Coldcard firmware vulnerability leads to over $100 million in Bitcoin theft
A 2021 firmware vulnerability in Coldcard hardware wallets resulted in insufficient randomness for recovery seeds. Since July 30, attackers have drained approximately 1,600 to 1,800 Bitcoin from affected wallets, impacting thousands of addresses with a value exceeding $100 million. Manufacturer Coinkite suggests the possibility of AI-assisted exploitation of public firmware. Separately, researcher Taylor Hornby discovered a 2022 vulnerability in the Zcash Orchard shielded pool using an AI audit agent, which could have allowed for the creation of counterfeit ZEC, though no theft was confirmed. Chainalysis reports a 440% increase in on-chain malicious software activity.
Summaries are written by AI from the original article. Not investment advice.