Coldcard's $130M Randomness Snafu Has Ledger Asking: Who Audits the Auditors? 🎲
Hardware wallet maker Ledger said the Coldcard exploit that has drained roughly $130 million worth of $BTC should serve as a wake-up call for the entire cryptocurrency industry, arguing that the incident exposed critical weaknesses in how some devices generate cryptographic randomness. Speaking to Decrypt, Ledger CTO Charles Guillemet framed the episode as proof that a hardware wallet's security model "lives or dies on randomness." "Cryptography is hard and implementing it securely is harder. This week's Coldcard incident made that visible in the most expensive way possible," Guillemet said.
The vulnerability originated in a March 2021 firmware build of Coinkite's air-gapped Coldcard Bitcoin hardware wallet. The flaw caused the device to fall back to a software random number generator rather than its dedicated hardware one when producing wallet recovery seeds, leaving some private keys guessable and enabling attackers to siphon funds from wallets that never touched the internet. Coinkite disclosed the issue last week, released patched firmware on Sunday, and urged affected users to migrate funds to newly generated wallets. Coinkite did not respond to Decrypt's request for comment.
On-chain data from Galaxy Research has now tracked more than 1,596 BTC stolen across three confirmed waves, with a suspected fourth wave that would lift the total to roughly 2,055 BTC, valued at about $130 million. Additional thefts remain under investigation. Guillemet stressed that Ledger's own devices were not impacted because they generate recovery phrases differently. "Ledger hardware wallets draw their root secret (the 24-word Secret Recovery Phrase) from a true hardware random number generator built directly into a certified Secure Element, with no software fallback path," he said. "That generator produces the full 256 bits of entropy for every seed."
Guillemet used the moment to argue that transparency alone is insufficient protection in an era of AI-assisted code review. "Open source and reviewed are not the same thing," he said. "This flaw sat in public code for more than five years until, reportedly, an adversary used AI to find it, a reminder that being open and being reviewed are two different things." He warned that artificial intelligence is now allowing attackers to scan code, hunt for configuration errors, and surface vulnerabilities "at machine speed," adding that "defense has to move at the same speed" and must be grounded in "security by design, hardware, and math." In May, a security researcher using Claude Opus 4.8 reportedly helped identify similar weaknesses, underscoring how quickly the threat landscape is evolving.
Mentioned Coins
Share Article
Quick Info
Disclaimer: This content is for information and entertainment purposes only. It does not constitute financial, investment, legal, or tax advice. Always do your own research and consult with qualified professionals before making any financial decisions.
See our Terms of Service, Privacy Policy, and Editorial Policy.