bitcoin
Bitcoin (BTC) $63,168.00 2.50%
ethereum
Ethereum (ETH) $1,872.42 2.30%
tether
Tether (USDT) $0.999094 0.00%
bnb
BNB (BNB) $588.82 0.70%
usd-coin
USDC (USDC) $0.999504 0.00%
xrp
XRP (XRP) $1.07 1.90%
solana
Solana (SOL) $73.31 1.60%
tron
TRON (TRX) $0.326189 0.80%
figure-heloc
Figure Heloc (FIGR_HELOC) $1.04 3.70%
staked-ether
Lido Staked Ether (STETH) $2,265.05 3.46%

It is estimated that over a thousand bitcoins have been stolen in a breach that gained attention on social media beginning July 30th. Coinkite, a highly regarded manufacturer of hardware wallets, has been identified as having a significant flaw in the secure generation of private keys for its Bitcoin wallets. Experts within the industry suggest that AI technology may have played a role in this incident.

The Coldcard MK3 devices, specifically those operating on firmware versions 4.0.1 (March 2021) to 4.1.9, are reported to be the most adversely affected. Any 12- or 24-word seeds generated by these devices, unless fortified by user-generated dice rolls or a BIP 39 extra passphrase, remain susceptible to exploitation.

Users falling under this category, who possess bitcoins in an MK3 Coldcard without utilizing the dice roll feature for added entropy or an extra passphrase, are advised to consider their assets at risk and should transfer their bitcoins from these wallets without delay. Technical writer Shinobi from Bitcoin Magazine has published a guide on this issue, and Coinkite has released both guidance and advisories for their users.

The vulnerability stems from a specific line of code within the firmware, a foundational software codebase governing the hardware. Fortunately, this firmware is upgradable. An update to Coinkite’s advisory issued this morning posits that users should upgrade the firmware for all three chip variants—MK3, MK4, and MK5 devices, along with the Coldcard Q:

“Updated July 31, 2026, at 9:33 a.m. EDT: Fixed firmware is now available. MK4 and MK5 users should update to version 5.6.0 or later, while Q users must upgrade to version 1.5.0Q or later. MK3 users should update to version 4.2.0 or later.”

Coinkite clarified within their advisory that simply updating the firmware does not render the private and public keys generated by the prior vulnerable firmware secure; those keys remain at risk as they were produced under weak conditions. Following a firmware update, a new wallet must be generated, and funds should be transferred on-chain to newly created addresses for optimal security. Coinkite stated:

“Updating the firmware does not alter or rectify an existing seed. If your seed was generated prior to the fixed firmware version for your model, please follow the migration guidance below unless the independent dice-entropy exception is applicable.”

Potential Risks for Multisignature Wallets

Peter Todd, a core contributor and cybersecurity engineer, addressed specific scenarios pertaining to multisignature wallets employing Coldcards to secure funds. “For example, if you possess a 2-of-3 multisignature setup, with 2 compromised Coldcards and a 3rd uncompromised device, transferring your funds could expose your script—previously concealed behind the address hash—to malicious actors. This affords them the opportunity to leverage the compromised Coldcard keys to seize your assets.”

In scenarios where multisig scripts are revealed via unconfirmed transactions, hackers may have the opportunity to initiate a competing transaction with a higher fee. Nonetheless, there is a solution available: the MARA mining pool offers a private mempool mining service named Slipstream. Todd elaborated, “They promise to keep your transaction—and thus, public keys—confidential until they have been recorded in a block, substantially diminishing the potential for theft.” He added, “If you have previously reused addresses, this option would not apply, and swift action is recommended to move your funds. However, if you have not, MARA may be able to assist.”

Looking Beyond the Immediate Crisis

NVK, a co-founder of Coldcard, provided a detailed overview through a post on X, outlining not only the basic security measures needed to safeguard funds but also broader implications pertaining to shifts in technology as AI’s hacking capabilities evolve. He stated the company’s commitment to support affected users in pursuing police reports, insurance claims, and private investigations, including offering a written incident summary specific to each user’s losses and any pertinent transaction data.

Furthermore, NVK underscored the broader technological transformation brought about by AI advancements, which have reshaped the cybersecurity landscape. He articulated:

“To every other developer: we believe this is a sobering reality of the new AI paradigm. AI-assisted code review can now uncover latent bugs at a pace that surpasses even the most experienced experts in the industry. If your firmware is open-source or has ever been made public, assume it is currently being scrutinized by both attackers and defenders.”

The recent breach, along with an estimated $70 million in stolen funds within a 24-hour window, acts as a financial incentive for hackers now likely conducting thorough audits on available wallet codebases. While the Bitcoin community has generally trusted hackers to probe their code, the emergence of AI models tailored for cybersecurity is likely to expedite these examination processes.

Last night, industry experts convened in a lengthy public discussion on X Spaces, exploring the recent incident extensively. Discussions not only covered urgent recommendations and responses to Bitcoin users but also foresaw probable developments in the upcoming weeks. Other wallet providers are likely to undergo scrupulous inspections, particularly those open-source projects that generate private key materials.

Although the X Spaces conversation was not recorded, aiming to protect the privacy of the participants, initial feedback suggests that companies must audit their code utilizing the latest frontier AI models to ensure survival. Cybersecurity-centric AI models created by organizations such as Anthropic, OpenAI, Moonshot’s Kimi K3, and others are currently accessible. Many companies within the Bitcoin sphere already employ these models for code integrity testing, though some may not; the quest for vulnerabilities in wallet-focused code will undoubtedly intensify in the weeks ahead.

In conclusion, the community reflects on lost assets, entering a period of introspection and meticulous examination. Beyond this historic breach lies the potential for a more secure open-source self-custody infrastructure, fueled by hard-earned lessons. Each hacker leveraging an AI agent is likely scrutinizing defenses as we speak.

Future Considerations for Multi-vendor, Multi-key Wallets and Covenants

The future of high-sovereignty wallets, whether at the retail or corporate level, is likely to embrace a model that does not rely solely on any one vendor. Well-implemented multisignature wallets can effectively distribute vulnerability risks across diverse codebases, teams, and hardware.

User-generated entropy emerged as a significant theme during the earlier X Spaces discussion, with the generation of entropy using dice rolls frequently referenced as a viable solution. Coinkite, along with other hardware wallet providers like Foundation Devices, offers comprehensive guidance on how users can correctly incorporate their own entropy, typically requiring a substantial number of individual dice rolls—ideally over a hundred. Once accomplished, these dice rolls provide a non-software-based source of randomness for wallets, thus minimizing risks associated with software- or hardware-generated entropy.

Additionally, covenants, a popular soft fork among a specialized segment of the Bitcoin industry, have been proposed as a further step towards reinforcing the self-custody paradigm. This prospective upgrade to Bitcoin’s consensus may face challenges, but it could afford users valuable smart contract capabilities, such as the ability to send funds exclusively to a predefined whitelist of addresses, a feature currently unattainable within Bitcoin script.

Source link

Leave a Comment

I accept the Terms and Conditions and the Privacy Policy

bitcoin
Bitcoin (BTC) $63,168.00 2.50%
ethereum
Ethereum (ETH) $1,872.42 2.30%
tether
Tether (USDT) $0.999094 0.00%
bnb
BNB (BNB) $588.82 0.70%
usd-coin
USDC (USDC) $0.999504 0.00%
xrp
XRP (XRP) $1.07 1.90%
solana
Solana (SOL) $73.31 1.60%
tron
TRON (TRX) $0.326189 0.80%
figure-heloc
Figure Heloc (FIGR_HELOC) $1.04 3.70%
staked-ether
Lido Staked Ether (STETH) $2,265.05 3.46%