Coinkite released firmware 5.6.1 for Mk4 and Mk5 and version 1.5.1Q for the Q model on August 20, 2026. The reason: a seed-generation flaw introduced in March 2021 reduced entropy from 128 bits to roughly 40–72 bits, making wallets brute-forceable without physical access to the devices. The tally, according to Galaxy Research, exceeds 1,778 BTC — over $130 million at the time of the source's calculation.
- Firmware 5.6.1/1.5.1Q, released August 20, 2026, replaces the Yasmarang pseudo-random generator with SHA-256 Hash_DRBG and mandates user-supplied entropy.
- The bug dates to firmware 4.0.1 in March 2021: for over five years, some seeds were generated with entropy reduced to ~40–72 bits versus the expected 128 bits.
- Galaxy Research traced over 1,778 BTC stolen from approximately 4,585 addresses, with estimates reaching 7,300 addresses and a potential fourth wave.
- Existing seeds on vulnerable firmware cannot be repaired: they require fresh generation and immediate fund migration.
"We're treating this as a serious reminder of how the whole security model of a hardware wallet lives or dies on randomness"
— Charles Guillemet, Ledger CTO
The Bug Hidden in the Heart of the Generator
The problem lies in Coinkite's choice to rely on the Yasmarang pseudo-random generator instead of the hardware-backed true RNG for certain seed-creation operations. This decision, active since firmware 4.0.1 in March 2021, produced effective entropy of roughly 72 bits on Mk3 devices and as low as ~40 bits on some Mk4/Mk5 configurations.
The difference is staggering. With 128 bits of entropy, the number of possible combinations makes a brute-force attack impractical even with state-level compute resources. At 40–72 bits, the key space shrinks to dimensions attackable with advanced consumer hardware or cloud clusters. The consequence: attackers could reconstruct seeds offline, without ever touching the Coldcard devices physically.
The first documented attack was lightning-fast. On July 30, 2026, according to Galaxy Research on-chain analyses cited by Decrypt, 594 BTC — roughly $38 million — were drained from about 500 wallets in just 25 minutes, spread across blocks 960188 through 960191. Galaxy Research subsequently traced three main waves and dozens of smaller incidents.
The AI Hypothesis and the New Speed of Discovery
Coinkite and Galaxy Research have advanced a hypothesis that, if confirmed, would mark a turning point in the threat model for open-source firmware. According to the source, attackers may have used artificial intelligence tools to analyze historical versions of Coldcard firmware, publicly available on open-source repositories, and identify the weakness pattern in the Yasmarang implementation.
Rodolfo Novak, Coinkite CEO, explicitly linked the incident to the new reality of AI-assisted code review: "AI-assisted code review can now find latent bugs at a speed that is outpacing even the industry's most seasoned experts." The dossier contains no forensic evidence confirming actual AI use by the malicious operators: it remains a hypothesis motivated by the speed and precision of the attack.
Confirmed or not, the datum raises a question for the entire sector. Legacy open-source code — even code reviewed for years by human experts — can now be subjected to automated screening at industrial scale. The window between a bug's introduction and its malicious discovery shrinks in a non-linear fashion.
The August 20 Fix: What Changes and What Doesn't
Firmware 5.6.1 for Mk4/Mk5 and 1.5.1Q for Q introduces three significant architectural changes. First: the definitive abandonment of Yasmarang in favor of SHA-256 Hash_DRBG as the deterministic generator. Second: activation of checks on the true hardware entropy generator, with RNG state verification before every critical operation. Third: mandatory additional user-supplied entropy — at least 65 keystrokes, 50 dice rolls, or 128 coin flips — before every new seed generation.
The dossier also documents the introduction of pre-sign PSBT checks, USB stack hardening, Delta mode, and backup system improvements. These elements strengthen the device's overall attack surface but do not mitigate the fundamental problem: seeds generated with vulnerable firmware remain irreversibly compromised.
The source is explicit on this point. No patch can transform a 40–72-bit seed into a 128-bit one. The only countermeasure is complete regeneration with the new firmware and immediate transfer of funds to the new address.
Why It Matters
The dossier does not specify remedial measures for users who cannot update firmware or regenerate seeds. It also does not document the existence of an assigned CVE or related CISA or national CERT advisories. Recovery of the stolen funds appears remote: roughly 90% of the stolen BTC had not moved as of August 4, 2026, but the source does not update this figure beyond that date.
The attackers' identity remains unknown. A law-enforcement investigation is underway, according to sources, but no names have been made public as of writing. Coinkite has publicly acknowledged the gravity of the situation: "We know an apology doesn't return anyone's funds. We know we'll have to earn back our users' trust."
The incident shatters a long-held axiom in crypto culture: that the air gap — the absence of a network connection — constitutes a sufficient security guarantee. The lesson is different. Hardware wallet security depends on the complete chain: from the silicon of the entropy generator to the firmware that queries it, from code audit to the practice of periodic regeneration. A weak link at any point compromises the entire architecture.
FAQ
Are TAPSIGNER, OPENDIME, and SATSCARD devices affected?
According to the source, the cited products are not affected by the vulnerability. The bug specifically concerns Coldcard Mk3, Mk4, Mk5, and Q models with vulnerable firmware.
Can I simply update the firmware and keep my seed?
No. The dossier explicitly documents that existing seeds generated with vulnerable firmware are not repairable. Complete regeneration is required.
Is it proven that attackers used AI?
No. The source reports that Coinkite suggested this hypothesis and that Novak discussed it as an emerging paradigm. However, no forensic confirmation exists in the dossier.
Information is based on the cited source and current as of publication.
Sources
- https://cryptoadventure.com/coldcard-releases-security-firmware-after-130m-bitcoin-exploit/
- https://decrypt.co/376270/coldcard-new-security-after-bitcoin-exploit
- https://www.cbc.ca/news/world/bitcoin-coinkite-security-hack-9.7295582
- https://yellow.com/news/coinkite-coldcard-mk3-seeds-predictable
- https://www.binance.com/en/square/post/357016031817714
- https://cryptoadventure.com/
- https://cryptoadventure.com/brx-coin-to-launch-on-pancakeswap-august-9-with-500000-liquidity-and-100-locked-lp/
- https://cryptoadventure.com/coinsdo-to-exhibit-at-webx-2026-bringing-non-custodial-wallet-infrastructure-to-asias-largest-web3-conference/