Coldcard 2021 firmware vulnerability caused over 100 million dollars worth of Bitcoin to be stolen
The firmware vulnerability of the hardware wallet Coldcard in 2021 led to insufficient randomness in some recovery seeds. Since July 30, attackers have transferred approximately 1,600 to 1,800 Bitcoins from affected wallets, involving thousands of addresses, with a valuation exceeding 100 million dollars. Coldcard manufacturer Coinkite stated that it must be assumed that someone is using AI to review its public firmware. This vulnerability has existed for about five years, and whether AI was involved in the related attacks has not been confirmed.
Shielded Labs researcher Taylor Hornby used Claude Opus 4.8 audit agent to discover a vulnerability in the Zcash Orchard shielded pool circuit that began in 2022, which could generate an unlimited amount of counterfeit ZEC without detection during testing. Developers completed the fix within a few days, and no theft of coins has been confirmed.
Blockchain analysis company Chainalysis statistics show that the on-chain write volume carrying malware instructions and command control information has increased from an average of about 2.06 times to 11.1 times daily, a growth of 440%.






