Key Takeaways
- Attackers exploited a firmware vulnerability from March 2021 to steal more than 1,778 Bitcoin from Coldcard hardware wallet users
- Total verified losses exceed $112.7 million, affecting over 8,600 wallet addresses
- Analysts at Galaxy Research suspect hackers deployed unrestricted artificial intelligence models to identify and weaponize the security flaw
- Cybersecurity experts claim AI safety regulations at American research facilities prevented them from utilizing comparable defensive tools
- Multisignature wallet configurations remained unaffected; affected users must create fresh seed phrases without delay
A critical security vulnerability embedded in Coldcard firmware dating back to March 2021 enabled malicious actors to extract more than 1,778 Bitcoin from upwards of 8,600 individual wallet addresses, establishing this incident as the most significant hardware wallet compromise ever documented. Based on current valuations, verified financial damages reach $112.7 million.
The coordinated assault commenced on July 30, 2026. In a mere 41-minute window, attackers successfully drained over 1,000 Bitcoin from more than 1,000 separate addresses. Since August 6, no additional malicious transactions have been detected.
The underlying issue originated from a firmware release distributed by Coinkite in version 4.0.1. This particular update inadvertently redirected the seed phrase creation mechanism from a hardware-based random number generator to a software-dependent pseudorandom number generator. Software-generated randomness exhibits significantly greater predictability, rendering the resulting cryptographic keys substantially more vulnerable to replication or brute-force attacks.
According to reports, a software developer alerted Coinkite to a connected concern as far back as May 2025. The security gap remained unaddressed for sufficient time to enable threat actors to develop and execute exploitation frameworks at scale, targeting numerous Coldcard versions including the Mk2, Mk3, Mk4, Q, and Mk5 models.
Artificial Intelligence Utilized in Attack and Defense Efforts
Galaxy Research concluded with substantial certainty that threat actors leveraged AI systems lacking cybersecurity guardrails to locate and weaponize the vulnerability. The recently published open-source Kimi K3 model was cited as representative of the technology likely employed in the breach.
According to Rob Hamilton, who serves as chief executive of Anchorwatch, restrictive safety protocols implemented at leading American AI research laboratories effectively prevented cybersecurity professionals from accessing equivalent defensive capabilities. This forced protection teams to depend on the identical Chinese open-source AI platforms utilized by the attackers themselves.
Hamilton collaborated with approximately 25 additional security specialists, including developer James O’Beirne and Calle from the Cashu initiative, to establish the Bitcoin Red Team. This collective has been conducting systematic reviews of code repositories throughout the cryptocurrency ecosystem to identify security weaknesses and propose remediation measures.
Coinkite published an official security bulletin on July 30 and deployed corrected firmware by July 31. Chief Executive Officer Rodolfo Novak released a formal public statement of apology.
Critical Actions for Affected Users
Simply installing updated firmware cannot resolve the underlying security problem. Any seed phrase created using compromised firmware remains permanently vulnerable to exploitation. Users are required to generate an entirely new seed phrase using patched firmware versions and transfer all holdings to freshly created wallets.
From the total of 1,778 Bitcoin confirmed stolen, approximately 1,531 Bitcoin continues to sit dormant in addresses controlled by the attackers. Roughly 246 Bitcoin has been relocated, with 65% entering Coinjoin privacy-mixing services and 35% transferred through blockchain methods engineered to eliminate transaction traceability.
Notably, zero instances of theft occurred from multisignature wallet configurations. Multisig architectures demand multiple cryptographic keys to validate transactions, ensuring that compromise of a single seed phrase proves insufficient to authorize fund transfers.
Galaxy Research reports having distributed attacker-controlled wallet addresses to cryptocurrency exchanges, regulatory compliance organizations, and law enforcement agencies with the objective of freezing assets should they arrive at centralized service providers.
This theft currently occupies the twentieth position among all documented cryptocurrency heists, positioned beneath Multichain’s $130 million incident from July 2023 and exceeding the $100 million extracted from Harmony’s Horizon bridge during June 2022.
The post AI-Powered Attack Drains $112M in Bitcoin from Coldcard Hardware Wallets appeared first on Blockonomi.
Source: https://blockonomi.com/ai-powered-attack-drains-112m-in-bitcoin-from-coldcard-hardware-wallets/





Be the first to comment