Loading market data...

Coldcard Hack Traced to Weak Randomness as Ledger Warns AI Is the Real Threat

Coldcard Hack Traced to Weak Randomness as Ledger Warns AI Is the Real Threat

Last week's $116 million Coldcard hack wasn't a failure of hardware wallets, according to Ledger's Chief Human Agency Officer, Ian Rogers. The real problem, he said, is what AI lets attackers do to systems built on weak randomness. The vulnerability traces back to a 2021 firmware bug that routed seed generation through a software pseudorandom number generator instead of the device's hardware chip.

The 2021 Bug That Opened the Door

That firmware flaw produced entropy of roughly 40 to 72 bits — a small enough address space for an AI-powered attacker to scan systematically and locate private keys. TRM Labs traced 1,082 BTC drained in the first wave's 41-minute sweep on July 30. The attack didn't break the hardware; it exploited a shortcut taken years earlier.

Rogers stressed that this incident is not evidence that self-custody or hardware wallets are inherently risky. Instead, he pointed to a compounding set of threats: AI gives attackers more firepower to find vulnerabilities in any system; AI-assisted development means more code ships faster, expanding the attack surface; and enterprises are deploying agents that hold access to internal secrets.

Ledger's Hardware-Only Approach

Ledger generates entropy entirely in hardware, using a certified secure chip with no software fallback. The resulting address space, Rogers said, is 'the number three with 67 zeros behind it.' That's a deliberate design choice, not an afterthought.

This isn't the first time Ledger has spotted a similar issue. In 2022, the company identified a comparable bug in Trust Wallet and worked through responsible disclosure to help users move funds to safety. The pattern, Rogers suggested, is that weak randomness is a recurring weak point — and AI makes it far easier to exploit.

Agents, Secrets, and the Teenager Analogy

Rogers described a future where people hand AI agents their passwords, credit cards, and identities as a dangerous, unmanaged risk. His analogy compares AI agents and secrets to a teenager and car keys — you wouldn't hand over the keys without some safeguards, and the same should apply to digital credentials.

Ledger already offers tools that let an agent hold a wallet without holding the private keys. The principle, Rogers said, is protection by design, not by policy. That means building systems where secrets never leave the hardware, even when an AI is doing the transacting.

The Coldcard incident is a reminder that the weakest link isn't always the device itself — it's the code that runs on it. As AI-driven attacks become more common, the question isn't whether to use hardware wallets, but whether the hardware is doing all the work.