Critical Vulnerability in Coldcard Wallets
Security experts are sounding alarms following revelations that Anthropic’s Claude Code AI independently pinpointed a critical flaw in the firmware of Coldcard wallets in just eight minutes. This vulnerability, which has been linked to one of the most significant hacks in the history of cryptocurrency wallets, allowed attackers to steal over $100 million worth of Bitcoin, with initial estimates suggesting more than 1,080 BTC was taken in less than an hour.
Understanding the Flaw
The issue revolves around the Coldcard’s method of generating cryptographic randomness, essential for creating secure private keys and signing transactions. If the process of generating random numbers becomes predictable or insufficiently random, it effectively opens the door to exploitation by malicious actors.
Community Reactions
Researcher Medusa highlighted the impressive capabilities of Claude Code by noting its identification of the Coldcard wallet issue with a single command, emphasizing a sobering sentiment among the cybersecurity community: “We’re not ready for what’s coming.”
This incident has raised concerns that the flaw might be indicative of broader vulnerabilities within the crypto wallet industry.
Systemic Issues and Ongoing Threats
Ari Paul, CEO of BlockTower Capital, suggested that the Coldcard incident underscores a systemic problem rather than a singular failure tied to one product. As the situation unfolds, there are indications that the threat to Coldcard users may not be concluded.
Alex Thorn, Galaxy Digital’s head of research, noted on social media a significant uptick in suspicious transaction activity related to Coldcard wallets. According to his analysis, Bitcoin blocks numbered 960,778 to 960,792 recorded 218 dubious transactions linked to 462 affected addresses, amounting to nearly 389 BTC.
Precautionary Measures for Users
In light of these developments, Coldcard users are urged to transfer any funds from their wallets immediately as a precaution, utilizing higher transaction fees to expedite the processing of their transfers in an attempt to outpace potential attackers.