Coldcard Vulnerability Losses Reach $130M, Highlighting AI-Driven Security Risks
Approximately $130M lost due to Coldcard firmware flaw allowing seed prediction. Ledger CTO warns AI accelerates code scanning, urging industry to adopt certified secure elements.
Woofun AI reports that Coinkite disclosed a vulnerability in Coldcard Bitcoin hardware wallets, traceable to firmware from March 2021, which allowed attackers to guess private keys via a software fallback mechanism. This flaw resulted in losses totaling approximately $130 million, prompting the release of fixed firmware and urgent migration instructions for affected users.
Ledger CTO Charles Guillemet stated that Ledger devices remain unaffected because their recovery phrases are generated by a hardware random number generator within a certified secure element. He emphasized that open-source code is not equivalent to audited security, noting that the Coldcard flaw persisted in public code for over five years. Guillemet added that AI now enables attackers to scan code at machine speed, while Ledger has integrated AI with security experts to review code and identify vulnerabilities over the past two years.
Comments
No comments yet.