Coldcard 2021 Firmware Flaw Led to Over $100 Million in Bitcoin Theft
Odaily News: A 2021 firmware vulnerability in the Coldcard hardware wallet caused insufficient randomness in some recovery seeds. Since July 30, attackers have moved approximately 1,600 to 1,800 bitcoins from affected wallets, involving thousands of addresses, valued at over $100 million.
Coinkite, the manufacturer of Coldcard, said it must be assumed that someone used AI to review its public firmware. The vulnerability has existed for about five years, and whether AI was involved in the related attacks has not been confirmed.
Shielded Labs researcher Taylor Hornby used a Claude Opus 4.8 audit agent to discover a vulnerability in the Zcash Orchard shielded pool circuit that dates back to 2022, which in testing could generate unlimited counterfeit ZEC without a trace. Developers completed a fix within days, and no theft of coins has been confirmed.
Blockchain analytics firm Chainalysis statistics show that on-chain writes carrying malware instructions and command-and-control information rose from an average of about 2.06 per day to 11.1 per day, an increase of 440%. (Bitcoin.com News)
This content is for informational and educational purposes only and does not constitute investment advice related to BTCC. BTCC makes every effort but cannot guarantee the truthfulness, accuracy, or originality of the content above.