$89 Million Crypto Heist Blames AI-Driven Bug
A series of attacks on Coldcard wallets has resulted in the theft of at least $89 million in cryptocurrency, prompting concerns about the security of even the most supposedly secure storage solutions.
The attackers were able to drain users' funds by exploiting a flaw in the algorithm used by the devices, which failed to generate sufficiently random numbers. The devices themselves were not hacked and were not connected to the internet, as is typical with cold storage.
CoinKite Inc., the Canadian company behind Coldcard, has apologized for the flaw and warned users that 'AI-assisted code review can now find latent bugs at a speed that is outpacing even the industry's most seasoned experts.'
The incident has highlighted the risks associated with relying on hardware wallets, which have long been considered safer than leaving digital assets on exchanges. Some observers remain hopeful that the transparent nature of blockchain transactions will make it more difficult for the thieves to convert the stolen assets into cash.