Coinkite issues firmware update after hackers stole over $114 million Bitcoin
Coinkite, the company behind Coldcard wallets, released new firmware after hackers exploited a flaw and stole over $114 million in Bitcoin.
If you've used a Mk4, Mk5, or Q model with a seed or master key created on affected firmware between 2021 and July 2026, you need to update your device and follow the migration steps.
Create new seeds using physical randomness
The fix patches the flaw, but that's not all: affected users should create new wallet seeds using physical randomness (think dice rolls or coin flips) and move their funds to fresh wallets.
Coinkite has also launched a public status page listing which releases are fixed and what migration steps apply, and tells owners to use its official downloads page only.
SHA-256 RNG and tightened transaction checks
A deep dive using AI tools found additional security gaps too.
The latest firmware now uses a stronger random number generator based on Bitcoin's SHA-256 algorithm and tightens up transaction checks, especially for USB connections, to keep things safer going forward.