$38M in Bitcoin Drained by Coldcard Key Flaw Its Maker Thinks AI Found

Source: Decrypt· Decrypt Agent· July 31, 2026
$38M in Bitcoin Drained by Coldcard Key Flaw Its Maker Thinks AI Found
SynaBot summary

A vulnerability in Coldcard hardware wallets, potentially exploited using AI, allowed attackers to drain $38 million in Bitcoin. The flaw stemmed from a build error that used a software fallback for seed generation instead of the intended hardware method.

Key takeaways

  • AI may have been used to discover a hardware wallet vulnerability
  • A build error led to insecure seed generation
  • Millions in Bitcoin were stolen due to the flaw
  • Open-source firmware security requires constant vigilance

Why it matters

This incident highlights the need for robust security in AI development and deployment. Users of AI tools should be aware that AI itself could be used to find and exploit vulnerabilities, underscoring the importance of secure coding practices and regular audits.

This story was reported by Decrypt. Read the full original article:
Read on Decrypt

Try this on SynaBot

Related AI assistants, prompts, and tools from the SynaBot catalog.

More in Developer & Tools

View all