AI Code Review Flags Major Coldcard Firmware Flaw in Minutes
AI Market Summary
Reports claim an AI-assisted audit rapidly identified a long-standing Coldcard firmware flaw: private keys allegedly generated via software PRNG rather than hardware TRNG, tied to ~$70m BTC theft across 1,196 wallets. If accurate, this heightens hardware-wallet and self-custody operational risk, potentially pressuring market confidence and increasing scrutiny of open-source security practices and vendor QA processes in the near term.
Impact level
● High
Affected assets
BTC/USDT+1.22%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
A developer on Reddit said an eight-minute scan of Coldcard's open-source firmware using Claude Code quickly pinpointed a critical weakness: when generating private keys, the firmware relied on a software-based pseudorandom number generator rather than a hardware true random number generator. The flaw has been linked to the theft of about $70 million in BTC from 1,196 wallets. Community members also reported that Zhipu GLM 5.2 (trained on June 16, offline) independently surfaced the same issue. The bug had reportedly been present in the open-source wallet codebase for more than five years.