At least $89 million in Bitcoin has been drained from users of Coldcard hardware wallets, prompting the Canadian manufacturer to warn that a «new AI paradigm» is changing the threat landscape for cryptocurrency security. The company said attackers exploited a flaw in the key-generation software used by the devices, exposing the limits of storage tools that have long been regarded as among the safest ways to hold digital assets.
Hardware wallets are physical devices designed to store the private keys needed to access cryptocurrency. Because they are normally kept offline, a practice known as cold storage, they have traditionally been considered safer than leaving funds on exchanges. In the recent attacks, however, unknown perpetrators were able to determine user keys after discovering that the algorithm used by the wallets did not generate sufficiently random numbers. Coinkite stressed that the devices themselves were not hacked and were not connected to the internet, as is typical for cold storage.
Cryptocurrencies function through distributed ledgers that record transactions, while secret cryptographic keys are used to verify that a transfer was authorized by the legitimate owner. The breach undermined that trust. Rodolfo Novak, chief executive of Coinkite Inc., apologized in a statement on Friday and linked the incident to advances in artificial intelligence. «We believe this is a sober reality of the new AI paradigm,» he wrote. «AI-assisted code review can now find latent bugs at a speed that is outpacing even the industry’s most seasoned experts.» Novak added that any firmware that is open-source or has ever been public should be assumed to be read by attackers and defenders alike.
Coinkite issued its first warning to customers on Thursday, telling them to update the affected firmware, which was originally released in March 2021, and to move their Bitcoin to new accounts protected by newly generated seeds. «Please treat this as urgent, migrate your funds,» the company said. It also asked users to help spread the word, especially to people who are less online and may not see the update, and stressed that the threat was still ongoing.
By Sunday, digital financial platform Galaxy said it had identified three separate waves of attacks against Coldcard users, resulting in the theft of 1,367.05 BTC, worth about $88.6 million at the time. On Monday, it warned of a likely fourth attack and estimated that losses could rise to 2,055 BTC, valued at roughly $130 million.
The incident has raised fresh questions about the assumption that hardware wallets are necessarily safer than centralized cryptocurrency storage services. Although such devices protect against remote hacking while offline, weaknesses in the software layer can still expose funds.
Some industry observers remain hopeful that the transparent nature of blockchain transactions will complicate efforts by the thieves to convert the stolen assets into cash. Since every transaction is recorded on a public ledger, the movement of the stolen Bitcoin can be monitored. «Every transaction will be watched, every movement will be analyzed, every attempt to cash out will attract attention,» one commentator said. Another observer urged the attackers to return the funds and accept a negotiated security bounty with Coinkite, arguing that spending the stolen Bitcoin would be extremely difficult.
