Did AI Actually Help Discover a Security Vulnerability in Coldcard?
A security vulnerability in Coldcard hardware wallets led to a theft of approximately 1,128.5 BTC ($71.1 million at the time). The issue stemmed from a five-year-old firmware configuration error affecting certain Mk3, Mk4, Mk5, and Q devices. This bug caused the devices to use a weak pseudo-random number generator during seed phrase creation, reducing effective entropy to as low as 40 bits instead of the intended 128 bits. This made it computationally feasible for an attacker to brute-force seeds by comparing derived addresses with the Bitcoin blockchain.
Manufacturer Coinkite issued an emergency firmware patch and advised affected users to generate a new seed using the fixed software and transfer their funds. Coinkite's CEO suggested that AI code analysis tools might have been used to discover this long-hidden vulnerability, highlighting a new paradigm in security auditing. However, critics emphasized that the root cause was a human engineering error that traditional code reviews could have caught. The incident underscores the challenges of open-source security, where visibility does not guarantee timely discovery of subtle flaws.
cryptonews.ru4 год тому