkite has suggested the attackers used AI to read older releases of its open-source firmware [15]. Both readings point at the archive: nothing a vendor has ever published stops being readable, and a volunteer Bitcoin Red Team has already run AI agents over hundreds of Bitcoin projects and surfaced thousands of candidate bugs [18].
The new seed requirement is calibrated rather than decorative. A run of 128 fair coin flips carries 128 bits; 50 rolls of a six-sided die carries about 129 [23]. Either option reconstitutes the full target on its own, before the device mixes in whatever its own generator produced [9]. That is a vendor conceding it should not be the only source of randomness, and the price is a buyer sitting there flipping a coin 128 times. Coinkite also replaced the Yasmarang backup PRNG with SHA-256 Hash_DRBG and added checks for hardware RNG failure [10].
The larger bill is the migration. Anyone whose seed came from affected firmware between 2021 and July 2026 has to generate a new one and move the coins [11], which is about five years of devices [26]. The first Galaxy tally averaged roughly $19,300 per address [24], the shape of ordinary self-custody rather than a handful of whales. The total also keeps moving: about $18 million, or 16 percent, has been added since the August 14 count [25], and Coinkite says the investigation is still open while customers relocate funds [19]. Treat $130 million as a running figure [7].
The most useful item in the release is the fix nobody was owed. Coldcard now re-checks a partially signed transaction immediately before signing, closing a path where a compromised USB host could alter a transaction between the user's review and the signature; Coinkite describes that as theoretical and does not say it was used [12][13]. Three weeks of concentrated outside attention also produced changes to USB data handling, firmware validation, Delta Mode and backups [14][2]. The seed bug was the one found first, not the only one there. Ledger CTO Charles Guillemet, a competitor with an interest in saying it, told Decrypt that a hardware wallet's security model lives or dies on randomness [16]. The checkable part of that is narrower and more useful: user-supplied entropy is the one input a vendor cannot quietly get wrong.
What to watch
- Any evidence that the pre-signing transaction substitution path was actually used, which would turn Coinkite's "theoretical" bug into a second live one.
- Whether rival hardware wallet makers make user-added entropy mandatory rather than an advanced option.
- Whether the open investigation produces attribution or any recovered Bitcoin.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence62
- Adoption54
- Hype gap+14
- Incentives66
- Confidence58
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Coinkite released a security overhaul for its Coldcard Bitcoin hardware wallets after a seed-generation flaw allowed attackers to steal more than $100 million in Bitcoin, and in a blog post on Thursday urged Coldcard Mk4, Mk5 and Q users to upgrade to firmware 5.6.1 or 1.5.1Q.
- [2]
The release followed a three-week review of Coldcard's systems that included outside security researchers and AI models including Kimi.
- [3]
In July, attackers began draining Bitcoin from air-gapped Coldcard wallets after exploiting a firmware flaw dating to 2021 that generated some wallet seeds with too little randomness, making private keys easier to guess.
- [4]
The first attack drained 594 BTC, worth about $38 million, from roughly 500 wallets in 25 minutes.
- [5]
By early August, Galaxy Research had tracked roughly $88.6 million stolen across 4,585 addresses and said the attacks appeared deliberate, programmatic, and potentially orchestrated using a large language model.
- [6]
By August 14, Galaxy Research said attackers had stolen more than 1,778 BTC, worth roughly $112 million at the time, across three major attack waves and dozens of smaller incidents.
- [7]
The Coldcard exploit has now resulted in roughly $130 million in stolen Bitcoin.
- [8]
On some affected devices the flaw reduced security from 128 bits of entropy to roughly 40 bits, making wallet seeds easier for attackers to guess without physical access to the device.
- [9]
Coldcard now requires users to add randomness when generating a wallet seed using at least 65 key presses, 50 dice rolls, or 128 coin flips, which the device combines with its own randomness.
- [10]
Coinkite replaced its Yasmarang backup pseudo-random number generator with SHA-256 Hash_DRBG and added checks intended to catch failures in the hardware random number generator.
- [11]
Users who may have generated seeds on affected firmware versions between 2021 and July 2026 must create a new seed using updated firmware and move their Bitcoin, the company said.
- [12]
Coldcard now checks a partially signed Bitcoin transaction immediately before signing it, and stops signing and displays a warning if the transaction changed; previously a compromised computer connected over USB could theoretically alter a transaction after the user reviewed it but before signing.
- [13]
Coinkite described the pre-signing transaction substitution issue as theoretical and did not say it had been exploited.
- [14]
Coinkite said it fixed issues involving transaction signing, USB data handling, firmware validation, Delta Mode, and wallet backups.
- [15]
Coinkite suggested the attackers may have used AI to examine older versions of its open-source firmware and uncover the flaw.
- [16]
Ledger CTO Charles Guillemet told Decrypt: "We're treating this as a serious reminder of how the whole security model of a hardware wallet lives or dies on randomness."
- [17]
Earlier this month, swap service Boltz suspended operations after saying AI-assisted attackers were finding bugs faster than its developers could fix them.
- [18]
A volunteer Bitcoin Red Team used AI agents to identify thousands of potential vulnerabilities across hundreds of Bitcoin projects.
- [19]
Coinkite said the investigation into the thefts remains ongoing as affected customers continue moving funds to new wallets.
- [20]
Forty bits of entropy corresponds to about 1.1 trillion candidate seeds.
- [21]
Falling from 128 bits to about 40 bits shrinks the seed search space by a factor of 2^88, roughly 3 x 10^26.
- [22]
The first wave emptied about 20 wallets per minute.
- [23]
The mandatory entropy options are each sized at roughly 128 bits: 128 fair coin flips give 128 bits, and 50 rolls of a six-sided die give about 129 bits.
- [24]
Galaxy's early-August tally averages about $19,300 stolen per affected address.
- [25]
The loss estimate has grown by about $18 million, or roughly 16 percent, since the August 14 figure.
- [26]
The affected seed-generation window spans about five years, from 2021 to July 2026.
- [27]
The 594 BTC taken in the first 25 minutes was about a third of the 1,778 BTC counted by August 14.
Sources
1 independent publisher whose own reporting we read for this story.
- decrypt.coColdcard Adds New Security Measures After $130 Million Bitcoin Exploit
1 article · August 21, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Bitcoin Custody IncidentsFollow
- AI-Assisted Vulnerability DiscoveryFollow
- Hardware Wallet SecurityFollow
- Firmware Patching and Forced Key RotationFollow
- Cryptographic Entropy FailuresFollow