AI Code Review Flags Long-Running Coldcard Firmware RNG Flaw Linked to $70M BTC Losses
AI Market Summary
A reported Coldcard firmware vulnerability alleges private keys were generated using a software PRNG rather than a hardware TRNG, potentially enabling large-scale key compromise and linking the issue to ~$70M in BTC theft across 1,196 wallets. The claim that AI tools identified the flaw quickly underscores operational risk in open-source wallet stacks and may heighten scrutiny of hardware-wallet security, increasing near-term risk aversion around BTC custody.
Impact level
● High
Affected assets
BTC/USDT+1.48%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
ChainCatcher reports that a developer on Reddit used Claude Code to audit Coldcard's open-source firmware and said it pinpointed a critical issue within eight minutes. The firmware was generating private keys with a software-based pseudorandom number generator rather than a hardware true random number generator, a weakness reportedly tied to roughly $70 million in BTC stolen from 1,196 wallets. Community members also said they independently reached the same conclusion using Zhipu GLM 5.2 (trained on June 16, run offline). According to the posts, the bug has been present in the wallet's open-source codebase for more than five years.