Ledger: Coldcard Vulnerability Losses Reach Approximately $130 Million, Hardware Wallet Security Needs to Adapt to AI
2026-08-04 21:17
Odaily Planet Daily News Hardware wallet manufacturer Ledger stated that the recent Coldcard vulnerability shows the hardware Bitcoin wallet industry needs to reassess its security model. Ledger CTO Charles Guillemet stated that Ledger devices were not affected, and their recovery phrases are generated by a hardware random number generator built into a certified secure element.
Coldcard manufacturer Coinkite disclosed last week that the isolated Coldcard Bitcoin hardware wallet has a vulnerability traceable to firmware versions from March 2021. The vulnerability uses a software fallback mechanism to generate wallet recovery seeds, causing some private keys to be guessable, with related losses reaching approximately $130 million.
Coinkite has released a fixed firmware on Sunday and urged affected users to transfer funds to newly generated wallets. Charles Guillemet stated that open source is different from being audited. This flaw has existed in the public code for more than five years, and AI is enabling attackers to scan code and identify vulnerabilities at machine speed.
Charles Guillemet also stated that over the past two years, Ledger has combined AI with security engineers and cryptography experts to review code and identify vulnerabilities. He believes that when evaluating hardware wallets, users should understand how randomness is generated and whether that process is independently certified.
Coldcard manufacturer Coinkite disclosed last week that the isolated Coldcard Bitcoin hardware wallet has a vulnerability traceable to firmware versions from March 2021. The vulnerability uses a software fallback mechanism to generate wallet recovery seeds, causing some private keys to be guessable, with related losses reaching approximately $130 million.
Coinkite has released a fixed firmware on Sunday and urged affected users to transfer funds to newly generated wallets. Charles Guillemet stated that open source is different from being audited. This flaw has existed in the public code for more than five years, and AI is enabling attackers to scan code and identify vulnerabilities at machine speed.
Charles Guillemet also stated that over the past two years, Ledger has combined AI with security engineers and cryptography experts to review code and identify vulnerabilities. He believes that when evaluating hardware wallets, users should understand how randomness is generated and whether that process is independently certified.
