Coldcard firmware exploit prompts Ledger warning on AI and wallet security
Coinkite patched a seed-generation flaw in some Coldcard firmware as Ledger says AI raises the bar for wallet security.
By Theo Nakamura · Staff Writer
· 3 min read
The Coldcard firmware exploit has prompted a security response from Coinkite and a broader warning from Ledger about AI-assisted vulnerability hunting. For Coldcard owners, the immediate issue is practical: updating the device alone does not fix an affected seed that was already generated, according to Coinkite.
Coinkite disclosed that a series of bugs in certain firmware versions kept the intended hardware random-number generator from contributing to seed generation. Instead, the process resolved to a MicroPython software fallback. The company said that reduced the security margin and could leave funds at risk in specified circumstances.
A seed is the cryptographic material used to generate wallet keys. Coinkite said the affected software path could make some private keys guessable.
Which Coldcard firmware versions are affected?
Coinkite identified Mk2 and Mk3 firmware versions 4.0.1 through 4.1.9 as affected. It also said seeds produced on Mk4, Mk5 and Q devices before their applicable fixed releases were affected.
The company estimates an effective search space of about 40 bits for affected Mk2 and Mk3 devices under its current attack assumptions. It described that figure as preliminary. For Mk4, Mk5 and Q, Coinkite estimates roughly 72 bits, because those models had additional secure-element input, though that did not restore the intended 128-bit target.
Coinkite said a seed created with at least 50 fair, independent and private dice rolls is not considered at risk from this random-number-generator issue alone. A strong, unique BIP-39 passphrase provides a separate barrier, it said, but does not repair an affected seed.
What should affected Coldcard owners do?
Coinkite says users should first install the fixed firmware for their model and release track, then generate and verify a new seed before moving funds. Its guidance also calls for a small test transaction before transferring the remaining balance. Updating firmware does not change a seed created under the affected versions.
- Mk2 and Mk3: version 4.2.0 or later.
- Mk4 and Mk5 standard track: version 5.6.0 or later.
- Q standard track: version 1.5.0Q or later.
- Mk4 and Mk5 Edge track: version 6.6.0X or later.
- Q Edge track: version 6.6.0QX or later.
Ledger CTO Charles Guillemet told Decrypt that the episode shows why hardware-wallet security depends on how cryptographic randomness is produced. He said users assessing a hardware wallet should understand how its randomness is generated and whether that process has independent certification.
Guillemet also argued that AI can speed up code review and vulnerability discovery, requiring defenses based on secure design, hardware and mathematical assurance. Coinkite said it has to assume someone may have used AI to examine older firmware, but that is not confirmation that AI found or exploited the flaw. Ledger says its own wallets were unaffected, a first-party claim about its products.
This story draws on original reporting from Decrypt.