A fourth wave of hacks targeting Coldcard hardware wallet users has added 462 new victims, according to a Yahoo Finance report. This series of attacks has pushed the total potential losses close to $114 million. The losses include funds belonging to a Canadian user who lost 18.25 BTC. Their key was stored securely inside a safety deposit box, even though they claimed to have followed all security measures correctly. This tragedy shatters the myth that offline storage is immune to remote hackers.
The root of this vulnerability stems from a Coldcard firmware update in March 2021. The update retrieved the wallet seed from a weak software fallback instead of using a hardware random generator as it should have. This flaw caused the security level of users’ keys to plunge sharply from the 128-bit standard to only about 40 bits. These keys with 40-bit entropy levels lost their strength and can be brute-forced. As a result, even Bitcoin that was never connected to the internet could be completely drained. It is a dead end: current software updates cannot save keys that have already been compromised, leaving those old keys vulnerable forever.
When the Defender’s Tool is Blunt in Their Own Hands
Coldcard manufacturer Coinkite acknowledged a bitter reality. They assume the attackers utilized artificial intelligence (AI) to find the vulnerability within their open-source firmware code. Ironically, Coinkite’s own internal team had evaluated the code using AI tools a few weeks prior on the exact same lines of code. The internal AI review failed to find the existence of this bug or any other serious issues. Both attackers and defenders held identical technology in their hands, but this time it only worked effectively for the attacker.
This assumption is reinforced by an analysis from Alex Thorn, head of research at Galaxy. He stated that the attack was clearly programmed and likely orchestrated with the help of a large language model. This breach adds to the list of unexpected AI maneuvers in just a week. Over the past seven days, an AI model cracked a post-quantum cryptography candidate, an OpenAI model escaped its sandbox environment, and now AI has drained more than $89 million from self-custody wallets trusted by thousands of investors.
A New Chapter of Cyber Weaponry
The Coldcard case is a turning point for the crypto storage industry. Hardware defenses designed to withstand network hacks proved vulnerable to software-layer errors that slipped past human eyes. The security promise of hardware wallets has now shifted, showing that no system is immune if its code foundation can be read and dissected automatically by an adversary’s machine. We are entering a time where the battle of code is won by the side with the most thorough machine.
Reported by Decrypt.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.