AI-Enhanced Hackers Drain $116M from Coldcard Users
A recent $116 million theft from Coldcard users has highlighted how AI can exploit weaknesses in wallet security. According to Ledger's chief human agency officer, Ian Rogers, this incident shows that AI can amplify existing flaws rather than proving that hardware wallets or self-custody are inherently unsafe.
The Coldcard seed-generation flaw was found to have reduced effective entropy to about 40 bits on older devices and roughly 72 bits on newer affected models. TRM Labs reported four theft waves beginning July 30, which drained around 1,816 Bitcoin (BTC) worth close to $116 million from over 5,200 addresses.
Rogers argued that AI gives attackers stronger vulnerability-discovery tools, accelerates software development, and expands the number of AI agents with access to sensitive systems. He also compared access controls for AI agents to a parent deciding when a teenager should receive car keys, suggesting that context should determine when an agent can use sensitive permissions.