Coldcard Hack Losses Top $130 Million as AI Fails to Detect Vulnerability
A major vulnerability in Coinkite's high-security Coldcard hardware wallets has led to losses exceeding $130 million, with attacks still ongoing. The company announced that even advanced AI models failed to detect the software vulnerability responsible for the theft of user funds.
The hack unfolded as follows: a flaw in the algorithm caused the 'seed phrase', used to access a wallet, to be generated in a way that enabled attackers to deduce the wallet's location. They then cross-referenced public blockchain data to identify where assets were stored, obtained the private keys, and transferred the funds.
The affected firmware versions Mk2/Mk3 were initially released in March 2021, and versions 4.0.1 through 4.1.9 contained a compilation configuration error: hardware-based true random number generation was silently bypassed, and predictable software-based pseudo-random numbers were used instead to generate seed phrases.
Coinkite's CEO Rodolfo Novak apologized on social media, stating 'The company takes full responsibility for the firmware error.'