Coinkite, the maker of Coldcard hardware wallets, said $38 million in Bitcoin was drained from user wallets after a critical firmware vulnerability allowed attackers to predict or reconstruct cryptographic seeds.
The flaw stemmed from a build error that caused Coldcard devices to generate seeds using a software fallback mechanism rather than the dedicated hardware random number generator. Because the software fallback produced weaker entropy, attackers could reconstruct the seeds and access associated funds.
Coinkite's internal investigation points to AI-driven analysis of its publicly available codebase. The company said the vulnerability's subtlety suggests a review process beyond typical manual code auditing.
Coinkite had run its own AI-powered code review weeks before the exploit. That analysis failed to flag the build error or its seed-generation implications, suggesting the attacker used different models or methodologies.
All current Coldcard models are affected to varying degrees. The flaw applies to any seed generated under the compromised firmware versions, regardless of when the device was manufactured.
Firmware updates do not remediate seeds already created under the flawed process. Users who generated wallet seeds with the vulnerable firmware must migrate funds to wallets with securely generated seeds.
At $38 million, the loss ranks among the larger single-vendor hardware wallet breaches on record, though it remains well below the smart contract exploits that have totaled hundreds of millions this year.

