
Attackers used frontier AI to find a seed-generation flaw in Coldcard wallets, stealing nearly $89 million. Security experts say the theft shows why static reviews are no longer enough.
Nearly $89 million disappeared from thousands of Bitcoin addresses linked to Coldcard hardware wallets on Thursday, July 30. The attackers did not break Bitcoin's cryptography or penetrate an air-gapped device. Instead, they identified a software defect using frontier artificial intelligence, Coinkite said.
Coinkite, the company behind Coldcard, said the problem originated in a 2021 software migration. Seed generation was routed away from the intended hardware random-number generator and toward a software fallback in a MicroPython component. The cryptographic library itself was sound. The integration was not.
Because the Coldcard source code is public, Coinkite assumes someone used frontier AI to review older firmware and find the issue. The flaw reduced the universe of possible private keys enough to make them searchable offline.
For banks, wallet providers and financial infrastructure firms, the incident reinforces a view among security analysts: code that passed an audit three years ago may need reexamination. Firmware and open-source dependencies must be treated as living attack surfaces. Random-number generation, too, requires constant scrutiny, the analysts said.
Software vulnerabilities have always existed. What is changing is the cost of finding them, the analysts said.
Professor Scott Aaronson, scientific adviser at StarkWare, told PYMNTS in February: "The time to start thinking about migrating to quantum-resistant methods of encryption is now."
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.