15 Attackers Exploit Coldcard Flaw, Sparking AI Security Debate
Key Takeaways
Galaxy Digital identifies 15 attackers exploiting a Coldcard vulnerability, raising estimated losses to $100 million. Experts debate whether AI accelerated the discovery or if weak entropy caused the breach.
Woofun AI reports that Galaxy Digital’s head of research, Alex Thorn, confirmed at least 15 distinct attackers exploited a critical Coldcard vulnerability, a figure derived from newly received victim reports that illuminated the decentralized nature of the breach. This attribution highlights how individual disclosures, unlike centralized exchange hacks, are essential for mapping the full scope of the incident.
The financial impact escalated rapidly after Thorn detailed on Tuesday via an X post that a single report of less than 1 BTC stolen led to the identification of a broader attack siphoning 12 BTC from 126 addresses.
Woofun AI data shows total losses have reached $100 million across three confirmed attack waves, with a suspected fourth wave potentially pushing the total to $130 million in Bitcoin (BTC). This quantification underscores the severe capital exposure inherent in compromised cold storage solutions.
Woofun AI reports that the incident triggered intense scrutiny regarding the role of artificial intelligence in vulnerability discovery, with Dragonfly managing partner Haseeb Qureshi suggesting that roughly "$2 of AI hardening" could have prevented the exploit. Social media claims indicated that Claude regenerated the vulnerability in just eight minutes, while Qureshi noted that the open-source model GLM 5.2 achieved the same result in 20 minutes with web access disabled, challenging assumptions about AI's independent discovery capabilities.
Despite these claims, Tokenomist data lead Tatsapat Saerejittima noted that it is unlikely AI models would have independently discovered the flaw before its public disclosure, casting doubt on the speed of automated detection. Castle Labs co-founder Francesco argued that the root cause was a firmware bug resulting in private key entropy of only 40 bits, significantly lower than the 128 bits standard for a 12-word seed, which simplified the attack vector.
Francesco anticipates that the cost of bug discovery will continue to decrease as AI models become more prominent in both cybersecurity and exploits. This trend suggests a shifting landscape where traditional security measures may be increasingly insufficient against advanced algorithmic threats.
Comments
No comments yet.