$116M Coldcard Hack Exposes AI's Power to Amplify Wallet Weaknesses
A recent hack of Coldcard wallets has resulted in the theft of approximately $116 million worth of Bitcoin, with losses valued at around 1,816 BTC. The incident highlights the potential risks posed by artificial intelligence (AI) amplifying weaknesses in wallet security.
Ian Rogers, a Ledger executive, suggests that AI can accelerate vulnerability discovery and make it easier for attackers to exploit weak randomness in wallet generation, rather than indicating an inherent flaw in hardware wallets or self-custody.
The Coldcard hack is attributed to a seed-generation flaw that reduced effective entropy on older devices to about 40 bits and roughly 72 bits on newer affected models. This vulnerability was caused by a firmware problem introduced in 2021, which used a software pseudorandom number generator instead of the intended hardware path.
Rogers emphasizes that AI is changing the threat environment in three ways: it provides attackers with stronger tools for discovering vulnerabilities, accelerates software development, and expands the number of AI agents with access to sensitive systems. He warns that context should determine when an agent can use sensitive permissions, comparing access controls for AI agents to a parent deciding when a teenager should receive car keys.
As a result, Ledger is building tools to separate an agent's ability to operate a wallet from control of the private keys. Rogers advises that users should be interested in the level of security protecting their assets, regardless of where they are stored.