Ledger CTO: Coldcard Vulnerability Warning Hardware Wallet Security Needs to Adapt to the AI Era
According to Decrypt, Ledger's Chief Technology Officer Charles Guillemet stated that the Coldcard vulnerability incident exposed weaknesses in hardware wallet random number generation and emphasized that AI is reshaping the cybersecurity offensive and defensive landscape. Guillemet pointed out that the security model of hardware wallets "lives or dies by random numbers," and this incident proved that in the most expensive way.
Ledger stated that its hardware wallets were unaffected because their mnemonic phrases are generated by a hardware random number generator within a certified secure element, with no software fallback path, generating a complete 256-bit random number each time. Guillemet believes that open-source code, if not thoroughly reviewed, does not equate to security, and AI is enabling attackers to scan code and identify vulnerabilities at machine speed, requiring defenses to advance at the same speed, which relies on secure design, hardware, and mathematics. Guillemet suggested that users should understand how the random number generation of a hardware wallet works and whether it has been independently certified when choosing one.






