Coldcard Heist Shows How Weak Randomness and AI Can Combine to Expose Crypto Users
A recent $116 million theft from Coldcard users highlights the risks of weak randomness in wallet generation, which AI can amplify to gain unauthorized access.
Ian Rogers, Ledger's chief human agency officer, argues that the incident demonstrates how AI lowers the cost of finding weaknesses and accelerates software development, rather than proving hardware wallets or self-custody are inherently unsafe.
The theft occurred through a firmware problem introduced in 2021 by Coinkite, which used a software pseudorandom number generator instead of the intended hardware path for seed generation. This reduced effective entropy to around 40 bits on affected Mk2 and Mk3 devices and about 72 bits on newer models.
Rogers emphasizes that AI creates new risks when autonomous agents gain access to credentials and other secrets, extending beyond crypto wallets to enterprise systems handling email, credentials, payment data, and internal communications. He believes access controls for AI agents need to be reevaluated, comparing it to a parent deciding when a teenager should receive car keys.
Ledger is developing tools that separate an agent's ability to operate a wallet from control of the private keys, echoing concerns raised by its Donjon security team in November 2022 after finding seed entropy had fallen to 32 bits in a Trust Wallet browser-extension flaw.