AI might have helped hackers steal $38M in bitcoin
Coldcard's firmware flaw may have given AI the keys

Image by Cybernews.
- 594 BTC was allegedly stolen from Coldcard hardware wallet users due to firmware bugs.
- AI may have been used to analyze open-source code and identify vulnerabilities enabling seed word prediction.
- Users who generated seeds on affected Coldcard versions or migrated them to other wallets remain at risk.
- Security experts recommend multisignature setups using multiple devices from different manufacturers for large bitcoin holdings.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Coldcard, a popular bitcoin-only hardware wallet, is at the epicenter of a serious drama in the bitcoin world. At least 594 BTC ($38 million) has been drained, and users who migrated from Coldcard to other wallets may also be affected. AI might have helped the criminals.
It's still unclear whether the attack is ongoing. The Canadian firm Coinkite, the manufacturer of Coldcard, "out of an abundance of caution," warned users who generated their so-called seed words using a Mk3 on version 4.0.1 (March 2021) or any subsequent version that their funds may be at risk.
Seeds generated on Mk4, Q, and Mk5 before the fixed firmware releases are also affected. A firmware fix has already been released. However, updating it does not remove the risk – a new seed must be generated, and the funds migrated to the new wallet, the company said, sharing more detailed instructions for Coldcard users.
However, bitcoin security experts warn that other BTC users can also be affected if they migrate their funds from Coldcard to another device.
"If you exported a seed generated in a vulnerable Coldcard, moving it to another wallet, then that same insecure seed is still affected," bitcoin engineering and security teams at Block, a fintech company that also manufactures its own BTC hardware wallet, Bitkey, said.
Seed words are a set of 12-24 words that grant anyone who has them access to the wallet.
According to Coinkite, until today, they were unaware of "a complex and subtle series of bugs" that prevented their devices from generating sufficient randomness in certain firmware versions. As a result, an attacker was able to guess the seed words and drain the funds.
"The COLDCARD source code has always been open and publicly available, so we have to assume that someone used AI to review previous versions of our firmware and stumbled upon this issue," Coinkite said, adding that a few weeks ago, they used "one of the best available AI models" to review their code, and it did not find this bug or anything serious.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Meanwhile, other hardware wallet manufacturers, such as Trezor, Blockstream, Foundation, and Tangem, claim their users are safe unless they migrated their seed words from Coldcard. If this is the case, users are advised to generate a new seed and move their funds.
The incident has also highlighted the importance of creating a multisignature setup to secure larger sums of BTC, which ideally should also involve different devices from different manufacturers. With multisignature, more than one signature is needed to confirm a transaction, for example, 2 out of 3.
In either case, while some bitcoiners emphasize that this is the right time to panic because "everybody has access to frontier LLMs" and "dozens of hacking teams now researching how to exploit this," others urge users not to panic but to act decisively because "this isn't a drill."
The story is developing.