Coldcard Exploit Sparks Warning on Hardware Wallet Security
A recent exploit of Coldcard's Bitcoin hardware wallet has left the cryptocurrency industry reeling.
The incident exposed weaknesses in how some devices generate cryptographic randomness, and showed how artificial intelligence is reshaping both cyberattacks and digital defenses.
Ledger CTO Charles Guillemet said that the security model of a hardware wallet 'lives or dies on randomness' and that the Coldcard exploit made this visible 'in the most expensive way possible.'
The bug used a software fallback instead of the device's hardware random number generator to create wallet recovery seeds, making some private keys guessable and allowing thieves to steal user Bitcoin.
To date, losses have reached roughly $130 million, with other thefts still under investigation. Coinkite released patched firmware on Sunday and urged affected users to move funds to newly generated wallets.