$116M Coldcard Heist Highlights AI's Amplification of System Weaknesses
Recently, a $116 million heist from Coldcard wallets has left the crypto community reeling. According to Ledger executive Ian Rogers, the theft highlights how AI can amplify vulnerabilities in systems, rather than proving that hardware wallets or self-custody are inherently insecure.
The issue lies in a seed-generation flaw that affected older devices, reducing effective entropy to around 40 bits, and newer models, which saw roughly 72 bits. This weakness was exploited by hackers who drained over $116 million from more than 5,200 addresses through four separate theft waves beginning July 30.
Rogers argues that AI lowers the cost of finding weaknesses, making it easier for attackers to target systems. He also warns that autonomous agents can create new risks when they gain access to sensitive information and credentials.
Coinkite, the maker of Coldcard, has acknowledged a firmware problem introduced in 2021, which caused seed generation to rely on a software pseudorandom number generator instead of the intended hardware path. Ledger, on the other hand, generates entropy through a hardware true random number generator inside a certified Secure Element.
Rogers emphasizes that AI is changing the threat landscape in three key ways: it provides attackers with stronger vulnerability-discovery tools, accelerates software development, and expands the number of AI agents with access to sensitive systems. He cautions that context should determine when an agent can use sensitive permissions and suggests building tools that separate an agent's ability to operate a wallet from control of private keys.