- Daily Dispatch
- Posts
- Coldcard key exploit drains $38M 😱
Coldcard key exploit drains $38M 😱
A vulnerability in the hardware wallet's seed generation enabled attackers to scoop 594 BTC from 500 wallets inside 25 minutes.
📝 What you need to know
Hardware wallets are routinely touted as the ne plus ultra of crypto security. That reputation took a body blow Friday when Coldcard disclosed an advisory that its wallets were vulnerable to a flaw in the key generation mechanic, making seeds more guessable than intended. The warning came too late for some 500 wallets, which were drained of $38 million in Bitcoin across just 25 minutes.
The wallet’s manufacturer, Coinkite, said it was likely the attacker had “used AI to review previous versions” of its open source firmware, in what could be the latest example of frontier AI being used to exploit crypto vulnerabilities. It comes just days after Zcash activated its Ironwood upgrade in response to a security researcher uncovering a critical flaw in its Orchard privacy pool.
It’s a worrying time for crypto holders as firms rush to audit their code, and mull whether the open source model that previously provided security assurances is now an attack surface for AI.
|
📰 In the News
📊 Myriad Insight of the Day
| ||||||||||||||||||
🕵🏻♀️ Editor’s Picks
🥇 Be First to Market With Myriad
Join the Myriad Markets Telegram to see the latest prediction markets the second they drop!
With Myriad, the on-chain prediction market launched by Decrypt’s parent company DASTAN, you can break the news and stake the news.
📚 Watch & Learn
📹 WATCH: Macro Markets, Memory vs Crypto, & WTF Is Stonkbroker - Special Guests: OSF & SimpleFarmer
Interested in partnering with Decrypt? Find out more here.









