AI Audit Reveals Coldcard Vulnerability Linked to $70M BTC Theft in 8 Minutes
Community users utilized AI tools to identify a critical RNG flaw in Coldcard firmware within 8 minutes, tracing it to the theft of $70M in BTC from 1,196 wallets.
Woofun AI reports that Reddit developers employed Claude Code to audit Coldcard open-source firmware, uncovering a critical vulnerability in just 8 minutes. The flaw involved the use of a software pseudo-random number generator instead of a hardware true random number generator for private key creation, which facilitated the theft of approximately $70 million in BTC from 1,196 wallets.
Independent verification using Zhizhu GLM 5.2, a model trained on June 16 without internet access, also detected the issue. This security defect had persisted in the wallet's codebase for more than five years prior to its discovery.
Comments
No comments yet.