Coldcard has released a firmware update following a $114 million bitcoin theft, identifying additional unrelated bugs in the process – though the update cannot secure already-compromised wallets, according to CoinDesk.
The wallet manufacturer investigated its code for three weeks after the theft, uncovering issues separate from the exploited flaw. Despite fixes, users who fell victim to the attack cannot recover lost funds by updating, according to the report.
KEY FACTS
- Coldcard shipped a firmware update after a $114 million bitcoin theft.
- Three weeks of review found unrelated bugs, not the exploited flaw.
- AI reportedly assisted in identifying additional vulnerabilities.
- Updating cannot restore stolen funds or secure compromised wallets.
What Did the Review Find?
The three-week audit reportedly detected coding issues unrelated to the vulnerability that enabled the theft. While no specifics about these bugs were provided, Coldcard employed AI tools to assist in the review process, according to CoinDesk.
What Does the Update Do?
The new firmware addresses unrelated flaws but offers no recourse for affected users. The update cannot retroactively secure wallets compromised in the $114 million theft or recover lost bitcoin. The vulnerability itself remains unpatched in the announcement.
WHAT WE KNOW – AND WHAT WE DON’T
Verified by the source:
- Coldcard deployed firmware after the $114M theft incident
- Three-week code review found unrelated bugs
- AI tools assisted in bug detection
Still unconfirmed:
- The technical nature of the exploited flaw
- Whether the unrelated bugs could enable future thefts
- The identities of affected users
WHY IT MATTERS
Hardware wallet security remains paramount as cryptocurrency thefts escalate globally. This incident underscores both the value of proactive audits and the irreversible nature of blockchain theft – vulnerabilities can have permanent consequences despite later fixes.
WHAT TO WATCH
Whether future updates address the original exploit, and if Coldcard discloses technical details about either the theft vulnerability or the unrelated bugs found during review.