Coldcard 2021 Firmware Vulnerability Led to Over $100 Million in Bitcoin Theft
Odaily News: A 2021 firmware vulnerability in the hardware wallet Coldcard resulted in insufficient randomness in some recovered seeds. Since July 30, attackers have transferred approximately 1,600 to 1,800 BTC from affected wallets, involving thousands of addresses, with an estimated value exceeding $100 million.
Coldcard manufacturer Coinkite stated that it must be assumed that someone used AI to review its public firmware. The vulnerability has existed for about five years, and whether AI was involved in the related attacks has not yet been confirmed.
Shielded Labs researcher Taylor Hornby used a Claude Opus 4.8 audit agent and discovered a vulnerability in the Zcash Orchard shielded pool circuit dating back to 2022, which in testing could generate unlimited counterfeit ZEC without a trace. Developers completed the fix within days, and no theft of coins has been confirmed.
Statistics from blockchain analytics firm Chainalysis show that on-chain writes carrying malware instructions and command-and-control information rose from about 2.06 per day to 11.1 per day, an increase of 440%. (Bitcoin.com News)
