$116M Coldcard Hack Shows How AI Exacerbates Wallet Weaknesses
The $116 million Coldcard hack has raised concerns about the security of self-custody wallets, but Ledger's chief human agency officer Ian Rogers argues that AI amplifies existing weaknesses rather than proving hardware wallets or self-custody are inherently unsafe.
Rogers points out that a seed-generation flaw in older Coldcard devices reduced effective entropy to around 40 bits, while newer affected models had roughly 72 bits. This weakness was exploited by thieves in four waves beginning July 30, draining over 1,816 BTC, worth approximately $116 million.
Coldcard maker Coinkite attributed the issue to a firmware problem introduced in 2021 that used a software pseudorandom number generator instead of the intended hardware path. Ledger emphasizes its own devices generate entropy through a certified Secure Element with a hardware true random number generator, without a software fallback.
Rogers warns that AI is changing the threat environment by providing attackers with stronger vulnerability-discovery tools and accelerating software development. He also notes that autonomous agents can expand access to sensitive systems, highlighting the need for proper controls. Ledger is building tools to separate an agent's ability to operate a wallet from control of private keys.