Post by Augustine Chiagozie (@pabloexchange)
๐ Coldcard Firmware Bug Led to $38M Bitcoin Drain in 25 Minutes
A build error in Coldcard hardware wallet firmware exposed roughly 500 wallets to a critical seed generation vulnerability, resulting in the theft of 594 BTC โ approximately $38 million โ in under 25 minutes.
Coinkite, the maker of Coldcard, disclosed that the flaw reduced wallet seed entropy from 128 bits to just 40 bits, making private keys far easier to brute-force. The company said an attacker used AI to identify the vulnerability โ a flaw that Coinkite's own AI-assisted code review had failed to catch.
The incident highlights growing risks in firmware supply chains and the emerging role of AI as both a security tool and an attack vector in crypto. Coldcard is a widely used hardware wallet among Bitcoin self-custody users.
0 likes ยท 0 comments ยท 0 shares