Ledger Executive Blames AI Attackers for Coldcard Hack, Not Hardware Wallets
The recent $116 million hack of Coldcard has left many in the crypto community wondering if hardware wallets are secure. However, Ledger's top security executive, Ian Rogers, says that's not the issue. According to Rogers, AI-powered attackers are the real problem.
Rogers pointed out that the Coldcard vulnerability was due to a 2021 firmware bug that used a software pseudorandom number generator instead of the device's hardware chip. This produced entropy of roughly 40 to 72 bits, which is a small enough address space for an AI-powered attacker to scan systematically and locate private keys.
Ledger generates entropy entirely in hardware, using a certified secure chip with no software fallback. As Rogers put it, 'the number three with 67 zeros behind it' - no attacker can brute-force that. In fact, Ledger has caught similar flaws before, including one in Trust Wallet in 2022.
Rogers warned of the compounding threats posed by AI, citing attacks on US water infrastructure and the expansion of the attack surface due to faster code deployment. He also highlighted the dangers of enterprises deploying agents that hold access to internal secrets like email, Slack, and credentials.