Coinkite Inc. maker of the Coldcard Bitcoin hardware wallet, is preparing a detailed post-mortem on a recent firmware exploit. The company said it will not speculate on the extent of customer losses, choosing instead to focus on its investigation.
Coinkite's non-disclosure is a deliberate choice, not a technical limitation. By design, Coldcard's privacy architecture prevents the company from independently confirming how much Bitcoin was drained from affected wallets.
Outside researchers estimate total losses from the firmware bug at approximately $130 million—funds removed from Coldcard devices compromised by the vulnerability.
The exploit stemmed from a bug in seed generation within the Coldcard firmware. That flaw allowed attackers to compromise the security of Bitcoin held on affected devices. Coinkite confirmed the wallets were drained late last week and said the company is actively working to assist impacted customers.
In a blog post, Coinkite said AI tools failed to detect the vulnerability—a direct warning to every firm building Bitcoin hardware and software. If your security pipeline runs on automated scanning alone, this incident is your wake-up call.
Coinkite plans to publish its full technical post-mortem once its investigation is complete and disclosure is safe. The report will detail the attack vectors involved.
To aid other developers, Coinkite launched a new resource at coinkite.com/historical-disclosures, cataloging all known public security research, disclosures and advisories related to Coldcard devices.

