AI-Driven Code Analysis Exposes Weaknesses in Hardware Wallet Security
Coldcard bitcoin thefts have revealed a broader change in cybersecurity, according to Jameson Lopp, co-founder of Casa. The loss of over $83 million in BTC is not just a result of hardware wallet failure, but rather a consequence of the increasing use of artificial intelligence (AI) in software security.
Lopp stated that large language models (LLMs) are changing the security landscape by reducing the cost and time needed to discover software vulnerabilities. This shift has made it easier for attackers to uncover flaws in code, just as it does for developers and defenders.
The Coldcard incident is a result of the company's firmware using predictable chip information instead of proper randomness when generating recovery wallet keys. This allowed cybercriminals to reconstruct the recovery phrases used in the wallets and steal funds without physically accessing them.