A critical Coldcard firmware flaw that has enabled the theft of more than US$70 million in Bitcoin is pushing open-source wallet developers towards AI-powered code audits and stronger security practices.
Coinkite has released fixed firmware after a critical vulnerability in its Coldcard hardware wallet firmware was linked to the theft of more than 1,000 BTC, worth over US$70 million. Security researchers believe AI-assisted vulnerability discovery likely played a role in identifying and exploiting the flaw, raising fresh concerns about the security of open-source Bitcoin wallet firmware.
The vulnerability affects Coldcard MK3 firmware versions 4.0.1 through 4.1.9 where wallet seeds were generated without user-added dice entropy or a BIP39 passphrase. Coinkite has released patched firmware for MK3, MK4, MK5 and Coldcard Q devices, but warned that upgrading alone does not secure previously generated wallet seeds. Users must create a new wallet and move funds to newly generated addresses.
The flaw stemmed from a single line of firmware code responsible for private key generation. According to NVK, Co-founder of Coldcard, “AI-assisted code review can now find latent bugs at a speed that is outpacing even the industry’s most seasoned experts. If your firmware is open-source or has ever been public, assume it’s already being read by attackers and defenders alike.”
The incident is expected to intensify security reviews across open-source wallet projects. Developers are increasingly expected to adopt AI-powered code auditing, while the industry is likely to accelerate the use of multi-vendor multisignature wallets, user-generated entropy, stronger wallet architectures and other measures to reduce future risks.













































































