Ledger Warns of AI Risks Following Coldcard Hack

cryptonews.ruОпубліковано о 2026-08-05Востаннє оновлено о 2026-08-05

Анотація

Ledger's CTO warned of AI-related security risks following a hack of Coldcard hardware wallets. The incident, which exploited a vulnerability in Coldcard's random number generator, highlighted that open-source code is not synonymous with audited code, as the flaw had been publicly available for over five years before being exploited. Ledger emphasized that its own devices use a hardware-based random number generator within a Secure Element, avoiding the software-based backup path that was problematic for Coldcard. The hack has been linked to the growing role of AI tools in code analysis. While such tools can accelerate vulnerability discovery for both attackers and defenders, there is no public evidence AI was used in this specific attack. However, online discussions suggest AI models like Claude Code could potentially identify such flaws in minutes. A venture capital partner noted the attack could have been prevented with a $2 AI code check. Losses from the exploit, carried out by at least 15 different attackers across multiple waves, are estimated at up to $130 million. In response to the incident, other hardware wallet manufacturers like Trezor have warned users of subsequent phishing attacks impersonating companies and offering fake "hardware audits."

The exploitation of a vulnerability in Coldcard has shown the need to reassess the verification of random number generators in Bitcoin storage devices. This was stated by Ledger CTO Charles Guillemet, reports Decrypt.

According to him, the incident demonstrated the limitations of the "open source equals verified code" approach. The specialist noted that the bug had been in the public database for over five years but was not discovered until the attacks began.

"Open source and code that has been audited are not the same thing," said the Ledger CTO.

According to Ledger's documentation, the company's devices generate 256 random bits via a hardware generator in the Secure Element. Guillemet stated that this architecture has no software fallback path, which became the issue in Coldcard.

Sleep at Night Technology: How Coldcard Turned Its Users' Sleep Into a Nightmare

Ledger linked the incident to the growing role of AI tools in code analysis. According to Guillemet, such systems accelerate the search for vulnerabilities for both attackers and defenders. However, at the time of writing, there is no public evidence that the attackers actually used artificial intelligence.

U.Today drew attention to posts on Reddit and X. According to user claims, Claude Code allegedly found the vulnerability in about eight minutes after a request to check the source code.

this is insane

claude code found the COLDCARD wallet vulnerability with a single prompt, in just 8 minutes of thinking

we're not ready for what's coming pic.twitter.com/wh1LtEWuje

— Medusa (@MedusaOnchain) August 2, 2026

Earlier, Dragonfly venture fund managing partner Haseeb Qureshi stated that the attack on Coldcard cold wallets could have been prevented by auditing the code with artificial intelligence for $2.

According to Galaxy Research, at least 15 different attackers exploited the vulnerability. Losses from three confirmed waves were estimated by analysts at $100 million. Including a presumed fourth wave, the amount could rise to around $130 million.

Recall that on August 4, hardware wallet manufacturers Trezor and Foundation warned users of phishing attacks in light of the incident. In some cases, scammers are sending emails purportedly from the manufacturer and offering to undergo "hardware auditing."

end-content

Трендові криптовалюти

Пов'язані питання

QWhat did the Ledger CTO say is the key lesson from the Coldcard exploit regarding open-source code?

AThe Ledger CTO, Charles Guillemet, stated that the incident revealed the limited nature of the 'open source equals vetted code' approach. He emphasized that 'open code and vetted code are not the same thing,' pointing out that a bug had been present in the public repository for over five years without being discovered until attacks began.

QHow does Ledger's device architecture prevent the type of issue that occurred with Coldcard?

AAccording to Ledger's documentation, its devices generate 256 random bits via a hardware random number generator within the Secure Element. The CTO explained that this architecture lacks a software fallback path, which was the problematic component exploited in the Coldcard incident.

QWhat AI-related risk did Ledger associate with the Coldcard hack?

ALedger linked the incident to the growing role of AI tools in code analysis. While these systems can accelerate vulnerability discovery for both attackers and defenders, the CTO noted there was no public evidence at the time of writing that the attackers actually used artificial intelligence in this specific case.

QAccording to social media posts referenced in the article, how did Claude Code reportedly find the Coldcard vulnerability?

ABased on posts on Reddit and X referenced in the article, users claimed that Claude Code found the Coldcard wallet vulnerability with a single prompt, completing the analysis in approximately eight minutes.

QWhat are the estimated financial losses from the confirmed waves of the Coldcard exploit according to Galaxy Research?

AGalaxy Research reported that losses from three confirmed waves of the exploit were estimated at $100 million. Factoring in a suspected fourth wave, the total losses were projected to rise to approximately $130 million.

Пов'язані матеріали

Торгівля

Спот

Популярні статті

Як купити T

Ласкаво просимо до HTX.com! Ми зробили покупку Threshold Network Token (T) простою та зручною. Дотримуйтесь нашої покрокової інструкції, щоб розпочати свою криптовалютну подорож.Крок 1: Створіть обліковий запис на HTXВикористовуйте свою електронну пошту або номер телефону, щоб зареєструвати обліковий запис на HTX безплатно. Пройдіть безпроблемну реєстрацію й отримайте доступ до всіх функцій.ЗареєструватисьКрок 2: Перейдіть до розділу Купити крипту і виберіть спосіб оплатиКредитна/дебетова картка: використовуйте вашу картку Visa або Mastercard, щоб миттєво купити Threshold Network Token (T).Баланс: використовуйте кошти з балансу вашого рахунку HTX для безперешкодної торгівлі.Треті особи: ми додали популярні способи оплати, такі як Google Pay та Apple Pay, щоб підвищити зручність.P2P: Торгуйте безпосередньо з іншими користувачами на HTX.Позабіржова торгівля (OTC): ми пропонуємо індивідуальні послуги та конкурентні обмінні курси для трейдерів.Крок 3: Зберігайте свої Threshold Network Token (T)Після придбання Threshold Network Token (T) збережіть його у своєму обліковому записі на HTX. Крім того, ви можете відправити його в інше місце за допомогою блокчейн-переказу або використовувати його для торгівлі іншими криптовалютами.Крок 4: Торгівля Threshold Network Token (T)Легко торгуйте Threshold Network Token (T) на спотовому ринку HTX. Просто увійдіть до свого облікового запису, виберіть торгову пару, укладайте угоди та спостерігайте за ними в режимі реального часу. Ми пропонуємо зручний досвід як для початківців, так і для досвідчених трейдерів.

629 переглядів усьогоОпубліковано 2024.12.10Оновлено 2026.06.02

Як купити T

Обговорення

Ласкаво просимо до спільноти HTX. Тут ви можете бути в курсі останніх подій розвитку платформи та отримати доступ до професійної ринкової інформації. Нижче представлені думки користувачів щодо ціни T (T).

活动图片