Coldcard Bitcoin Wallet Flaw Exposes Years-Long Seed Theft Risk, AI Audit Finds Dozens More Bugs
A long-standing flaw in the random number generator (RNG) used by Coldcard, a popular hardware wallet for storing Bitcoin, has reportedly been responsible for one of the largest known thefts of cryptocurrency seed phrases. The error existed in the device's firmware for five years before being identified, allowing attackers to compromise the private keys that protect users' funds.
Following the discovery, security researchers used AI-assisted analysis to review other software and hardware across the broader Bitcoin ecosystem. This audit uncovered 85 additional critical vulnerabilities, suggesting that similar weaknesses in random number generation and key management may be far more widespread in cryptocurrency products than previously understood.
While this issue centres on cryptocurrency hardware rather than typical business IT systems, it highlights a broader lesson for any organisation: security flaws in foundational components, such as randomness generation used in encryption, can go unnoticed for years and have severe consequences once discovered.