Ledger Warns $116M Coldcard Hack Shows AI Can Amplify Wallet Flaws

Alexey Bondarev
Alexey Bondarevpage_time_hoursAgo
A $70M Bitcoin theft tied to Coldcard firmware pushed Ledger and Trezor to insist their own hardware wallets are unaffected. (Image: Shutterstock)
A $70M Bitcoin theft tied to Coldcard firmware pushed Ledger and Trezor to insist their own hardware wallets are unaffected. (Image: Shutterstock)

Ledger executive Ian Rogers says the $116 million Coldcard theft shows how AI can amplify weak-randomness failures, rather than proving hardware wallets or self-custody are inherently unsafe.

Key Points:

  • A Coldcard seed-generation flaw cut effective entropy to about 40 bits on older devices and roughly 72 bits on newer affected models.
  • TRM Labs says theft waves beginning Jul. 30 drained about 1,816 Bitcoin (BTC), worth close to $116 million.
  • Rogers argues AI lowers the cost of finding weaknesses, while autonomous agents create new risks when they gain access to credentials and other secrets.

Bitcoin Wallet Flaw

Media reported Aug. 12 that Rogers, Ledger's chief human agency officer, rejected the idea that the incident showed an inherent weakness in hardware wallets. He instead pointed to poor randomness and AI tools that can help attackers search vulnerable systems more efficiently.

Coldcard maker Coinkite said a firmware problem introduced in 2021 caused seed generation to use a software pseudorandom number generator rather than the intended hardware path. Its preliminary estimates put effective entropy near 40 bits on affected Mk2 and Mk3 devices and about 72 bits on newer affected models.

TRM Labs said four theft waves drained roughly 1,816 BTC from more than 5,200 addresses, with losses valued near $116 million. Ledger says its devices generate entropy through a hardware true random number generator inside a certified Secure Element, without a software fallback.

Also Read: XRP Breaks Below $1 While Whales Quietly Scoop Up 380M Tokens

Ian Rogers Warning

Rogers said AI is changing the threat environment in three ways: it gives attackers stronger vulnerability-discovery tools, accelerates software development and expands the number of AI agents with access to sensitive systems.

The third risk extends beyond crypto wallets because enterprise agents may handle email, credentials, payment data and internal communications.

He compared access controls for AI agents to a parent deciding when a teenager should receive car keys, arguing that context should determine when an agent can use sensitive permissions. Ledger is building tools that separate an agent's ability to operate a wallet from control of the private keys.

“Wherever your assets are stored, you should be interested in the level of security that’s protecting them,” Rogers told Bloomberg.

Ledger has raised similar randomness concerns before. Its Donjon security team reported a Trust Wallet browser-extension flaw to the company in November 2022 after finding seed entropy had fallen to 32 bits.

Read Next: Apple Pay Chief Jennifer Bailey Retires After 25 Years At The Company

Alexey Bondarev profile photo

Alexey Bondarev

Alexey Bondarev is the Head of Content at Yellow.com, having reported on crypto for the last 10 years. He specializes in in-depth Research and Learn pieces, with a focus on analytical reporting, industry context, and the bigger forces shaping crypto, from the AI era and security technologies to fintech innovation. He believes that everything digital will imminently overcome everything analogue and is working hard to make that come true.

page_article_disclaimer
Ledger Warns $116M Coldcard Hack Shows AI Can Amplify Wallet Flaws | Yellow