
The exploitation of a vulnerability in Coldcard has highlighted the need to reassess the verification of random number generators in Bitcoin storage devices. This was stated by Ledger CTO Charles Guillemet, according to Decrypt.
According to him, the incident revealed the limitations of the “open code means verified code” approach. The expert noted that the flaw had been in the public domain for over five years but was not detected until the attacks began.
“Open code and verified code are not the same,” said Ledger’s CTO.
According to Ledger’s documentation, the company’s devices generate 256 random bits through a hardware generator in the Secure Element. Guillemet stated that this architecture lacks a software fallback, which became an issue in Coldcard.
Ledger linked the incident to the growing role of AI tools in code analysis. Guillemet noted that such systems accelerate the discovery of vulnerabilities for both attackers and defenders. However, as of the time of writing, there is no public evidence that attackers actually used artificial intelligence.
U.Today highlighted posts on Reddit and X. Users claimed that Claude Code allegedly found the vulnerability in about eight minutes after a request to review the source code.
this is insane
claude code found the COLDCARD wallet vulnerability with a single prompt, in just 8 minutes of thinking
we’re not ready for what’s coming pic.twitter.com/wh1LtEWuje
— Medusa (@MedusaOnchain) August 2, 2026
Earlier, Dragonfly venture fund managing partner Haseeb Qureshi stated that the attack on Coldcard hardware wallets could have been prevented by using artificial intelligence to verify the code for $2.
According to Galaxy Research, at least 15 different attackers exploited the vulnerability. Analysts estimated losses from three confirmed waves at $100 million. With a potential fourth wave, the amount could rise to approximately $130 million.
On August 4, hardware crypto wallet manufacturers Trezor and Foundation warned users about phishing attacks following the incident. In some cases, scammers send emails purportedly from the manufacturer, offering to conduct an “equipment audit.”
