A total of 1,778 Bitcoin worth hundreds of millions of dollars vanished without a trace. The vulnerability that drained the funds of thousands of users did not stem from physical attacks, but from a weakness in the Coldcard hardware wallet’s seed generation system that has existed since 2021.
Coinkite has finally released emergency firmware update version 5.6.1 for the Mk4 and Mk5 models, as well as version 1.5.1Q. This code patching step was taken following a three-week marathon security audit. They collaborated with external researchers and utilized the Kimi AI model to uncover the root cause behind this series of massive hacks.
The weak point was hidden deep within their legacy open-source code. The initial seed generation system turned out to produce only about 40 bits of entropy, far below the secure standard of 128 bits. As a result, private keys became vulnerable to remote guessing without the need for attackers to touch the victims’ devices at all.
Sweeping 500 Wallets in 25 Minutes
The impact of this vulnerability was costly. The first attack broke out in July 2026, sweeping 594 BTC worth approximately $38 million from 500 wallets in just 25 minutes. The loss figures continued to balloon after that initial incident.
The latest data from Galaxy Research as of August 14 recorded that at least 1,778 BTC, equivalent to $112 million, vanished from 4,585 wallet addresses. This breach was executed through three major waves of attacks and dozens of additional incidents. The total value of overall losses has now surpassed $130 million. Coinkite strongly suspects that hackers used AI to dissect legacy firmware code to find this disastrous vulnerability.
To close the security loophole, the latest firmware update no longer tolerates automated systems. Users generating a new seed are required to input manual entropy. The requirements are strict: a minimum of 65 button presses on the device, 50 actual dice rolls, or 128 physical coin tosses.
The Most Expensive Test of Hardware Wallet Cryptography
The behind-the-scenes security system has also been completely overhauled. The Yasmarang PRNG algorithm was discarded and replaced with the SHA-256 Hash_DRBG standard. Devices now inspect PSBT transactions just before final signing to block transaction modification vulnerability via USB connections.
Charles Guillemet, Chief Technology Officer at Ledger, highlighted this incident as a reminder for the industry. “Cryptography is hard, and implementing it securely is even harder - the Coldcard incident made that visible in the most expensive way,” he said.
All Coldcard users who generated wallet seeds between 2021 and July 2026 are required to immediately generate new seeds using the updated firmware and move their entire Bitcoin balance. Currently, law enforcement is still hunting for the perpetrators behind the attack worth hundreds of millions of dollars, while Coinkite has stated it is ready to assist its customers during the migration process.
Reported from Decrypt.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




