Loading market data...

Coldcard Bug Linked to $70M Bitcoin Heist, Users Urged to Move Funds

Coldcard Bug Linked to $70M Bitcoin Heist, Users Urged to Move Funds

Over a thousand bitcoins were stolen in a hack that began on July 30, with the breach tied to a critical bug in Coldcard hardware wallets. The vulnerability, in firmware versions 4.0.1 through 4.1.9 on MK3 devices, allowed attackers to compromise private key generation. Coinkite has released fixed firmware, but warns that updating alone doesn't secure existing seeds.

The bug and the fix

The flaw was a single line of code in the firmware responsible for secure private key generation. Seeds generated without user-added dice rolls or a BIP 39 extra passphrase are vulnerable. Coinkite published a guide and advisory, and pushed fixed firmware: MK3 to 4.2.0+, MK4/MK5 to 5.6.0+, and Q to 1.5.0Q+. But updating firmware doesn't fix existing seeds — users must create a new wallet and move their coins on-chain.

Why AI is in the spotlight

AI was used in the breach. NVK, co-founder of Coldcard, said AI-assisted code review can now find latent bugs faster than human experts, calling it a new paradigm. The hack and the estimated $70 million in stolen funds serve as a bounty for hackers to audit wallet codebases. An X Spaces public call drew a large crowd to discuss the incident.

The multisig risk

Multisignature wallets using a threshold of Coldcards may be especially exposed. For example, a 2-of-3 setup with two Coldcards and one uncompromised device could still be at risk. When moving funds, the multisig script revealed in the transaction could allow attackers to front-run with a higher fee transaction. MARA mining pool's Slipstream private mempool service can help keep transaction details secret until confirmed.

What users should do now

Anyone with a vulnerable seed should move their coins immediately. Coinkite's guide walks through creating a new wallet and transferring funds. NVK committed to helping affected users with police reports, insurance claims, and investigations. The industry is now watching for copycat attacks — the stolen bitcoin is a loud signal that wallet codebases are under scrutiny.