AI Audit Uncovers Critical Coldcard Wallet Vulnerability in 8 Minutes

iconTechFlow
Share
AI summary iconSummary
A recent AI audit flagged a critical vulnerability in the Coldcard wallet’s firmware. A Reddit developer used Claude Code to identify the flaw in just eight minutes, revealing that a software-based random number generator had been used for private key generation. This error resulted in a $70 million BTC theft across 1,196 wallets. Another user confirmed the issue using Zhipu GLM 5.2. The bug had existed in the code for over five years. The incident underscores the growing focus on security risks in open-source projects amid the rising intersection of AI and cryptocurrency.

On Reddit, a developer used Claude Code to scan the Coldcard open-source firmware and identified the core issue in just 8 minutes: The firmware used a software-based pseudo-random number generator instead of a hardware true random number generator when generating private keys—a vulnerability that led to the theft of approximately $70 million in BTC across 1,196 wallets. Additionally, community members reported that Zhipu GLM 5.2 (trained on June 16, offline) independently detected the same vulnerability. This bug had existed in the open-source wallet code for over five years.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.