A critical Coldcard firmware flaw that has enabled the theft of more than US$70 million in Bitcoin is pushing open source wallet developers towards AI-powered code audits and stronger security practices.
Coinkite has released fixed firmware after a critical vulnerability in its Coldcard hardware wallet firmware was linked to the theft of more than 1000 BTC, worth over US$70 million. Security researchers believe AI-assisted vulnerability discovery likely played a role in identifying and exploiting the flaw, raising fresh concerns about the security of open source Bitcoin wallet firmware.
The vulnerability affects Coldcard MK3 firmware versions 4.0.1 through 4.1.9 where wallet seeds were generated without user-added dice entropy or a BIP39 passphrase. Coinkite has released patched firmware for MK3, MK4, MK5 and Coldcard Q devices, but warned that upgrading alone does not secure previously generated wallet seeds. Users must create a new wallet and move funds to newly generated addresses.
The flaw stemmed from a single line of firmware code responsible for private key generation. According to NVK, Co-founder of Coldcard, “AI-assisted code review can now find latent bugs at a speed that is outpacing even the industry’s most seasoned experts. If your firmware is open source or has ever been public, assume it’s already being read by attackers and defenders alike.”
The incident is expected to intensify security reviews across open source wallet projects. Developers are increasingly expected to adopt AI-powered code auditing, while the industry is likely to accelerate the use of multi-vendor multisignature wallets, user-generated entropy, stronger wallet architectures and other measures to reduce future risks.















































































