Loading market data...

Coldcard Wallet Flaw Existed for Five Years, Led to $38M Bitcoin Theft, Maker Says AI Helped Find It

Coldcard Wallet Flaw Existed for Five Years, Led to $38M Bitcoin Theft, Maker Says AI Helped Find It

A software vulnerability in Coldcard hardware wallets went undetected for five years, potentially allowing attackers to reconstruct private keys and steal over 1,100 Bitcoin — worth about $38 million at the time. The wallet's manufacturer said the flaw was discovered partly with the help of artificial intelligence.

The Five-Year-Old Flaw

The vulnerability existed in Coldcard wallets since at least 2021, according to the company. It allowed attackers to recover private keys from the devices, enabling a coordinated sweep of wallets. The theft of more than 1,100 Bitcoin was the result. Coldcard has not disclosed how many wallets were compromised or whether all affected users have been notified.

AI-Assisted Discovery

Coldcard attributed the discovery of the flaw partly to AI. The company did not provide details on which AI tools or methods were used, but the acknowledgment marks a notable instance of AI being credited with finding a critical hardware vulnerability. The finding led to a patch, though the timeline of the fix is unclear.

Coordinated Sweep and Aftermath

The theft involved a coordinated sweep, suggesting the attackers had a systematic approach. Coldcard has not confirmed if law enforcement is involved. Users are advised to check for updates from the manufacturer. The incident raises questions about the security of hardware wallets that have been on the market for years without a discovered flaw.

The full scope of the breach remains unknown. Coldcard has not said how many wallets were affected or whether the attackers have been identified. For now, the industry is left with a five-year-old vulnerability and a $38 million question.