AI Claude Finds Coldcard Wallet Flaw in 8 Minutes, Exposing $100M Bitcoin Vulnerability

3 hour ago 2 sources negative

Key takeaways:

  • Bitcoin's price may face headwinds if stolen BTC are sold, raising short-term supply overhang.
  • Trust in hardware wallets could erode, shifting capital towards exchange custody services.
  • Dual-use AI capabilities heighten cybersecurity risks, potentially curbing retail adoption of crypto.

A Reddit user claimed that Anthropic’s AI model, Claude, identified the critical vulnerability in Coldcard hardware wallets that led to a series of thefts totaling approximately 1,367 BTC—worth around $86 million, with community estimates now placing the total above $100 million. The user, posting under the handle Impressive-Gene-421 in a Bitcoin-focused subreddit, said that Claude Code was asked to review the source code for vulnerabilities and, after roughly eight minutes of analysis, pinpointed the flaw that enabled the hacks.

Security researcher Medusa corroborated the finding on X, stating that Claude analyzed the Coldcard wallet’s source code after receiving a single prompt requesting a security review and located the same vulnerability exploited in the attack. The flaw was traced to weak cryptographic randomness in the wallet’s random number generation—a critical component for creating private keys and digital signatures. This oversight allowed an attacker to remotely exploit the wallets, leading to the massive heist.

Investigators noted that the attack campaign may still be active. Alex Thorn, Galaxy’s head of research, reported that Bitcoin blocks 960,778 through 960,792 contained 218 suspicious transactions affecting 462 wallet addresses, transferring nearly 389 BTC in another coordinated wave. Users are urged to immediately update firmware, move funds to secure wallets, and prioritize transaction confirmations with higher fees.

The incident highlights both the potential of AI in cybersecurity and its dual-use risk—attackers reportedly leveraged similar AI methods to discover the flaw. Coldcard has not yet issued an official statement, but the case underscores the urgent need for rigorous code audits and continuous security monitoring in the crypto industry.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.