Developers and security researchers say that Anthropic’s Claude Code identified a security vulnerability related to a recent attack in the Coldcard hardware wallet’s source code in just about eight minutes. This case has reignited market interest in AI’s ability to assist with cryptocurrency security audits.
The vulnerability points to the random number generator.
Reports indicate that the issue lies in how certain Coldcard firmware generates cryptographic random numbers. For cryptocurrency wallets, random numbers are used to generate private keys and digital signatures, making them one of the most critical security components.
If the random number is predictable or lacks sufficient entropy, an attacker could use this to derive the private key and transfer assets from the wallet. This is why such vulnerabilities carry such high risk.
Losses have exceeded $100 million
This vulnerability has been linked to one of the largest security incidents in the history of Bitcoin hardware wallets. Initial estimates suggest that the attacker stole over 1,080 BTC in less than an hour.
- Initial estimated theft amount: Over 1,080 BTC
- Time of occurrence: Less than 1 hour
- Community's latest estimate: Losses exceed $100 million
Subsequently, community estimates raised the total loss to over $100 million. According to reports, this figure still comes from community statistics, and a more comprehensive official summary has not yet been released.
Suspicious transactions are still occurring.
Researcher Thorn stated that between Bitcoin blocks 960,778 and 960,792, 218 suspicious transactions occurred on-chain, affecting 462 victim addresses and transferring nearly 389 BTC.
- Suspicious transactions: 218
- Addresses involved: 462
- Involved funds: approximately 389 BTC
He advised Coldcard users to promptly transfer any remaining assets from affected devices and increase transaction fees to prioritize confirmation, reducing the risk of funds being stolen again by attackers.

