Around 594 BTC worth approximately $38 million was drained from some 500 Coldcard hardware wallets in just 25 minutes early Friday. Of the total stolen funds, 562 BTC has now been moved to a single address starting with bc1qnk, according to data from on-chain tracker @lookonchain on X.
This was no ordinary hack, but a machine-versus-machine battle won by the attacker.
Outsmarted by an Attacking AI
Coldcard manufacturer Coinkite believes the hacker used artificial intelligence (AI) to scour older versions of its open-source firmware and uncover the hidden flaw. Ironically, Coinkite admitted it had run one of the top AI models on the exact same code just weeks earlier - yet failed to catch the bug.
The bug stemmed from a function call used to gather random entropy. There were two implementations with identical signatures: Coinkite’s native hardware generator and a MicroPython software fallback. The issue arose when a preprocessor guard only checked whether a setting was defined without verifying its value. As a result, the system had been compiling with the software fallback without any warning ever since a code migration in March 2021.
This flaw reduced the effective search space for Mk3 device seeds to just around 40 bits, far below the expected 128-bit security standard.
Who Is Affected?
The vulnerability affects Mk3 devices, as well as Mk4, Q, and Mk5 models with varying levels of risk. The Mk4, Q, and Mk5 models are slightly safer because they still receive around 72 bits of additional entropy from their built-in secure elements. Other Coinkite products such as Tapsigner, Opendime, and Satscard are confirmed safe as they use a different codebase. Other wallet manufacturers like Trezor and Block (Square) also confirmed that their products were unaffected.
To address the issue, Coinkite released emergency hotfix version 5.6.0 for the Mk4 and Mk5, alongside version 1.5.0Q for Q devices. However, these updates only patch the system and cannot recover the lost assets.
Steps Users Must Take
A firmware update does not automatically strengthen seeds that were generated under older versions. Seeds generated by a compromised system remain weak, even if the recovery phrase is imported into another wallet brand.
The only solution for users is to update their firmware and generate a brand-new seed from scratch on the patched device. Coinkite also recommends adding extra protection through a strong BIP-39 passphrase, rolling physical dice at least 99 times, or both. When layers of human-written code and machine assistants fail, a user’s physical dice rolls remain the final defense against this exploit.
Reported by Decrypt.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




