Ledger executive Ian Rogers says the $116 million Coldcard theft shows how AI can amplify weak-randomness failures, rather than proving hardware wallets or self-custody are inherently unsafe.
Key Points:
- A Coldcard seed-generation flaw cut effective entropy to about 40 bits on older devices and roughly 72 bits on newer affected models.
- TRM Labs says theft waves beginning Jul. 30 drained about 1,816 Bitcoin (BTC), worth close to $116 million.
- Rogers argues AI lowers the cost of finding weaknesses, while autonomous agents create new risks when they gain access to credentials and other secrets.
Bitcoin Wallet Flaw
Media reported Aug. 12 that Rogers, Ledger's chief human agency officer, rejected the idea that the incident showed an inherent weakness in hardware wallets. He instead pointed to poor randomness and AI tools that can help attackers search vulnerable systems more efficiently.
Coldcard maker Coinkite said a firmware problem introduced in 2021 caused seed generation to use a software pseudorandom number generator rather than the intended hardware path. Its preliminary estimates put effective entropy near 40 bits on affected Mk2 and Mk3 devices and about 72 bits on newer affected models.
TRM Labs said four theft waves drained roughly 1,816 BTC from more than 5,200 addresses, with losses valued near $116 million. Ledger says its devices generate entropy through a hardware true random number generator inside a certified Secure Element, without a software fallback.
Also Read: XRP Breaks Below $1 While Whales Quietly Scoop Up 380M Tokens
Ian Rogers Warning
Rogers said AI is changing the threat environment in three ways: it gives attackers stronger vulnerability-discovery tools, accelerates software development and expands the number of AI agents with access to sensitive systems.
The third risk extends beyond crypto wallets because enterprise agents may handle email, credentials, payment data and internal communications.
He compared access controls for AI agents to a parent deciding when a teenager should receive car keys, arguing that context should determine when an agent can use sensitive permissions. Ledger is building tools that separate an agent's ability to operate a wallet from control of the private keys.
“Wherever your assets are stored, you should be interested in the level of security that’s protecting them,” Rogers told Bloomberg.
Ledger has raised similar randomness concerns before. Its Donjon security team reported a Trust Wallet browser-extension flaw to the company in November 2022 after finding seed entropy had fallen to 32 bits.
Read Next: Apple Pay Chief Jennifer Bailey Retires After 25 Years At The Company





