A firmware flaw in Coinkite’s Coldcard hardware wallets, present since a March 2021 update, caused affected devices to bypass their dedicated hardware random-number generator and use a predictable software substitute when generating seed phrases, sharply reducing key entropy. Beginning around July 30, 2026, attackers exploited the flaw to drain roughly 1,596 bitcoin, worth about $140 million, from more than 7,000 addresses within hours. Coinkite says it had run AI-assisted code review against the affected firmware in the weeks before the exploit and it failed to catch the bug, and the company believes the attackers used AI tools to discover the flaw in its open-source code.