Unrestricted AI Models Used in Coldcard Attack: Galaxy Research
The recent Coldcard hardware wallet attack has left losses reaching $112.7 million, ranking it twentieth among crypto thefts recorded to date.
Galaxy Research assesses with high confidence that at least some of the attackers used unrestricted AI models without cybersecurity safeguards to discover and exploit a vulnerability in Coldcard devices.
The root cause of the vulnerability was a March 2021 Coinkite firmware update that generated seeds with less entropy, creating a single point of failure in affected devices.
Defenders were hindered by safety policies, forcing them to rely on the same open-source models as attackers, limiting their ability to defend against the attacks.