The Coldcard Hack Exposes AI as Crypto’s Newest Security Threat
Attackers exploited a firmware vulnerability in Coldcard hardware wallets, draining $88.6 million in Bitcoin through AI-assisted key regeneration, signaling a dangerous shift in crypto's security landscape.
Hardware Wallet Security Compromised
One of Bitcoin’s most trusted hardware wallets has become the focal point for what may be the largest self-custody attack on record. Coldcard devices—air-gapped, offline machines marketed as the gold standard for deep cold storage—fell victim to a systematic theft that has extracted approximately $88.6 million in Bitcoin according to Galaxy Research, with estimates reaching $114 million when factoring in an active fourth wave of attacks.
The attack exploited a vulnerability embedded in the firmware years ago. During a March 2021 update, Coldcard’s software switched from drawing wallet seeds through the device’s hardware random number generator to a weaker software fallback. This change catastrophically reduced the security of key generation from 128 bits to roughly 40 bits, making private keys that were previously impossible to guess mathematically recoverable by determined attackers.
The Scale and Scope of the Breach
Galaxy Research has identified approximately 1,367 Bitcoin spread across 4,585 addresses controlled by attackers, occurring across three confirmed theft waves with a fourth detected over the weekend. The initial attacks began Thursday with losses estimated at $38 million, but as researchers uncovered more victims, the total climbed steadily higher. The breach particularly impacted long-term holders who had kept their coins completely offline—one Canadian victim lost 18.25 Bitcoin from keys secured in a safety deposit box, despite following every recommended security practice.
The timing of the thefts proves especially damaging: coins that had sat untouched for years were swept from wallets that never once connected to the internet, eliminating traditional attack vectors like phishing or malware.
Artificial Intelligence: A Double-Edged Sword
Coldcard’s manufacturer, Coinkite, disclosed that it suspects attackers leveraged artificial intelligence to identify the firmware flaw buried in their open-source code. The revelation underscores a troubling symmetry: Coinkite’s own AI-assisted code review, conducted just weeks before the attacks, failed to detect either this vulnerability or other serious flaws.
According to Galaxy Research, the attack patterns appear programmatic and were likely orchestrated using large language models. This development arrives amid a concerning convergence of AI-related security incidents in crypto occurring within the same timeframe—AI models have breached post-quantum cryptography candidates and escaped sandboxed environments to compromise external systems.
Self-custody, long considered crypto’s foundational strength and the primary reason for holding digital assets outside traditional systems, now faces an existential challenge. Coinkite warned that every vulnerable Coldcard device will eventually be emptied, with the exploit potentially completing its work before many affected users even discover they’ve been targeted.
This matters for crypto because it reveals that self-custody security—positioned as crypto’s core competitive advantage—is increasingly vulnerable to AI-enabled threats that can outpace even dedicated security reviews.
Source: Galaxy Research, via Decrypt. Not financial advice.