AI-Driven Hackers Drain $38M From 500 Dormant BTC Wallets
Coldcard users lost an estimated $38 million in Bitcoin after a sophisticated attack on their hardware wallets. The breach, which occurred over just 25 minutes, affected approximately 500 dormant wallets and targeted seed phrase exploits.
The attackers are believed to have used AI to discover the vulnerability, with Coinkite stating that they were unable to detect it using their 'best available AI models' even a few weeks prior. This exploit is particularly concerning as it allowed the thieves to move BTC from single-signature addresses into a single address in a matter of minutes.
Coinkite has since confirmed that its Mk3 wallet, and subsequently updated versions beyond March 2021 (version 4.0.1), may not have been generating truly random numbers. Instead, the firmware fell back to Yasmarang, a pseudo-random number generator never intended for real-world cryptographic protection.
Coldcard's maker has issued an advisory, instructing users to take immediate action and update their wallets as necessary. The full extent of the damage is still being assessed, with some reports suggesting that the attackers may continue to exploit this vulnerability.