Coldcard, a hardware wallet manufacturer, released firmware version 5.6.1 following a $114 million exploit that compromised user funds across multiple devices. The update includes revisions to USB handling and firmware validation discovered during an AI-assisted security review.

The exploit, which Coinkite quantified at approximately 1,816 bitcoin across affected wallets, represents the largest known hardware wallet compromise of 2026. The vulnerability allowed attackers to access private keys without triggering the device's security mechanisms, according to the company's security disclosure.

Coinkite's engineering team worked with AI models during code review and identified additional weaknesses beyond those that enabled the initial attack. The company said the review process flagged edge cases in how the device validated firmware signatures and processed USB communications that could have been exploited in chain attacks.

The most visible change in 5.6.1 targets seed generation, the process by which new private keys are created on the device. Coldcard now requires users to introduce physical randomness during this process, rejecting purely algorithmic key derivation. Users can satisfy this requirement through 65 key presses, 50 dice rolls, or 128 coin flips on the device's interface. Coinkite said this requirement forces attackers to either compromise the user's physical input or intercept entropy at creation time, closing attack vectors that had relied on predicting or manipulating seed values.

The firmware update follows an emergency patch issued on July 31. That interim release addressed the most critical vector but did not fully resolve the underlying validation logic. August 20's 5.6.1 represents the first complete rewrite of the affected subsystems.

MSB Intel

Coinkite has not disclosed the timeline between when the exploit began circulating and when it was discovered. Public reports first surfaced the vulnerability in early August, prompting the emergency response. The $114 million figure encompasses confirmed thefts and includes estimates from on-chain analysis firms tracking the movement of stolen bitcoin through exchange deposit addresses.

The physical randomness requirement is mandatory for all new seeds generated on 5.6.1 and later. Existing seeds on older firmware remain subject to the original vulnerability unless users perform a full key rotation, a process that requires moving holdings to a new device or address derived from a manually entered seed. Coinkite estimated adoption of the patched firmware at approximately 40 percent within the first 72 hours of release based on device telemetry.

The exploit has accelerated a broader industry recalibration of hardware wallet security practices. Ledger and Trezor have both announced firmware audits in the weeks following Coldcard's disclosure. The $114 million loss is roughly 2.3 times larger than the previous record for a single hardware wallet family, the 2018 Ledger phishing campaign that exposed approximately 50,000 customer email addresses and shipping information but did not directly compromise private keys. Industry auditors and institutional custodians have cited the Coldcard incident as validation of their existing deployment models that isolate hardware wallets from general-purpose internet-connected infrastructure.

Coinkite's ability to push a firmware update to existing devices depends on whether users can physically access their devices and install patches. The company provides remote telemetry only for the purpose of checking for available updates; the actual installation remains manual. If adoption falls below 30 percent within 60 days, the population of devices running vulnerable firmware would exceed the number already exploited, creating pressure for regulatory intervention or class-action litigation against Coinkite for negligent key derivation practices.