Web3 Wallets in a 'Turbulent Autumn': In the AI Era, How to Understand the Evolution of 'Spear and Shield' in Crypto Security?

marsbitОпубликовано 2026-08-19Обновлено 2026-08-19

Введение

The recent spate of incidents involving Coldcard, Trezor, and SafePal highlights a critical evolution in cryptocurrency wallet security, moving the focus beyond simple private key protection to a holistic, multi-layered attack surface. These events—spanning a random number generator flaw, supply chain data leaks, and plugin permission issues—underscore that vulnerabilities now exist across the entire wallet lifecycle: from secure element and code generation to logistics, user data, and daily interactions with dApps. This broadening threat landscape is accelerating with the advent of AI. Attackers are leveraging AI to automate and scale previously labor-intensive tasks like vulnerability discovery, sophisticated social engineering, and targeted phishing campaigns. This effectively lowers the cost of attacks, eroding the security margin once provided by the high effort required to find and exploit flaws. In response, defense strategies must also evolve by integrating AI. The future of wallet security lies not just in static rules and blacklists, but in proactive, AI-powered risk assessment. This includes pre-transaction simulation, behavioral analysis to detect anomalies (like sudden large approvals), and contextual awareness of dApps and counterparties. The goal is to transform wallets from passive signing tools into active guardians that can understand intent, predict outcomes, and clearly communicate risks to users—all while preserving user sovereignty and control through ...

In the past month, the security nerves of the Crypto community have been on edge again.

First, Coldcard was exposed to have a severe random number generation vulnerability, followed by Trezor and SafePal successively disclosing risk incidents involving user privacy data leaks.

At first glance, these three incidents don't seem to have much in common. However, if we extend the timeline slightly, we find they collectively point to an increasingly important question:

As AI begins to automate vulnerability discovery, attack development, and social engineering, how many places in a crypto wallet might become the next weak spot attackers look for?

1. With AI, Hacking Transforms from "Craftsmanship" to "Industrialization"

Objectively speaking, these three incidents exposed completely different attack surfaces.

Coldcard's issue lies in private key generation, which is a severe security problem; Trezor's problem stemmed from a third-party logistics service, and SafePal's from its order system and plugin permissions, both belonging to risk exposure associated with privacy leaks.

Although there is currently no evidence directly linking all three incidents to AI, it must be admitted that in the AI era, the hacker's "toolbox" is undergoing a massive transformation.

This is because many advanced cyberattacks in the past were fundamentally limited by a very real constraint—human time.

Studying a large codebase, understanding call relationships, and finding hidden logic vulnerabilities required experienced security researchers to invest significant time; collecting identity information on a specific user, researching their habits, and designing a sufficiently credible phishing email even required months to construct a complex social engineering script.

This led to a trade-off in past attacks: Either highly automated but with crude methods, casting a wide net to catch a few users; or meticulously designed for specific high-value targets but difficult to scale and replicate.

However, with AI capabilities rapidly evolving today, the hacker's toolbox has been thoroughly upgraded:

  • Automated Vulnerability Discovery: AI can assist attackers in quickly analyzing smart contracts, client code, and even firmware, automatically seeking zero-day vulnerabilities and logic flaws.
  • Scalable Social Engineering: Previously meticulously crafted phishing emails can now be automatically generated by AI based on leaked user identity data, creating highly customized, extremely persuasive phishing content, SMS, or even audio/video (Extended reading: "Spring Festival Asset Security Handbook: How to Guard Your Tokens While Relaxing with Family and Friends?");
  • Intelligent Attack Execution: From target selection to multi-channel concurrent deployment, the cost of the entire attack chain has dropped to a historical low point;

It can be said that capabilities once dispersed among different attackers—from target screening and vulnerability research to malicious code generation, social engineering, and attack content deployment—are gradually being compressed into a more automated workflow.

This is the truly profound impact of AI on cybersecurity.

It may not suddenly create a previously unseen attack method, but it is rapidly lowering the cost of existing ones—finding a vulnerability is cheaper, analyzing a target is faster, and generating a thousand different versions of phishing emails is also much easier than before.

In other words, the reason many systems weren't attacked in the past wasn't necessarily because vulnerabilities didn't exist, but sometimes because they were too hard to find, the attack cost was too high, or the target wasn't worth the effort. Now, that invisible security boundary that relied on "attackers not having that much time" is gradually thinning.

From this perspective, the security offensive and defensive game for crypto assets is also expanding from the relatively concentrated "private key battle" of the past into a full-chain tug-of-war covering code, devices, supply chains, user identities, and daily interactions.

AI is merely pressing the accelerator further.

2. A Wallet's True Attack Surface Extends Beyond a Recovery Phrase

This is also why looking at these recent events together is particularly representative.

They sequentially hit different positions in a wallet's lifecycle, reminding us that the risks wallets face have long surpassed the single dimension of "whether the private key is stolen," and are embedded in every step—from private key generation, hardware devices, and logistics supply chains to user privacy information.

Let's break it down simply.

Coldcard is the most typical example. Its problem occurred even before users truly started using the wallet.

The recovery phrase might still look like 12 or 24 normal words, the device could sign and transfer normally, and users might not even notice anything abnormal. However, if the random numbers generating this phrase weren't truly random, then even if you never told anyone your recovery phrase, you could still be at risk.

Because the premise of "safely storing the recovery phrase" is that the phrase was first generated in a sufficiently secure and unpredictable manner.

Then there are Trezor and SafePal.

Unlike Coldcard, their hardware itself wasn't compromised, and the recovery phrases remained intact. Yet, user purchase records were leaked—including name, phone number, email, and even shipping address.

This is like buying a top-grade explosion-proof safe. The safe wasn't cracked, but the logistics company's shipping slip was lost, clearly stating your name, email, phone number, address, and that you purchased a hardware wallet specifically for storing crypto assets.

What the attacker obtains is a list of potential high-value Crypto user leads. They can impersonate wallet customer service to send "urgent firmware update" notifications, customize phishing pages based on the purchase model, call claiming order anomalies, or even further associate users' social media, public identities, and on-chain addresses.

In other words, not being able to crack the cryptography doesn't mean an attack is impossible.

There's even an extreme saying circulating in the Crypto community for years—the "$5 Wrench Attack": No matter how strong the encryption algorithm, it cannot solve the problem of an attacker physically locating the asset holder.

This isn't purely a theoretical risk. According to data provided by Chainalysis to the Financial Times, as of mid-August 2026, at least 46 violent attacks targeting Crypto holders have been recorded this year, with kidnappings accounting for over half, and home invasions making up over a third.

So, looking back at these three incidents, we realize that today's so-called "wallet security" has actually become a long chain:

From wallet code, random numbers, and key generation, to chips, firmware, and devices, then to the official website, purchase channels, supply chain, logistics, and order database; after users truly start using it, it connects to RPCs, DApps, browser extensions, and smart contracts, subsequently involving authorizations, signatures, customer service, social media, and even AI Agents.

If any single link becomes the weakest point, it may bypass the security defenses built by all other links.

3. As Attacks Become Automated, Defense Must Integrate AI

If AI continues evolving at its current pace, the problems exposed today are likely just the beginning.

Because one of the things AI excels at is continuously searching for anomalies, repetitive patterns, and weak points within a vast system.

Attackers can have Agents continuously scan open-source code, batch-test websites, APIs, and extension permissions, automatically collect information from social media and public databases, and then filter for potential high-value targets.

Even phishing itself might evolve from the old, monotonous "your wallet is about to expire, please enter your recovery phrase" to real-time conversations that truly understand who you are:

  • If the attacker knows you just purchased a specific hardware wallet model, they can generate a corresponding "firmware security notification" for you;
  • If they know you recently participated in a DeFi protocol, they can impersonate the project team asking you to migrate to a new protocol treasury;
  • If they further obtain your social accounts and public posts, they can even mimic familiar team members, KOLs, or customer service personnel to communicate with you;

From this perspective, an important challenge wallets will face in the future is: when attacks have upgraded from "fixed rules" to systems that can analyze, judge, and adapt, can defense still rely solely on static rules?

After all, previous wallet security mechanisms are still relatively close to a set of "rule libraries": if an address is flagged as phishing, a pop-up reminder appears; if a domain enters a blacklist, access is blocked; if a certain authorization pattern is high-risk, an additional layer of warning is added.

These mechanisms remain important. However, facing increasingly dynamic attacks, relying solely on known past risks to identify the next one is clearly insufficient.

AI can precisely become a very important supplement on the defense side (Extended reading: "As Hackers Use AI 'More Efficiently', How Does the 'Spear and Shield' Arms Race in Web3 Escalate?"). In fact, this isn't a suddenly emerging new proposition.

Previously, in discussions surrounding "AI × Web3 Security," imToken proposed a similar direction: the security capabilities of future wallets should not remain limited to address blacklists, risk labels, and fixed pop-ups. Instead, by leveraging AI, security judgments can be further moved forward into the user's entire transaction process.

For example, before code enters the production environment, AI can continuously review code dependencies, call paths, and anomalous logic; when a user accesses a DApp, AI can combine domain history, frontend behavior, contract addresses, and on-chain relationships to determine if it's abnormal; before signing, it can simulate the actual execution result of a transaction, rather than just showing users a string of hard-to-understand hexadecimal data.

Going a step further, wallets could gradually establish dynamic security models for each user.

An account that has only been making transfers of a few hundred dollars suddenly preparing to approve all assets to a stranger contract deployed just two hours ago is itself an anomaly; an address a user has never interacted with suddenly requesting unlimited Approval should trigger a higher-priority risk warning; and an email claiming to be from the wallet's official source asking for the recovery phrase, no matter how convincingly written, should be directly judged as high-risk.

Thus, the change brought by AI might not just be "automatically helping users judge if an address is safe." It's more like enabling the wallet to gradually develop a layer of proactive risk assessment capability, evolving from a relatively passive key custodian and signing tool.

This also makes another layer of security boundary previously discussed by imToken even more crucial: AI can help users understand and execute complex operations, but asset control rights should not be infinitely surrendered because of it. For critical actions like large transfers, new address authorizations, and sensitive contract interactions, AI's capabilities must still be confined within clear authorization scopes through minimal permissions, human confirmation, pre-execution simulation, and clear explainability.

Especially in truly anomalous situations, clearly telling the user "why it's dangerous," "what will happen after execution," and "where the risk actually lies."

In other words, the significance of AI defense lies in propelling wallets from being passive signing tools to gradually possessing the ability to proactively understand transactions, identify anomalies, and constrain execution.

In Conclusion

The recent series of wallet security incidents do not mean self-custody has lost its value, nor do they mean users should hand over all asset control rights back to centralized platforms.

What they truly remind us is that self-custody never equates to inherent security; it merely returns absolute control of assets to the user.

Protecting this control requires a security system that can evolve with the times and continuously upgrade. Because security is not a one-time product delivery; it's a long-term, dynamic evolution requiring the joint efforts of users, project teams, and wallet manufacturers.

Attackers can use AI to understand code, users, and environments; defenders can do the same.

This will be a prolonged "spear and shield" upgrade race.

Трендовые криптовалюты

Связанные с этим вопросы

QWhat is the main impact of AI on crypto security, according to the article?

AThe main impact is that AI is drastically lowering the cost and complexity of attacks. It automates and scales tasks like vulnerability discovery, social engineering, and attack deployment, shifting attacks from 'artisanal' to 'industrialized.' This thins the security boundary that previously relied on the high cost and time investment required from attackers.

QBesides the private key itself, what other attack vectors for crypto wallets are highlighted in the article?

AThe article highlights that wallet security is a long chain. Key attack vectors include random number generation (like the Coldcard vulnerability), the hardware supply chain, logistics and order databases (leading to privacy leaks as with Trezor and SafePal), and user identity data. This data can enable targeted phishing or even real-world physical attacks ('$5 wrench attack').

QHow can AI be used defensively to improve wallet security, as suggested in the article?

AAI can be used defensively to move beyond static rule-based security. It can proactively analyze code dependencies and logic, assess DApp risks by combining domain history and on-chain behavior, simulate transaction outcomes before signing, and build dynamic user models to detect behavioral anomalies (like sudden large transfers to new contracts). This transforms the wallet into a tool with active risk assessment capabilities.

QWhat does the article imply by the phrase '$5 wrench attack' in the context of crypto security?

AThe '$5 wrench attack' is an extreme example illustrating that strong cryptography cannot protect against physical coercion. It refers to the theoretical (and, according to data cited, practical) risk where an attacker bypasses digital security entirely by physically threatening or attacking the asset holder to obtain their keys or access.

QWhat is the core principle the article emphasizes regarding self-custody and security after discussing recent wallet incidents?

AThe article emphasizes that self-custody does not equate to inherent security. It merely returns absolute control of assets to the user. Protecting that control requires a dynamic, evolving security system—a continuous 'arms race' where defenders must also leverage tools like AI to keep pace with increasingly automated and sophisticated attacks.

Похожее

Глобальный саммит RWA от Websea успешно прошел: фокус на новых возможностях цифровой экономики между Китаем и Казахстаном, сигнал к трансграничной синергии

18 августа 2026 года в Алматы (Казахстан) успешно прошел «Глобальный саммит RWA по выходу компаний на международные рынки и инвестиционно-привлекательная конференция для китайско-казахстанских отраслей», организованный платформой Websea. Мероприятие было посвящено цифровизации реальных активов (RWA), трансграничному промышленному сотрудничеству и привлечению инвестиций, собрав представителей промышленных кругов, инвесторов и экспертов в области цифровой экономики из Китая, Казахстана и других стран. Участники обсудили возможности цифровизации для таких отраслей, как горнодобывающая промышленность, сельское хозяйство, недвижимость и зеленая энергетика. В ходе панельных дискуссий и презентаций проектов особое внимание уделялось повышению прозрачности активов, эффективности сотрудничества и созданию трансграничных связей с помощью технологий. Председатель Федерации специальных экономических зон Казахстана Ербол Карбаев отметил, что RWA — это не просто технологическая концепция, а инструмент для цифровой трансформации отраслей в рамках четкого нормативного регулирования. Саммит также послужил платформой для углубления китайско-казахстанского сотрудничества в области цифровой экономики. Были проведены переговоры о стратегическом партнерстве и подписании соглашений, что способствует переходу от общих планов к конкретным механизмам реализации проектов. Платформа Websea, выступая партнером мероприятия, подчеркнула в своем выступлении важность доверия пользователей, безопасности активов и качества торгового опыта как основы для устойчивого развития в цифровую эпоху. Кроме того, в рамках саммита были запущены такие инициативы, как «Среднеазиатский этап конкурса красоты Web3», «Альянс качественных создателей контента Китая и Казахстана» и агентство Web3 MCN, демонстрируя многогранность формирующейся экосистемы, которая объединяет не только бизнес и капитал, но также технологии, контент и сообщества. Мероприятие обозначило четкий сигнал: будущее цифровой экономики создается совместными усилиями широкого круга участников при поддержке институтов, инфраструктуры и долгосрочных инвестиций. Websea выразила намерение и далее способствовать построению безопасного, открытого и устойчивого цифрового экономического будущего вместе с глобальными пользователями и партнерами.

marsbit19 мин. назад

Глобальный саммит RWA от Websea успешно прошел: фокус на новых возможностях цифровой экономики между Китаем и Казахстаном, сигнал к трансграничной синергии

marsbit19 мин. назад

Спасение казначейских облигаций в «стиле Сороса»: от валютного курса к процентным ставкам. Может ли Бессент победить рынок?

Автор: Лун Юэ | Источник: Wall Street News Бывший управляющий фонда Сороса, а ныне министр финансов США Скотт Бессентт, использует агрессивные рыночные интервенции, чтобы сдерживать доходность казначейских облигаций. Он уже помог провести совместную с Японией валютную интервенцию для поддержки иены в конце июля, а теперь удвоил масштабы выкупа долгосрочных госдолга США. Эти шаги, напоминающие тактику хедж-фондов, направлены на прямое влияние на кривую доходности. Однако экономисты ставят под сомнение эффективность такой тактики. Основная проблема — структурный дефицит бюджета США и растущие расходы на обслуживание долга. Краткосрочные рыночные интервенции не решают этих фундаментальных вопросов. Ранее Бессентт сам критиковал подобные меры как политически мотивированные. Эксперты предупреждают, что, воюя одновременно на фронтах валютного рынка и рынка госдолга, министр ведёт крайне трудную битву, а его методы могут подорвать традиционный принцип Министерства финансов — предсказуемость и прозрачность.

marsbit40 мин. назад

Спасение казначейских облигаций в «стиле Сороса»: от валютного курса к процентным ставкам. Может ли Бессент победить рынок?

marsbit40 мин. назад

Кровопотеря банков России и криптоохота: с начала года граждане сняли из банков 24 миллиарда евро, закон об ограничении суммы покупки криптовалют вступит в силу в ближайшее время

По данным ЦБ РФ, за первые 7 месяцев 2026 года граждане вывели из банковской системы около 244 млрд евро наличными, причем отток ускорился в июле. Одновременно нарастают объемы криптовалютных операций, которые, по оценкам, достигают 500 млрд рублей в день и используются как инструмент сбережений. Чтобы взять под контроль этот процесс, 4 августа президент Путин подписал закон «О цифровых валютах и цифровых правах», основные положения которого вступают в силу 1 сентября. Согласно закону, неквалифицированные инвесторы смогут покупать криптовалюту (пока только Bitcoin, Ethereum и USDT) через лицензированных посредников на сумму не более 30 000 рублей (около 3600 долларов) в год на одну платформу. Квалифицированные инвесторы и компании для внешнеторговых расчетов ограничений не имеют. Власти объясняют отток наличности техническими причинами, такими как рост НДС и сбои в цифровых платежах. Аналитики же связывают его с опасениями населения относительно стабильности банковской системы и возможных ограничений. 1 сентября также стартует пилотный проект по цифровому рублю для физических лиц, что создает третий, полностью контролируемый государством, канал для финансовых операций. Таким образом, возможности рядовых россиян для самостоятельного управления сбережениями сужаются.

marsbit43 мин. назад

Кровопотеря банков России и криптоохота: с начала года граждане сняли из банков 24 миллиарда евро, закон об ограничении суммы покупки криптовалют вступит в силу в ближайшее время

marsbit43 мин. назад

Тихий чемпион «мойки чипов»: японский гигант бытовой химии

Японский гигант бытовой химии Kao, известный своими стиральными порошками и средствами для умывания, стал лидером на рынке высокоточных чистящих средств для полупроводников. Согласно финансовому отчету за первое полугодие 2026 финансового года, доля Kao на рынке чистящих средств для монтажных плат в процессе сборки составляет около 60%, а в некоторых процессах производства NAND-памяти компания занимает первое место. Химический бизнес Kao, включая эту продукцию, показал рост на 9,4%, опережая потребительские товары, и поставляет продукцию таким лидерам, как TSMC, Samsung и Kioxia. История успеха Kao в этой высокотехнологичной области началась в 1990-х годах, когда экологические нормы потребовали замены фреона. Опираясь на многолетний опыт в области управления поверхностными явлениями, полученный при разработке моющих средств, Kao предложила водное чистящее средство CLEANTHROUGH. За последние 30 лет компания расширила линейку продуктов, охватив процессы как до, так и после обработки пластин, включая очистку от частиц, удаление фоторезиста и специализированные составы для сложных процессов упаковки, таких как 2.5D/3D. Ключом к удержанию позиций является глубокое вовлечение в процессы клиентов. Kao открыла центры точной очистки в Японии и Синьчжу (Тайвань), которые позволяют совместно разрабатывать и тестировать процессы, создавая высокие барьеры для замены поставщика. Сейчас компания нацелена на расширение присутствия в области памяти DRAM и логических полупроводников, используя бум производства, вызванный развитием ИИ и advanced packaging. Пример Kao, как и успех Ajinomoto (пленка ABF), TOTO (электростатические патроны) и Nitto Denko (резательная лента), показывает, что победа в нишевых сегментах материалов для полупроводников часто основана на глубокой экспертизе в фундаментальной химии, накопленной в основном бизнесе.

marsbit44 мин. назад

Тихий чемпион «мойки чипов»: японский гигант бытовой химии

marsbit44 мин. назад

Торговля

Спот

Популярные статьи

Как купить ERA

Добро пожаловать на HTX.com! Мы сделали приобретение Caldera (ERA) простым и удобным. Следуйте нашему пошаговому руководству и отправляйтесь в свое крипто-путешествие.Шаг 1: Создайте аккаунт на HTXИспользуйте свой адрес электронной почты или номер телефона, чтобы зарегистрироваться и бесплатно создать аккаунт на HTX. Пройдите удобную регистрацию и откройте для себя весь функционал.Создать аккаунтШаг 2: Перейдите в Купить криптовалюту и выберите свой способ оплатыКредитная/Дебетовая Карта: Используйте свою карту Visa или Mastercard для мгновенной покупки Caldera (ERA).Баланс: Используйте средства с баланса вашего аккаунта HTX для простой торговли.Третьи Лица: Мы добавили популярные способы оплаты, такие как Google Pay и Apple Pay, для повышения удобства.P2P: Торгуйте напрямую с другими пользователями на HTX.Внебиржевая Торговля (OTC): Мы предлагаем индивидуальные услуги и конкурентоспособные обменные курсы для трейдеров.Шаг 3: Хранение Caldera (ERA)После приобретения вами Caldera (ERA) храните их в своем аккаунте на HTX. В качестве альтернативы вы можете отправить их куда-либо с помощью перевода в блокчейне или использовать для торговли с другими криптовалютами.Шаг 4: Торговля Caldera (ERA)С легкостью торгуйте Caldera (ERA) на спотовом рынке HTX. Просто зайдите в свой аккаунт, выберите торговую пару, совершайте сделки и следите за ними в режиме реального времени. Мы предлагаем удобный интерфейс как для начинающих, так и для опытных трейдеров.

993 просмотров всегоОпубликовано 2025.07.17Обновлено 2026.06.02

Как купить ERA

Обсуждения

Добро пожаловать в Сообщество HTX. Здесь вы сможете быть в курсе последних новостей о развитии платформы и получить доступ к профессиональной аналитической информации о рынке. Мнения пользователей о цене на ERA (ERA) представлены ниже.

活动图片