In brief

Coinkite says a build error meant seeds on its Coldcard hardware wallets were drawn from a software fallback instead of the hardware generator.

It believes an attacker used AI on its open-source code, and says its own AI review weeks earlier found nothing.

Every current model is affected to some degree, and updating the firmware does not repair a seed already created.

Coinkite believes an attacker used AI to find a flaw that has cost owners of its Coldcard hardware wallets tens of millions of dollars in Bitcoin, and says its own AI review of the same code weeks earlier turned up nothing. The hardware wallet manufacturer published an advisory for its Mk3 and a technical breakdown on Thursday, after learning that seeds generated by its devices were far more guessable than intended.