{"investigation":{"slug":"coldcard-wallet-coinkite-firmware-exploit","entity_name":"Coldcard Wallet (Coinkite Firmware Exploit)","trust_score":28,"severity_base":null,"score_modifier":0,"confidence":0.85,"status":"published","content_type":"investigation","summary":"Coldcard is a Bitcoin hardware wallet manufactured by Canadian company Coinkite. Beginning July 30, 2026, attackers exploited a five-year-old firmware bug that caused seed generation to use a weak software pseudorandom number generator instead of the device hardware entropy source, reducing effective key strength to as low as 40 bits on older models. Galaxy Research estimated total losses of approximately 1,816 to 2,417 BTC (roughly $116–$151 million USD) across more than 5,200 addresses, making it the largest hardware wallet exploit on record and the third-largest crypto hack of 2026. Coinkite published a security advisory and patched firmware but has not announced any compensation program for affected users.","sections":[{"content":"A build configuration error introduced in Coldcard firmware version 4.0.1, released March 17, 2021, caused the wallet seed generation routine to use MicroPython's Yasmarang software pseudorandom number generator (PRNG) rather than the STM32 hardware true random number generator (TRNG). According to an independent technical analysis published by Block's engineering team, the libngu library checked whether the preprocessor macro MICROPY_HW_ENABLE_RNG was defined rather than whether it was set to a non-zero value. Because Coinkite set that macro to zero — intending to disable the software fallback in favor of the hardware RNG — the #ifndef guard still resolved as true, binding seed generation to the Yasmarang fallback for the life of the affected firmware series. Coinkite confirmed this root cause in its official technical backgrounder: 'A build and link integration error meant that setting did not have the intended effect, and libNgU's rng_get() symbol resolved to MicroPython's default Yasmarang implementation instead.' The bug lay dormant in open-source firmware for over five years before exploitation began.","heading":"Overview of the Vulnerability","sources":[{"url":"https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware","name":"Technical Deep Dive: Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware — Block Engineering Blog","type":"research","credibility":2},{"url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/","name":"Coldcard Security Advisory — COINKITE Blog","type":"official","credibility":1},{"url":"https://blog.coinkite.com/entropy-technical-backgrounder/","name":"Technical Entropy Backgrounder — COINKITE Blog","type":"official","credibility":1}],"severity":"critical"},{"content":"According to Coinkite's published security advisory, the following firmware versions are affected. Mk2 and Mk3 devices running firmware 4.0.1 through 4.1.9 received no cryptographic entropy from the hardware source; with knowledge of the device's MCU UID and timer state, seed generation on these models was effectively deterministic, reducing effective entropy to approximately 40 bits. Mk4, Mk5, and Q devices running firmware 5.0.0 through 5.5.x (Mk4/Mk5) and 1.0.x through 1.4.x (Q) were also affected; a secure element contributed some entropy but the implementation retained only four bytes through a SHA256d hash, limiting the effective search space to approximately 2^31 candidate trials, or about 72 bits of entropy, against the expected 128 bits. Block's engineering analysis confirmed this assessment independently. Seeds generated using at least 50 independent, private dice rolls are considered unaffected regardless of firmware version, per Coinkite's advisory. Updating firmware does not remediate seeds already generated under vulnerable versions; Coinkite stated that any seed created between March 2021 and the patch date should be treated as compromised.","heading":"Affected Firmware Versions and Entropy Degradation","sources":[{"url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/","name":"Coldcard Security Advisory — COINKITE Blog","type":"official","credibility":1},{"url":"https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware","name":"Technical Deep Dive: Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware — Block Engineering Blog","type":"research","credibility":2},{"url":"https://cryptouniversity.network/news/the-2026-coldcard-entropy-vulnerability-explained","name":"The 2026 Coldcard Entropy Vulnerability, Explained — Crypto University","type":"news_article","credibility":2}],"severity":"critical"},{"content":"Active exploitation began July 30, 2026. The first confirmed wave swept approximately 1,082.65 BTC (roughly $70.2 million) from 1,196 addresses in approximately 41 minutes, according to on-chain analysis reported by The Hacker News. Three additional waves followed over the subsequent week, with Galaxy Research tracking at least 15 independent attackers exhibiting differing transaction construction patterns, suggesting multiple actors exploiting the same vulnerability concurrently rather than a single coordinated group. Galaxy Research's rolling tally, as reported by TRM Labs, placed confirmed losses at approximately 1,816 BTC (~$116 million USD) across more than 5,200 addresses. Decrypt reported Galaxy's estimate of potential losses reaching 2,417 BTC (~$151.3 million) including a potential fourth wave. TechCrunch reported total losses exceeding $130 million across more than 7,700 addresses. TRM Labs characterized the event as the largest hardware wallet exploit on record and the third-largest crypto hack of 2026. As of Galaxy Research's August 14 update, no confirmed attacker activity had appeared after August 6, 2026, with the abatement attributed to victims migrating funds or remaining vulnerable balances already drained. Of the approximately 1,778 BTC confirmed stolen at that date, 1,531 BTC remained unmoved in attacker-controlled addresses; approximately 246 BTC had been moved, with roughly 65 percent flowing into coinjoin transactions.","heading":"Exploitation and Financial Impact","sources":[{"url":"https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack","name":"The Largest Hardware Wallet Exploit of 2026: Inside the USD 116 Million Coldcard Hack — TRM Labs","type":"research","credibility":2},{"url":"https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html","name":"Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes — The Hacker News","type":"news_article","credibility":2},{"url":"https://decrypt.co/375656/coldcard-bitcoin-thefts-slow-losses-top-150-million","name":"Coldcard Bitcoin Thefts Slow, But Losses Could Top $150 Million: Galaxy — Decrypt","type":"news_article","credibility":2},{"url":"https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/","name":"Hackers steal over $130M by exploiting bug in offline hardware wallets — TechCrunch","type":"news_article","credibility":1},{"url":"https://www.cryptotimes.io/2026/08/04/coldcard-exploit-15-attackers-130m-losses-galaxy/","name":"15 Attackers Exploit Ongoing Coldcard Hack as Losses Approach $130M — CryptoTimes","type":"news_article","credibility":2},{"url":"https://www.cryptotimes.io/2026/08/14/galaxy-claims-coldcard-attacks-halt-after-aug-6/","name":"Galaxy Claims Coldcard Attacks Halt After Aug 6 — CryptoTimes","type":"news_article","credibility":2}],"severity":"critical"},{"content":"Coinkite published a security advisory and technical backgrounder on or around July 30–31, 2026, confirming the vulnerability. Patched firmware versions were released, with Mk4 and Mk5 users directed to update to version 5.6.0 or later, Q users to version 1.5.0Q or later, and Mk3 users to version 4.2.0 or later. Coinkite stated it was unaware of the bug until the day of disclosure, writing: 'We were unaware of the bug until today.' The company stated it believed adversarial AI-assisted code review was the likely discovery method for attackers, though it acknowledged this was an inference rather than a confirmed finding. Following the breach disclosure, Coinkite conducted its own AI-assisted code review using frontier models and reported finding additional, unrelated vulnerabilities in transaction approval logic, USB data handling, and firmware update validation, according to CoinDesk's August 21 report. In August 2026, Coinkite suspended its standard 120-day automatic customer data deletion policy, citing legal preservation obligations arising from anticipated litigation. The company offered an opt-out mechanism for customers who did not wish their data retained. No compensation program for affected users has been publicly announced as of the date of this investigation.","heading":"Coinkite's Response and Firmware Patch","sources":[{"url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/","name":"Coldcard Security Advisory — COINKITE Blog","type":"official","credibility":1},{"url":"https://blog.coinkite.com/entropy-technical-backgrounder/","name":"Technical Entropy Backgrounder — COINKITE Blog","type":"official","credibility":1},{"url":"https://www.coindesk.com/tech/2026/08/21/coldcard-ships-firmware-after-usd114-million-bitcoin-theft-says-ai-helped-catch-more-bugs","name":"Coldcard ships firmware after $114 million bitcoin theft, says AI helped catch more bugs — CoinDesk","type":"news_article","credibility":1},{"url":"https://www.cryptotimes.io/2026/08/07/coldcard-maker-suspends-data-deletion-as-legal-proceedings-loom/","name":"Coldcard Maker Suspends Data Deletion as Legal Proceedings Loom — CryptoTimes","type":"news_article","credibility":2}],"severity":"high"},{"content":"As of August 2026, no formal lawsuit against Coinkite has been reported as filed. However, class-action litigation has been publicly threatened by victim groups, and legal commentary has identified two potential recovery routes: on-chain asset tracing targeting the attackers, and civil liability claims against Coinkite in Canada, where the company is registered. Bitcoin.com News reported in August 2026 that victims were coordinating class-action proceedings; the report characterized the filings as threatened and anticipated rather than entered. Canadian law firm Weir Foulds published analysis on Lexology noting that negligence and product defect theories present a credible basis for investigation, while acknowledging legal experts are divided on the likelihood of recovery. Coinkite's standard terms of service disclaim liability for software defects, an issue that remains unresolved in litigation that has not yet been adjudicated. No regulatory action by a securities regulator, financial regulator, or law enforcement agency against Coinkite has been reported as of this investigation.","heading":"Legal and Regulatory Exposure","sources":[{"url":"https://news.bitcoin.com/regulation-and-legal/coinkite-faces-class-action-threat-as-bitcoin-wallet-bug-costs-users-over-1300-btc/","name":"Coinkite Faces Class Action Threat as Bitcoin Wallet Bug Costs Users Over 1,300 BTC — Bitcoin.com News","type":"news_article","credibility":2},{"url":"https://www.lexology.com/library/detail.aspx?g=fb177a37-2ba6-419e-9fc5-b337da7bae64","name":"The Coldcard Exploit: Why Victims May Have Two Routes to Recovery — Weir Foulds via Lexology","type":"other","credibility":2},{"url":"https://www.weirfoulds.com/the-coldcard-exploit-why-victims-may-have-two-routes-to-recovery","name":"The Coldcard Exploit: Why Victims May Have Two Routes to Recovery — Weir Foulds","type":"other","credibility":2}],"severity":"high"},{"content":"The incident has reignited debate about the risks of Bitcoin self-custody. CoinDesk reported in July 2026 that the exploit shook faith in self-custody and may push some investors toward Bitcoin ETFs. The attack method required no physical access to devices; attackers reconstructed private keys entirely offline by exploiting the reduced entropy of weakened seeds. The vulnerability is distinct from supply-chain attacks or physical interdiction; the flaw was a software defect present in open-source firmware across a five-year production window. Coldcard devices themselves were not remotely accessed or taken over. The event established a precedent that hardware wallet manufacturers do not face any legal or industry obligation to compensate users for firmware-derived losses, absent a court ruling to the contrary. No indemnity fund, insurance mechanism, or exchange backstop applied to self-custodied hardware wallet losses in this case.","heading":"Self-Custody Risk and Industry Context","sources":[{"url":"https://www.coindesk.com/business/2026/07/31/coldcard-s-usd38-million-so-far-exploit-shakes-faith-in-self-custody-may-push-investors-to-etfs","name":"Coldcard exploit reignites Bitcoin self-custody debate after $38 million theft — CoinDesk","type":"news_article","credibility":1},{"url":"https://fortune.com/2026/08/03/bitcoin-owners-116-million-hack-coldcard-coinkite-exploit/","name":"Bitcoin owners rocked by $116 million hack: What we know about the Coldcard exploit — Fortune","type":"news_article","credibility":1}],"severity":"medium"}],"timeline":[{"date":"2021-03-17","event":"Coldcard firmware version 4.0.0 (followed shortly by 4.0.1) released, introducing the libngu library integration error that caused seed generation to fall back to the Yasmarang software PRNG instead of the STM32 hardware RNG. Bug lay dormant in open-source code.","source":"Block Engineering Blog; Coinkite Technical Backgrounder","source_url":"https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware"},{"date":"2026-07-30","event":"First wave of exploitation begins. Approximately 1,082.65 BTC (~$70.2 million) drained from 1,196 addresses in roughly 41 minutes. Coinkite publishes security advisory the same day acknowledging the vulnerability and releasing initial patched firmware.","source":"The Hacker News; Coinkite Security Advisory","source_url":"https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html"},{"date":"2026-07-31","event":"CoinDesk reports total losses at approximately $38 million with the exploit still ongoing. Coinkite confirms patched firmware versions available (Mk4/Mk5: 5.6.0+; Q: 1.5.0Q+; Mk3: 4.2.0+). Self-custody debate begins publicly.","source":"CoinDesk","source_url":"https://www.coindesk.com/business/2026/07/31/coldcard-s-usd38-million-so-far-exploit-shakes-faith-in-self-custody-may-push-investors-to-etfs"},{"date":"2026-08-02","event":"Galaxy Research identifies approximately 1,367 BTC drained across 4,585 addresses. Class-action threats against Coinkite reported by Bitcoin.com News. Attack spreads reported by CoinDesk.","source":"Crypto Briefing; Bitcoin.com News","source_url":"https://cryptobriefing.com/galaxy-research-coldcard-btc-attack-1367/"},{"date":"2026-08-04","event":"Galaxy Research identifies at least 15 independent attackers. TechCrunch reports losses exceeding $130 million across more than 7,700 addresses. TRM Labs publishes full analysis characterizing the event as the largest hardware wallet exploit on record and the third-largest crypto hack of 2026.","source":"TechCrunch; TRM Labs","source_url":"https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/"},{"date":"2026-08-06","event":"Galaxy Research reports no confirmed attacker activity after this date. Approximately 1,531 BTC remains unmoved in attacker-controlled addresses.","source":"CryptoTimes (citing Galaxy Research)","source_url":"https://www.cryptotimes.io/2026/08/14/galaxy-claims-coldcard-attacks-halt-after-aug-6/"},{"date":"2026-08-07","event":"Coinkite suspends its standard 120-day customer data deletion policy, citing legal preservation obligations arising from anticipated litigation. Opt-out mechanism offered to customers.","source":"CryptoTimes","source_url":"https://www.cryptotimes.io/2026/08/07/coldcard-maker-suspends-data-deletion-as-legal-proceedings-loom/"},{"date":"2026-08-14","event":"Galaxy Research publishes update noting attack activity has halted. Potential total losses estimated at up to 2,417 BTC (~$151.3 million) including an unconfirmed fourth wave.","source":"Decrypt; CryptoTimes","source_url":"https://decrypt.co/375656/coldcard-bitcoin-thefts-slow-losses-top-150-million"},{"date":"2026-08-21","event":"Coinkite ships additional enhanced firmware update, stating that post-incident AI-assisted code review found additional unrelated vulnerabilities in transaction approval logic, USB handling, and firmware update validation.","source":"CoinDesk","source_url":"https://www.coindesk.com/tech/2026/08/21/coldcard-ships-firmware-after-usd114-million-bitcoin-theft-says-ai-helped-catch-more-bugs"}],"sources_used":[{"url":"https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/","name":"Coldcard Security Advisory — COINKITE Blog","type":"official","archive_url":"http://web.archive.org/web/20260914233518/https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/","credibility":1,"archive_timestamp":"2026-09-14T23:35:18+00:00"},{"url":"https://blog.coinkite.com/entropy-technical-backgrounder/","name":"Technical Entropy Backgrounder — COINKITE Blog","type":"official","archive_url":"http://web.archive.org/web/20260911040619/https://blog.coinkite.com/entropy-technical-backgrounder/","credibility":1,"archive_timestamp":"2026-09-11T04:06:19+00:00"},{"url":"https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack","name":"The Largest Hardware Wallet Exploit of 2026: Inside the USD 116 Million Coldcard Hack — TRM Labs","type":"research","archive_url":"http://web.archive.org/web/20260908064819/https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack","credibility":2,"archive_timestamp":"2026-09-08T06:48:19+00:00"},{"url":"https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware","name":"Technical Deep Dive: Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware — Block Engineering Blog","type":"research","archive_url":"http://web.archive.org/web/20260911040619/https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware","credibility":2,"archive_timestamp":"2026-09-11T04:06:19+00:00"},{"url":"https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html","name":"Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes — The Hacker News","type":"news_article","archive_url":"http://web.archive.org/web/20260911223129/https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html","credibility":2,"archive_timestamp":"2026-09-11T22:31:29+00:00"},{"url":"https://www.coindesk.com/business/2026/07/31/coldcard-s-usd38-million-so-far-exploit-shakes-faith-in-self-custody-may-push-investors-to-etfs","name":"Coldcard exploit reignites Bitcoin self-custody debate after $38 million theft — CoinDesk","type":"news_article","archive_url":"http://web.archive.org/web/20260917160449/https://www.coindesk.com/business/2026/07/31/coldcard-s-usd38-million-so-far-exploit-shakes-faith-in-self-custody-may-push-investors-to-etfs","credibility":1,"archive_timestamp":"2026-09-17T16:04:49+00:00"},{"url":"https://www.coindesk.com/tech/2026/08/02/bitcoin-cold-wallet-attack-spreads-to-4-500-addresses-as-losses-near-usd89-million","name":"Bitcoin cold-wallet attack spreads to 4,500 addresses as losses near $89 million — CoinDesk","type":"news_article","archive_url":"http://web.archive.org/web/20260807042244/https://www.coindesk.com/tech/2026/08/02/bitcoin-cold-wallet-attack-spreads-to-4-500-addresses-as-losses-near-usd89-million","credibility":1,"archive_timestamp":"2026-08-07T04:22:44+00:00"},{"url":"https://www.coindesk.com/tech/2026/08/21/coldcard-ships-firmware-after-usd114-million-bitcoin-theft-says-ai-helped-catch-more-bugs","name":"Coldcard ships firmware after $114 million bitcoin theft, says AI helped catch more bugs — CoinDesk","type":"news_article","archive_url":"http://web.archive.org/web/20260915214026/https://www.coindesk.com/tech/2026/08/21/coldcard-ships-firmware-after-usd114-million-bitcoin-theft-says-ai-helped-catch-more-bugs","credibility":1,"archive_timestamp":"2026-09-15T21:40:26+00:00"},{"url":"https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/","name":"Hackers steal over $130M by exploiting bug in offline hardware wallets — TechCrunch","type":"news_article","archive_url":"http://web.archive.org/web/20260908064838/https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/","credibility":1,"archive_timestamp":"2026-09-08T06:48:38+00:00"},{"url":"https://fortune.com/2026/08/03/bitcoin-owners-116-million-hack-coldcard-coinkite-exploit/","name":"Bitcoin owners rocked by $116 million hack: What we know about the Coldcard exploit — Fortune","type":"news_article","archive_url":"http://web.archive.org/web/20260904004259/https://fortune.com/2026/08/03/bitcoin-owners-116-million-hack-coldcard-coinkite-exploit/","credibility":1,"archive_timestamp":"2026-09-04T00:42:59+00:00"},{"url":"https://decrypt.co/375656/coldcard-bitcoin-thefts-slow-losses-top-150-million","name":"Coldcard Bitcoin Thefts Slow, But Losses Could Top $150 Million: Galaxy — Decrypt","type":"news_article","archive_url":"http://web.archive.org/web/20260824100029/https://decrypt.co/375656/coldcard-bitcoin-thefts-slow-losses-top-150-million","credibility":2,"archive_timestamp":"2026-08-24T10:00:29+00:00"},{"url":"https://cryptobriefing.com/galaxy-research-coldcard-btc-attack-1367/","name":"Galaxy Research identifies 1,367 BTC drained in attacks on Coldcard addresses — Crypto Briefing","type":"news_article","archive_url":"http://web.archive.org/web/20260807042245/https://cryptobriefing.com/galaxy-research-coldcard-btc-attack-1367/","credibility":2,"archive_timestamp":"2026-08-07T04:22:45+00:00"},{"url":"https://www.cryptotimes.io/2026/08/04/coldcard-exploit-15-attackers-130m-losses-galaxy/","name":"15 Attackers Exploit Ongoing Coldcard Hack as Losses Approach $130M — CryptoTimes","type":"news_article","archive_url":"http://web.archive.org/web/20260807042246/https://www.cryptotimes.io/2026/08/04/coldcard-exploit-15-attackers-130m-losses-galaxy/","credibility":2,"archive_timestamp":"2026-08-07T04:22:46+00:00"},{"url":"https://www.cryptotimes.io/2026/08/14/galaxy-claims-coldcard-attacks-halt-after-aug-6/","name":"Galaxy Claims Coldcard Attacks Halt After Aug 6 — CryptoTimes","type":"news_article","archive_url":"https://web.archive.org/web/20260919005723/https://www.cryptotimes.io/2026/08/14/galaxy-claims-coldcard-attacks-halt-after-aug-6/","credibility":2,"archive_timestamp":"2026-09-19T00:57:23+00:00"},{"url":"https://www.cryptotimes.io/2026/08/07/coldcard-maker-suspends-data-deletion-as-legal-proceedings-loom/","name":"Coldcard Maker Suspends Data Deletion as Legal Proceedings Loom — CryptoTimes","type":"news_article","archive_url":"http://web.archive.org/web/20260808214426/https://www.cryptotimes.io/2026/08/07/coldcard-maker-suspends-data-deletion-as-legal-proceedings-loom/","credibility":2,"archive_timestamp":"2026-08-08T21:44:26+00:00"},{"url":"https://news.bitcoin.com/regulation-and-legal/coinkite-faces-class-action-threat-as-bitcoin-wallet-bug-costs-users-over-1300-btc/","name":"Coinkite Faces Class Action Threat as Bitcoin Wallet Bug Costs Users Over 1,300 BTC — Bitcoin.com News","type":"news_article","archive_url":"http://web.archive.org/web/20260913234923/https://news.bitcoin.com/regulation-and-legal/coinkite-faces-class-action-threat-as-bitcoin-wallet-bug-costs-users-over-1300-btc/","credibility":2,"archive_timestamp":"2026-09-13T23:49:23+00:00"},{"url":"https://www.lexology.com/library/detail.aspx?g=fb177a37-2ba6-419e-9fc5-b337da7bae64","name":"The Coldcard Exploit: Why Victims May Have Two Routes to Recovery — Weir Foulds via Lexology","type":"other","archive_url":null,"credibility":2,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://crypto.news/coldcard-firmware-bug-drains-38-million-bitcoin/","name":"A build error in Coldcard's firmware drained $38 million in bitcoin in 25 minutes — Crypto.news","type":"news_article","archive_url":"http://web.archive.org/web/20260821033349/https://crypto.news/coldcard-firmware-bug-drains-38-million-bitcoin/","credibility":2,"archive_timestamp":"2026-08-21T03:33:49+00:00"},{"url":"https://bitcoinmagazine.com/business/coinkite-releases-fixed-firmware-after-coldcard-bug-ai-likely-involved-in-the-hack","name":"Coinkite Releases Fixed Firmware After Coldcard Bug; AI Likely Involved In The Breach — Bitcoin Magazine","type":"news_article","archive_url":"http://web.archive.org/web/20260910092733/https://bitcoinmagazine.com/business/coinkite-releases-fixed-firmware-after-coldcard-bug-ai-likely-involved-in-the-hack","credibility":2,"archive_timestamp":"2026-09-10T09:27:33+00:00"}],"source_tags":[],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-09-18T23:06:22.962325+00:00","updated_at":"2026-09-19T01:01:14.416352+00:00"}}