ChainCatcher reported that a developer on Reddit used Claude Code to scan Coldcard’s open-source firmware and identified the core issue within eight minutes. According to the report, the firmware used a software pseudo-random number generator instead of a hardware true random number generator when generating private keys. The report said that flaw led to the theft of BTC from 1,196 wallets, with losses totaling about $70 million. It also said a community user independently found the same issue by scanning the code with Zhipu GLM 5.2, a model trained on June 16 and not connected to the internet. The bug, according to the report, had existed in the open-source wallet code for more than five years.
ChainCatcher reported that a developer on Reddit used Claude Code to scan Coldcard’s open-source firmware and identified what the report described as the core flaw within eight minutes.
According to the report, the firmware called a software pseudo-random number generator rather than a hardware true random number generator when generating private keys. ChainCatcher said that flaw led to the theft of BTC from 1,196 wallets, with losses totaling about $70 million.
The report also said community users found the same issue through a separate scan using Zhipu GLM 5.2. The model was described as having been trained on June 16 and not connected to the internet.
ChainCatcher added that the bug had been present in the open-source wallet code for more than five years.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.