Coldcard firmware flaw tied to theft of roughly 1,600 to 1,800 BTC, report says

Coldcard firmware flaw tied to theft of roughly 1,600 to 1,800 BTC, report says

N
News Editor
2026-09-20 05:41:52
A 2021 firmware flaw in hardware wallet maker Coldcard left some recovery seeds with insufficient randomness, and attackers have drained roughly 1,600 to 1,800 Bitcoin from affected wallets since July 30, according to ChainCatcher. The stolen funds span thousands of addresses and are valued at more than $100 million. Coldcard manufacturer Coinkite said it must assume someone used AI to review its public firmware, though there is still no confirmation that AI was involved in the attack itself. The report also cited a separate finding from Shielded Labs researcher Taylor Hornby, who used a Claude Opus 4.8 auditing agent to identify a Zcash Orchard shielded pool circuit flaw dating back to 2022. In testing, the bug could generate unlimited counterfeit ZEC without leaving traces. Developers fixed that issue within days, and no theft has been confirmed. Chainalysis data in the same report showed that on-chain insertions carrying malware instructions and command-and-control information rose from about 2.06 per day to 11.1 per day, a 440% increase.

ChainCatcher reported that a 2021 firmware flaw in Coldcard hardware wallets left some recovery seeds with insufficient randomness. Since July 30, attackers have moved roughly 1,600 to 1,800 Bitcoin from affected wallets, spanning thousands of addresses and valued at more than $100 million.

Coldcard manufacturer Coinkite said it has to assume that someone used AI to review its public firmware. The flaw had existed for about five years, though there is still no confirmation that AI played a role in the attack.

Zcash issue fixed within days

Shielded Labs researcher Taylor Hornby said he used a Claude Opus 4.8 auditing agent to find a vulnerability in the Zcash Orchard shielded pool circuit that dated back to 2022. In testing, the flaw could produce unlimited counterfeit ZEC without leaving traces. Developers fixed the issue within days, and no theft has been confirmed.

Chainalysis data shows rise in malicious on-chain inserts

Blockchain analytics firm Chainalysis said the daily average number of on-chain writes carrying malware instructions and command-and-control information rose from about 2.06 to 11.1, an increase of 440%.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
3600

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.