What happened.
Coldcard maker Coinkite has shipped fixed firmware after a reported seed-generation flaw allowed attackers to recreate private keys. Galaxy Research now reportedly connects nearly 1,200 drained addresses, holding more than 1,000 BTC, to the issue. The upstream record describes losses of roughly $70 million, though those figures are reported rather than independently verified.
This is an update to prior Coldcard coverage: the new elements are a firmware fix and a larger reported tally of affected funds. The reported exploit did not require attackers to touch the physical devices.
Why it matters.
The distinction between a device update and a vulnerable seed is central. If coins were controlled by private keys created through the affected process, updating firmware alone may not protect those coins. The supplied record says the practical monitoring implication is to move funds off pre-patch seeds.
The case also raises a narrower security question about AI-assisted code review. Coinkite’s NVK suspects an attacker used AI to find the latent flaw in older open-source firmware. That attribution is not established in the supplied evidence.
What to watch next.
Watch for further Coinkite guidance that clarifies which seeds are affected and what remediation is required, alongside additional tracing that either supports or revises the reported address and loss totals. A useful receipt would be a clear, source-backed update connecting the patched firmware, affected seed-generation process, and confirmed remediation steps.
Further Coinkite remediation guidance and corroborated tracing of the reportedly drained addresses and funds.
Upstream references and independent checks
Digest dated 2026-08-01 · upstream model claude-sonnet-4-6. Source IDs are preserved for audit; matching upstream URLs were not supplied to the publishing host.
- 1
77f3ad747a55ee9abd0c1acad88976375c6fa138Upstream reference; direct URL unavailable. - 2
72bc637e39e1b727320b041c5bb2bd35ac647931Upstream reference; direct URL unavailable. - 3
e66268915cbb3ba97a90c02999d0aa6cb459d2c4Upstream reference; direct URL unavailable. - 4
fbdd5320c9554f2dfae95dd7f8fca7257189d73dUpstream reference; direct URL unavailable. - 5
5407a0593cae3dc55e1656ebdfa76d5f16e06792Upstream reference; direct URL unavailable.
Related reading
- 1White hats move 52 Bitcoin from Coldcard exploit to recovery trust.September 25, 2026
This Research brief was generated by Terra from a dated upstream research digest. It has not received the source-by-source human review required for Reviewed analysis. Material limit: The loss estimate, address count, and AI-related attribution are reported in the upstream record and were not independently verified here.
