AI is reshaping wallet security, Jameson Lopp says after Coldcard thefts

- Jameson Lopp says the Coldcard thefts show how large language models are lowering the cost of finding software vulnerabilities for both attackers and defenders.
- The suspected flaw involved weak seed generation in some Coldcard firmware versions, allowing attackers to target wallets without physical access to the devices.
- The incident does not mean self-custody has failed, but it strengthens the case for independent firmware audits, multisig setups, and spreading trust across more than one wallet provider.
The flaw behind more than $83 million in Coldcard bitcoin thefts is about more than a single hardware wallet failure, according to Casa co-founder Jameson Lopp. It shows a broader change in cybersecurity, with artificial intelligence reducing the time needed for both attackers and defenders to uncover software vulnerabilities.
In The Block’s The Starting Block podcast, Lopp claimed that large language models (LLMs) are changing software security by minimizing the cost of discovering bugs.
“Advancements in large language models are drastically changing the security landscape,” he said, claiming that the Coldcard incident is one of the first examples of the phenomenon, which is expected to have ramifications for many wallets.
A race that cuts both ways
According to Lopp, it is less a case of malfunctioning hardware than that of changing security software. From being the sole privilege of well-funded security teams, AI-powered code analysis has gone mainstream. As a result, attackers can now access public code repositories for missed vulnerabilities prior to developers finding them.
The CEO of Coinkite, Rodolfo Novak, came to the same conclusion while acknowledging his responsibility in relation to the firmware bug. According to him, the incident is “a sober reality of the new AI paradigm,” with AI-assisted audits being able to uncover flaws much faster than traditional manual audits.
Surprisingly, in its previous report, Cryptopolitan mentioned that Coinkite had employed an artificial intelligence application to analyze its coding before being hacked.
As reported by Tradingview, that analysis was unable to detect the weakness, highlighting the fact that both attackers and defenders have access to similar AI technology, which gives an advantage to the one who detects the flaw first.
What actually went wrong inside the device
The weakness emerged due to the method of generating recovery wallet keys in some Coldcard firmware versions. As per information shared by Block’s Bitcoin engineering and security team, reported by the New York Post, the vulnerable devices employed certain predictable chip information (such as processor serial number and clock data) instead of using proper randomness in generating the numbers.
As a result, cybercriminals were able to reconstruct the recovery phrases used in the wallets and to steal the funds without physically accessing the wallet.
The defective firmware was introduced in March 2021 and was repaired only in the release of version 4.21. According to Coinkite, simply updating the firmware doesn’t solve the problem. Individuals who created wallets using the flawed versions should generate a new recovery seed and transfer their money since the vulnerability is closely connected with the previously used seed phrase.
Galaxy Research stated that on July 30, criminals managed to steal 1,082.65 BTC from 1,196 wallets in about 40 minutes. After that, more attacks took place, including the last wave seen by Alex Thorn of Galaxy, which seemed to be directed at multi-sig wallet holders as opposed to the earlier attacks targeted solely at single-sig users.
Popular Bitcoin commentator Guy Swann stated that the incident is “the worst hit in bitcoin history” for cautious owners of the virtual currency.
Where “don’t trust, verify” runs out
For Lopp, the breach also exposes the limits of one of Bitcoin’s best-known principles: “Don’t trust, verify.”
“It’s a good mantra,” he said, “but you have to understand that verification of complex software and hardware is simply not feasible for 99.9% of the population.”
According to Lopp, users will ultimately place their trust in a third party to validate the information. Rather than relinquish the ability to use their own wallets, Lopp advocates for users to diversify their trust by utilizing multiple hardware wallets and software applications.
Zach Herbert, CEO of Foundation, expressed the same opinion on the podcast, stating that it’s “really dangerous” to conclude that self-custody has failed considering just one case. On the contrary, he suggests that the industry needs to improve its security practices.
Lorenzo Valente, who is associated with ARK Invest, claimed that many users have merely traded their exchange counterparty risk for “software risk, hardware risk, supply-chain risk, phishing risk, backup risk.”
The case for independent audits
This occurrence has once again sparked the demand for firmware audits by an independent party in place of total reliance on the vendor’s self-review. Cryptopolitan recently published an article discussing whether open-source code presents adequate security, and the Coldcard incident is further proof of this argument.
According to Andrew Lazutkin, the Chief Technological Officer at Tangem, publicly accessible code should not be assumed to be secure. As he explained, “Security comes from strong architecture, thorough testing and independent verification.”
Lopp commented that major hardware wallet disclosures had occurred “a dozen times” and believed that all those incidents had contributed to the improvement in the industry. The next question that needs to be answered is whether Coinkite will implement its promised technical post-mortem and more widespread independent security assessments before AI-enabled hackers discover the next weakness.
Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.
FAQs
How much bitcoin was stolen in the Coldcard exploit?
Galaxy Research estimated 1,082.65 BTC, worth about $70 million, drained from 1,196 addresses in a 40-minute window on July 30, and later waves lifted the running total to roughly $83 million to $89 million.
What caused the Coldcard vulnerability?
A firmware error dating to the March 2021 4.0.0 release made devices fall back to a weak software random number generator seeded by nonsecret chip data such as the serial number and clock, producing recovery phrases predictable enough to brute-force.
What should Coldcard owners do now?
Coinkite says updating the firmware is not enough, because the flaw follows the recovery phrase; affected users must generate a new seed on patched firmware and move their bitcoin to the new wallet.
Should hardware wallet vendors undergo independent security audits?
Experts generally see independent audits as one layer in a broader security strategy that also includes open-source code, responsible disclosure programs and continuous testing.
Should entropy generation be externally certified?
Some researchers argue that wallet vendors should provide stronger evidence that their entropy-generation methods have been independently validated or certified. Others caution that certification alone cannot eliminate implementation errors and should complement, rather than replace, secure hardware design, transparent code review and ongoing security testing.
Should reproducible firmware become mandatory?
Reproducible, or deterministic, firmware builds allow anyone to verify that the firmware installed on a device matches the publicly released source code. Many Bitcoin developers consider reproducible builds an important transparency feature because they reduce the risk of hidden or unauthorized code being introduced during the build process. However, reproducible firmware does not prevent all vulnerabilities,
Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Micah Abiodun
Micah Abiodun makes good use of his Environmental Engineering and Management (MSc) at Tallinn University of Technology (TalTech) to polish content and price prediction news at Cryptopolitan. Now on his 7th year in the crypto media space, he covers major cryptos, altcoins, DeFi, stablecoins, macro trends, and emerging tech.
















