BTC $63,124.47 +0.38%
ETH $1,861.94 -0.29%
BNB $587.69 +1.76%
XRP $1.08 +1.88%
SOL $73.13 +0.71%
TRX $0.3273 -0.47%
DOGE $0.0703 +0.49%
ADA $0.1893 +8.77%
BCH $213.49 +2.69%
LINK $8.27 +2.35%
HYPE $52.27 -0.39%
AAVE $92.12 +0.50%
SUI $0.6902 +1.14%
XLM $0.1738 +1.89%
ZEC $471.41 -0.22%
BTC $63,124.47 +0.38%
ETH $1,861.94 -0.29%
BNB $587.69 +1.76%
XRP $1.08 +1.88%
SOL $73.13 +0.71%
TRX $0.3273 -0.47%
DOGE $0.0703 +0.49%
ADA $0.1893 +8.77%
BCH $213.49 +2.69%
LINK $8.27 +2.35%
HYPE $52.27 -0.39%
AAVE $92.12 +0.50%
SUI $0.6902 +1.14%
XLM $0.1738 +1.89%
ZEC $471.41 -0.22%

Community users audited Coldcard code using AI and discovered a critical vulnerability in just 8 minutes

2026-08-02 23:46:31

Developers on Reddit used Claude Code to scan the Coldcard open-source firmware for vulnerabilities, identifying the core issue within 8 minutes:

The firmware called a software pseudo-random number generator instead of a hardware true random number generator when generating private keys, and this vulnerability led to the theft of approximately $70 million in BTC from 1,196 wallets.

At the same time, community users also reported that an independent scan using Zhizhu GLM 5.2 (trained on June 16, not connected to the internet) similarly discovered the same vulnerability.

This bug has existed in the open-source wallet code for over five years.

app_icon
ChainCatcher Building the Web3 world with innovations.