A 2021 firmware flaw in hardware wallet maker Coldcard has been tied to a large Bitcoin theft, according to the report cited by Odaily. The issue allegedly reduced randomness in some recovery seeds, and attackers have moved roughly 1,600 to 1,800 BTC from affected wallets since July 30, spanning thousands of addresses and valued at more than $100 million. Coinkite, the company behind Coldcard, said it has to consider the possibility that someone used AI to review its public firmware, though there is still no confirmation that AI played a role in the attack.
The report also pointed to a separate disclosure from Shielded Labs researcher Taylor Hornby, who said an audit agent powered by Claude Opus 4.8 found a vulnerability in the Zcash Orchard shielded pool circuit dating back to 2022. In testing, the flaw could create unlimited counterfeit ZEC without leaving traces. Developers fixed the issue within days, and no theft has been confirmed. Separately, Chainalysis said daily on-chain inscriptions carrying malware instructions and command-and-control information rose from about 2.06 to 11.1, a 440% increase.
A 2021 firmware vulnerability in Coldcard hardware wallets led to insufficient randomness in some recovery seeds, according to Odaily, citing Bitcoin.com News. Since July 30, attackers have moved about 1,600 to 1,800 BTC from affected wallets across thousands of addresses, with the haul valued at more than $100 million.
Coinkite, the manufacturer of Coldcard, said it has to assume that someone may have used AI to inspect its public firmware. Even so, the flaw had existed for about five years, and there is still no confirmation that AI was involved in the attack.
In a separate case, Shielded Labs researcher Taylor Hornby said he used a Claude Opus 4.8 audit agent and found a vulnerability in the Zcash Orchard shielded pool circuit that dated back to 2022. In testing, the bug could generate unlimited counterfeit ZEC without leaving traces. Developers fixed it within days, and no theft has been confirmed.
Blockchain analytics firm Chainalysis said the daily number of on-chain entries carrying malware instructions and command-and-control information rose from about 2.06 to 11.1, an increase of 440%.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.