An attacker drained $38 million in Bitcoin by exploiting a vulnerability in Coldcard hardware wallets, the device's maker Coinkite disclosed this week. The company believes the thief used artificial intelligence to analyze previous open-source firmware versions and pinpoint the flaw.
How the attacker found the hole
Coldcard's firmware is open source, meaning anyone can inspect the code. Coinkite says the attacker likely trained an AI model on older firmware releases to identify a weakness that could be exploited remotely. The company did not specify which firmware version contained the bug or how long it had been present before the exploit was discovered.
What Coinkite is doing now
Coinkite has released a patched firmware update and is urging all Coldcard users to install it immediately. The company has not said whether it will offer reimbursement to victims or if law enforcement has been contacted. The $38 million figure represents the total Bitcoin stolen in the attack, though the number of affected wallets remains unclear.
Hardware wallets are marketed as one of the most secure ways to store crypto, with funds kept offline. This incident shows that even air-gapped devices can be vulnerable if their firmware has bugs — and that open-source code, while auditable, can also be weaponized by attackers with enough computing power. Coldcard has a strong reputation among Bitcoiners, so the breach is a blow to trust in the ecosystem.
Coinkite says it will publish a full post-mortem in the coming weeks. Users are advised to update firmware and move funds to a new wallet if they suspect exposure. The broader question — how to defend against AI-assisted vulnerability hunting in open-source hardware — remains open.




