from CoinKite X Account
To all Coinkite users and the entire Bitcoin community,
To all Coinkite users and the entire Bitcoin community,
I'm sorry and I'm devastated. Our team is heartbroken about yesterday's news.
As a team that has dedicated our lives to securing the Bitcoin held by millions of individuals, businesses, and families, this is our core responsibility, and we fell short.
If you know anyone who owns a Coldcard, please make sure they see this. Some affected users may not be watching social media right now, and every hour matters. We do not store customer information, and would appreciate all assistance in reaching affected users.
If you generated a seed using a Coldcard wallet, move your funds now, using our updated best practices, before reading further.
We take full accountability for the firmware bug and we offer our sincere apologies to those affected. We continue to work 24/7 to understand and fully scope the extent of the issue.
What we're doing today:
We've shipped a firmware hotfix that removes the software fallback path entirely. This protects new seeds going forward. It does not fix seeds that were already generated on vulnerable firmware. If your seed was generated before the fix, it needs to be individually migrated to a new seed. A firmware update alone cannot do that for you.
We will publish a full technical writeup of how the bug entered the codebase and why our own review process didn't catch it once we've verified every detail. We would rather be accurate than fast on the technical postmortem, even though we know people want answers now.
We will publish updates at https://blog.coinkite.com/ as we learn more. We do not have full attribution or scope of the issue yet, and we won't speculate until our full technical evaluation is complete.
We are committed to working with affected users who want to pursue a police report, insurance claim, or their own investigation. We will provide a written incident summary specific to your loss and any transaction data we can share. We are cooperating fully with the on-chain investigators and any law enforcement agency that opens a case.
We know an apology doesn't return anyone's funds. We know we'll have to earn back our users' trust. That starts with being open and telling the truth about how this happened.
To every other developer: we believe this is a sober reality of the new AI paradigm. AI-assisted code review can now find latent bugs at a speed that is outpacing even the industry’s most seasoned experts. If your firmware is open-source or has ever been public, assume it's already being read by attackers and defenders alike.
We started Coinkite because we believed in Bitcoin and in people's right to hold their own keys. We remain committed to doing everything going forward in the best interest of the Bitcoin project, the industry, and our users.
nvk,
coinkite
