Skip to content

InvestNot yet confirmed elsewhere1 publisher3 min readPublished

Coinkite now makes Coldcard owners roll dice, after $130M walked out of air-gapped wallets

A 2021 seed flaw cut entropy from 128 bits to about 40, so no attacker needed to touch the hardware. Every seed generated before July 2026 now has to be replaced.

The Investor · Invest desk

How we use AISend a correction

Photograph accompanying Coinkite now makes Coldcard owners roll dice, after $130M walked out of air-gapped wallets
Photo: decrypt.co

What happened

  • Coinkite shipped firmware 5.6.1 and 1.5.1Q and told Coldcard Mk4, Mk5 and Q owners to upgrade after a seed-generation flaw.
  • The flaw, present since 2021, cut entropy on some devices from 128 bits to roughly 40, making seeds guessable without touching the hardware.
  • Galaxy Research's running count reached more than 1,778 BTC, about $112 million, by August 14, across three major waves and dozens of smaller incidents.
  • New seeds now demand at least 65 key presses, 50 dice rolls or 128 coin flips from the user, mixed with the device's own randomness.

Why it matters

  • cost The remediation lands on holders who were never touched: five years of seeds have to be regenerated and every balance moved on-chain, at their expense.
  • constraint Physical isolation stops exfiltration and nothing else, so the air-gap pitch can no longer stand in for a claim about how the key was generated.
  • precedent Vendor-only randomness becomes hard for any wallet maker to defend once a competitor has made dice and coin flips a condition of setup.
  • exposure Every archived firmware release a vendor has ever published is now cheap to audit at scale, and one Bitcoin service has already stopped trading rather than keep pace.

Air-gapping protects a seed after it exists; it says nothing about how the seed was born. A wallet that never touches a network still publishes a public key the first time it receives coins, and if the private key behind it came from a pool of roughly 1.1 trillion candidates rather than 2^128, every step of the attack happens off the device [20][8]. Cutting entropy from 128 bits to about 40 shrinks the search space by a factor of around 3 x 10^26 [21]. The physical isolation held. The secret it was guarding did not [8].

The tempo of the first wave says the same thing. Roughly 500 wallets emptied in 25 minutes works out to 20 a minute [22], and those 594 BTC were about a third of everything eventually taken [27], which reads as a list being worked through rather than a search being run. Galaxy Research called the campaign deliberate and programmatic, possibly orchestrated with a large language model [5]. Coinkite has suggested the attackers used AI to read older releases of its open-source firmware [15]. Both readings point at the archive: nothing a vendor has ever published stops being readable, and a volunteer Bitcoin Red Team has already run AI agents over hundreds of Bitcoin projects and surfaced thousands of candidate bugs [18].

The new seed requirement is calibrated rather than decorative. A run of 128 fair coin flips carries 128 bits; 50 rolls of a six-sided die carries about 129 [23]. Either option reconstitutes the full target on its own, before the device mixes in whatever its own generator produced [9]. That is a vendor conceding it should not be the only source of randomness, and the price is a buyer sitting there flipping a coin 128 times. Coinkite also replaced the Yasmarang backup PRNG with SHA-256 Hash_DRBG and added checks for hardware RNG failure [10].

The larger bill is the migration. Anyone whose seed came from affected firmware between 2021 and July 2026 has to generate a new one and move the coins [11], which is about five years of devices [26]. The first Galaxy tally averaged roughly $19,300 per address [24], the shape of ordinary self-custody rather than a handful of whales. The total also keeps moving: about $18 million, or 16 percent, has been added since the August 14 count [25], and Coinkite says the investigation is still open while customers relocate funds [19]. Treat $130 million as a running figure [7].

The most useful item in the release is the fix nobody was owed. Coldcard now re-checks a partially signed transaction immediately before signing, closing a path where a compromised USB host could alter a transaction between the user's review and the signature; Coinkite describes that as theoretical and does not say it was used [12][13]. Three weeks of concentrated outside attention also produced changes to USB data handling, firmware validation, Delta Mode and backups [14][2]. The seed bug was the one found first, not the only one there. Ledger CTO Charles Guillemet, a competitor with an interest in saying it, told Decrypt that a hardware wallet's security model lives or dies on randomness [16]. The checkable part of that is narrower and more useful: user-supplied entropy is the one input a vendor cannot quietly get wrong.

What to watch

  • Any evidence that the pre-signing transaction substitution path was actually used, which would turn Coinkite's "theoretical" bug into a second live one.
  • Whether rival hardware wallet makers make user-added entropy mandatory rather than an advanced option.
  • Whether the open investigation produces attribution or any recovered Bitcoin.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence62
Adoption54
Hype gap+14
Incentives66
Confidence58
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Coinkite released a security overhaul for its Coldcard Bitcoin hardware wallets after a seed-generation flaw allowed attackers to steal more than $100 million in Bitcoin, and in a blog post on Thursday urged Coldcard Mk4, Mk5 and Q users to upgrade to firmware 5.6.1 or 1.5.1Q.

    ReportedSupportedView cited source
  2. [2]

    The release followed a three-week review of Coldcard's systems that included outside security researchers and AI models including Kimi.

    ReportedSupportedView cited source
  3. [3]

    In July, attackers began draining Bitcoin from air-gapped Coldcard wallets after exploiting a firmware flaw dating to 2021 that generated some wallet seeds with too little randomness, making private keys easier to guess.

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. decrypt.co

    1 article · August 21, 2026

    Coldcard Adds New Security Measures After $130 Million Bitcoin Exploit

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Loading related stories