to leave a comment.

▲ Cryptocurrency Hacking, Security / AI-generated image
It has been revealed that at least 15 attackers exploited the Coldcard wallet vulnerability.
According to crypto media outlet Cointelegraph on August 5 (local time), Alex Thorn, Head of Research at Galaxy Digital, stated that at least 15 different attackers exploited the Coldcard vulnerability, citing new victim reports received since the incident. Thorn explained on Tuesday that these victim reports helped identify new attackers who would have otherwise remained unknown, noting that the nature of this attack differs from centralized exchange hacks. He stated in a post on X, "A single report from one victim who lost less than 1 BTC led to the identification of a new attack where 12 BTC was drained from 126 addresses."
According to Galaxy Research, the estimated losses from the Coldcard vulnerability have swelled to $100 million across three confirmed waves of attacks. The firm also identified a suspected fourth wave of attacks, which, if included, could bring the total losses to approximately $130 million in Bitcoin (BTC). The ongoing attacks have reignited the debate about the security of cold storage wallets and whether it is safer for individuals to self-custody their Bitcoin.
Haseeb Qureshi, Managing Partner at Dragonfly, stated that the Coldcard vulnerability could have been prevented with AI-enhanced work worth approximately $2. He cited social media reports that some AI models rediscovered the vulnerability that led to this attack in less than 20 minutes. Qureshi's remarks came in response to several social media users claiming that Claude could reproduce the vulnerability in just 8 minutes. He argued that these results might have been contaminated by web searches, adding that the open-source AI model GLM 5.2 rediscovered the attack in 20 minutes even with web access turned off.
However, Tatsapat Saerejittima, Head of Data at crypto analytics platform Tokenomist, told Cointelegraph that it is unlikely AI models independently discovered the vulnerability before it was publicly disclosed. He said, "The claim that AI found the vulnerability in 2 minutes came from an anonymous Reddit user who scanned the code after the vulnerability was already public. There was no blind test, no documented methodology, and no evaluation of the model's false positive rate."
Francesco, co-founder of crypto research firm Castle Labs, said that as the capabilities of AI models grow, the cost and time required to find new cryptocurrency vulnerabilities are rapidly decreasing. However, he added that Coldcard's private key mechanism might have also contributed to this vulnerability. He told Cointelegraph, "Due to a firmware bug, Coldcard used a private key entropy of 40 bits, a much lower standard than adopted by other wallets. Compared to the 128 bits of a 12-word seed, the attack became much easier." Francesco, who requested his last name not be disclosed, said that as AI models play a more prominent role in both cybersecurity and vulnerability exploitation, the cost of bug discovery is expected to continue to decrease.
[Article Key Summary]
-Galaxy Digital reported that at least 15 attackers exploited the Coldcard vulnerability, with estimated losses potentially reaching $130 million.
-Qureshi claimed that the vulnerability could have been prevented with approximately $2 worth of AI enhancement, but Saerejittima refuted these claims as poorly substantiated.
-Francesco predicted that Coldcard's low private key entropy made the attack easier and that the cost of discovering vulnerabilities will continue to decrease with advancements in AI.
*Disclaimer: This article is for investment reference only, and we are not responsible for investment losses based on it. The content should be interpreted for informational purposes only.*
Newsletter
Get key news delivered to your email every morning
to leave a comment.