📅 Kamis, 6 Agustus 2026 · --:-- WIB Ikuti kami
Ecosystem
ID
AI Sedot 2.055 BTC Lewat Celah Kode 5 Tahun Coldcard - CTO Ledger Sebut Label Open Source Bukan Lagi Jaminan Aman

AI Drains 2,055 BTC Through 5-Year Coldcard Code Vulnerability - Ledger CTO Says Open Source Label Is No Longer a Guarantee of Security

Artificial intelligence has helped hackers drain $130 million from Coldcard wallet users. A security vulnerability in the March 2021 firmware release was successfully exploited by attackers, and Galaxy estimates this exploit may have stolen up to 2,055 BTC. According to recent reports, the perpetrators deployed artificial intelligence to scan code, search for configuration flaws, and identify system vulnerabilities at machine speed.

Ledger CTO Charles Guillemet called this chain of events a stark warning for the entire crypto wallet industry. The bug had apparently been hiding in Coldcard’s public code for more than five years before finally being uncovered by hackers. The main issue lies in the use of fallback software instead of a hardware random number generator (hardware RNG) in the wallet’s seed recovery generation process. This vulnerability is what made users’ private keys guessable.

“Open source and reviewed are two different things,” Guillemet emphasized. He highlighted that public availability of code does not automatically guarantee it is free of vulnerabilities, especially when attackers now deploy sophisticated tools that never tire of searching for errors. Coldcard’s creator, Coinkite, has released a firmware fix and urged users to immediately move their remaining funds to a new wallet.

Who Is Reading Your Code Today?

The trend of hunting for security vulnerabilities using AI proves that bad actors now hold a much more efficient weapon to dissect codebases. Last May, security researchers used the AI model Claude Opus 4.8 to find a four-year-old bug in the Zcash network. The vulnerability, which could potentially trigger infinite coin minting, immediately pushed the price of Zcash down by 40% in a single day.

With the effectiveness of AI proven in the Coldcard case, Coinbase’s advisory board estimates that approximately 7 million Bitcoins are potentially vulnerable. This risk is exposed through public keys being revealed and the habit of reusing the same wallet addresses.

Genuine Hardware vs Fallback Software

To anticipate similar threats, Ledger claims their product line is unaffected. Guillemet explained that their wallets draw the seed phrase from a genuine hardware RNG embedded directly within a certified Secure Element, without ever relying on fallback software. The company also revealed that it has been combining AI capabilities with a team of human security engineers for two years to review their own code in order to stay ahead of hackers.

This hundred-million-dollar exploit highlights a major shift in how bug hunters work. When machines can dissect thousands of lines of open-source code in seconds, defense models relying solely on open-source status begin to crumble.

For crypto asset owners, this is a signal that storing coins even in a hardware wallet demands extra vigilance. If a vulnerability can persist for five years in the open without any human noticing it, you can no longer simply rely on the safety labels in brochures. Even the smallest updates now determine who finds the entry point first - the company’s engineers or the hackers’ cracking machines.

As reported by Decrypt.


Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.

Bagikan artikel ini:
📩 KABAR BITCOIN 1 MENIT

Berita kripto harian, langsung ke inbox

Ringkasan 1 menit untuk kamu yang selalu bergerak. Gratis, kapan saja bisa berhenti.

Total
0
Share