Coldcard Wallet Flaw Leads to $38M in Bitcoin Drained by AI-Exploited Seeds
A hardware wallet maker's admission that its devices' seeds were more guessable than intended has led to an estimated $38 million in Bitcoin being drained. Coinkite, which produces Coldcard wallets, said it believes an attacker used AI on its open-source code to exploit a flaw that was not caught by the company's own AI review weeks earlier.
The issue affected every current model of the wallet, with owners whose devices' firmware is 4.0.1 or later needing to generate new seeds on patched hardware. Updating the firmware did not repair existing seeds.
Coinkite estimated that an attacker could guess a seed on an Mk3 device in about 40 bits of space, compared to the 128 bits a seed should have. The company said extra entropy from secure elements on other models improved their security but still left them vulnerable to attack.