Coldcard wallet bug enables $112M Bitcoin theft via AI exploit
A Coldcard firmware bug let attackers steal 1,778+ BTC ($112.7M) from 8,600+ wallets. Exploited via AI, the flaw affects wallets since March 2021. Users must create new seed phrases on updated firmware to stay secure.
A critical firmware bug in Coldcard hardware wallets, introduced in March 2021, allowed attackers to exploit a weakened seed phrase generation process. This vulnerability, found in firmware version 4.0.1 and affecting several Coldcard models, rerouted seed generation from a secure hardware random number generator to a predictable software-based one. As a result, attackers managed to steal over 1,778 Bitcoin from more than 8,600 wallet addresses, with confirmed losses exceeding $112.7 million. This incident marks the largest hardware wallet breach on record. Analysts believe unrestricted AI models were used to identify and exploit the bug, while defenders faced limitations due to AI safety policies. The attacks began in late July 2026, with over 1,000 Bitcoin stolen within just 41 minutes. No multisignature wallets were affected, and no further thefts have been recorded since August 6. Simply updating the firmware does not secure wallets created with the compromised software; users must generate new seed phrases on updated firmware to protect their funds.