The exploitation of a vulnerability in Coldcard has shown the need to reassess the verification of random number generators in Bitcoin storage devices. This was stated by Ledger CTO Charles Guillemet, reports Decrypt.
According to him, the incident demonstrated the limitations of the "open source equals verified code" approach. The specialist noted that the bug had been in the public database for over five years but was not discovered until the attacks began.
"Open source and code that has been audited are not the same thing," said the Ledger CTO.
According to Ledger's documentation, the company's devices generate 256 random bits via a hardware generator in the Secure Element. Guillemet stated that this architecture has no software fallback path, which became the issue in Coldcard.
Sleep at Night Technology: How Coldcard Turned Its Users' Sleep Into a Nightmare
Ledger linked the incident to the growing role of AI tools in code analysis. According to Guillemet, such systems accelerate the search for vulnerabilities for both attackers and defenders. However, at the time of writing, there is no public evidence that the attackers actually used artificial intelligence.
U.Today drew attention to posts on Reddit and X. According to user claims, Claude Code allegedly found the vulnerability in about eight minutes after a request to check the source code.
this is insane
— Medusa (@MedusaOnchain) August 2, 2026
claude code found the COLDCARD wallet vulnerability with a single prompt, in just 8 minutes of thinking
we're not ready for what's coming pic.twitter.com/wh1LtEWuje
Earlier, Dragonfly venture fund managing partner Haseeb Qureshi stated that the attack on Coldcard cold wallets could have been prevented by auditing the code with artificial intelligence for $2.
According to Galaxy Research, at least 15 different attackers exploited the vulnerability. Losses from three confirmed waves were estimated by analysts at $100 million. Including a presumed fourth wave, the amount could rise to around $130 million.
Recall that on August 4, hardware wallet manufacturers Trezor and Foundation warned users of phishing attacks in light of the incident. In some cases, scammers are sending emails purportedly from the manufacturer and offering to undergo "hardware auditing."
end-content





