Ledger Chief Technology Officer Charles Guillemet said the Coldcard vulnerability incident exposed a core weakness in hardware wallet design: random number generation. Speaking in comments cited by Decrypt, Guillemet said the security model of a hardware wallet can live or die on the quality of its randomness, calling the incident proof delivered in the most expensive way possible.
Ledger said its own devices were not affected. The company said mnemonic phrases on its hardware wallets are generated by a hardware random number generator inside a certified secure element, with no software fallback path, and that each generation produces a full 256 bits of randomness.
Guillemet also argued that open-source code should not be treated as automatically secure if it has not been thoroughly reviewed. He said AI is changing the balance in cybersecurity by allowing attackers to scan code and identify bugs at machine speed. In his view, defenders need to move just as fast, relying on secure design, hardware, and mathematics. He advised users to check how a hardware wallet generates randomness and whether that mechanism has been independently certified.
According to Decrypt, Ledger Chief Technology Officer Charles Guillemet said the Coldcard vulnerability incident exposed weaknesses in how hardware wallets generate randomness, and added that AI is reshaping the balance between attackers and defenders in cybersecurity.
Guillemet said a hardware wallet’s security model can live or die on random number generation, and that this incident proved the point “in the most expensive way possible.”
Ledger said its own hardware wallets were not affected. The company said mnemonic phrases on Ledger devices are generated by a hardware random number generator inside a certified secure element, with no software fallback path, and that each generation produces a full 256 bits of randomness.
Guillemet also said open-source code does not equal security if it has not been reviewed thoroughly. In his view, AI now lets attackers scan code and spot vulnerabilities at machine speed, which means defense has to advance at the same pace. He said that requires secure design, hardware, and mathematics.
He advised users choosing a hardware wallet to understand how its random numbers are generated and whether the mechanism has been independently certified.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.