AI Is Reshaping Wallet Security, Jameson Lopp Says After Coldcard Thefts
Key Takeaways
- •A firmware vulnerability in Coldcard wallets enabled the theft of over $83 million in Bitcoin, including 1,082.65 BTC stolen from 1,196 wallets in approximately 40 minutes on July 30.
- •The flaw originated because affected firmware versions used predictable chip data such as processor serial numbers instead of proper cryptographic randomness to generate wallet recovery keys, allowing criminals to reconstruct seed phrases without physical device access.
- •The defective firmware was introduced in March 2021 and remained undetected for over three years until it was patched in version 4.21, despite Coinkite having conducted an AI-assisted code review that failed to identify the weakness.
- •Affected users must generate an entirely new recovery seed and transfer their funds, as simply updating the firmware does not resolve the vulnerability tied to the original seed phrase.
- •The incident has intensified calls for independent third-party firmware audits and raised questions about whether most users can practically verify the complex software and hardware underpinning self-custody solutions.

The vulnerability behind more than $83 million in Coldcard Bitcoin thefts represents something far broader than a single hardware wallet failure, according to Casa co-founder Jameson Lopp. It signals a wider shift in cybersecurity, as artificial intelligence accelerates the timeline for both attackers and defenders to discover software vulnerabilities. Hardware wallets have long been considered the gold standard for self-custody precisely because they keep private keys offline, making this breach particularly significant for user confidence in the category.
Speaking on The Block's The Starting Block podcast, Lopp argued that large language models (LLMs) are transforming software security by dramatically lowering the cost of finding bugs.
"Advancements in large language models are drastically changing the security landscape," Lopp said. He described the Coldcard incident as one of the earliest concrete examples of this phenomenon, one he expects will have ramifications across the hardware wallet industry.
A Race That Cuts Both Ways
According to Lopp, the Coldcard breach is less about malfunctioning hardware and more about a shifting software security landscape. AI-powered code analysis, once the exclusive domain of well-funded security teams, has gone mainstream. Consequently, attackers can now comb public code repositories for overlooked vulnerabilities before developers themselves identify them.
Coinkite CEO Rodolfo Novak reached a similar conclusion while acknowledging his company's responsibility for the firmware bug. He called the incident "a sober reality of the new AI paradigm," noting that AI-assisted audits can surface flaws far more quickly than traditional manual reviews.
Notably, as reported by TradingView, Coinkite had actually used an AI application to analyze its code prior to being hacked. That analysis failed to detect the weakness — underscoring the reality that both attackers and defenders now wield comparable AI tools, with the advantage going to whoever finds the flaw first.
Technical Details of the Vulnerability
The flaw stemmed from how certain Coldcard firmware versions generated wallet recovery keys. According to information shared by Block's Bitcoin engineering and security team and reported by the New York Post, the affected devices relied on predictable chip data — such as processor serial numbers and clock information — rather than proper cryptographic randomness to generate keys.
This allowed cybercriminals to reconstruct wallet recovery phrases and steal funds without ever physically accessing the devices. The vulnerability went undetected for more than three years — the defective firmware was introduced in March 2021 and was not patched until version 4.21 — illustrating how subtle cryptographic weaknesses can persist even in products designed for high-security use.
According to Coinkite, simply updating the firmware is insufficient. Users who created wallets on the affected versions must generate an entirely new recovery seed and transfer their funds, as the vulnerability is tied to the original seed phrase.
Galaxy Research reported that on July 30, criminals stole 1,082.65 BTC from 1,196 wallets in approximately 40 minutes. Additional attack waves followed, including one observed by Alex Thorn of Galaxy that appeared to target multi-signature wallet holders, whereas earlier attacks had focused exclusively on single-signature users.
Prominent Bitcoin commentator Guy Swann described the incident as "the worst hit in bitcoin history" for conscientious cryptocurrency holders.
The Limits of "Don't Trust, Verify"
For Lopp, the breach also exposes the practical boundaries of one of Bitcoin's most celebrated principles: "Don't trust, verify."
"It's a good mantra," he acknowledged, "but you have to understand that verification of complex software and hardware is simply not feasible for 99.9% of the population."
Lopp contended that users inevitably end up placing trust in third parties to validate information. Rather than abandoning self-custody, he advocates for users to diversify that trust across multiple hardware wallets and software applications.
Zach Herbert, CEO of Foundation, echoed this perspective on the podcast, stating that it would be "really dangerous" to conclude that self-custody has failed based on a single incident. Instead, he argued, the industry must strengthen its security practices.
Lorenzo Valente of ARK Invest observed that many users have effectively swapped exchange counterparty risk for "software risk, hardware risk, supply-chain risk, phishing risk, backup risk."
The Case for Independent Audits
The incident has reignited calls for independent third-party firmware audits rather than sole reliance on vendor self-review. Andrew Lazutkin, Chief Technology Officer at Tangem, cautioned that publicly accessible code should not be automatically assumed to be secure. "Security comes from strong architecture, thorough testing and independent verification," he said.
Lopp noted that major hardware wallet vulnerabilities have been disclosed "a dozen times" over the years and expressed his belief that each incident has contributed to strengthening the industry. Coldcard's open-source firmware model, while enabling community review, also means that the same publicly available code is accessible to AI-equipped attackers scanning repositories for exploitable flaws.
The outstanding question now is whether Coinkite will follow through on its promised technical post-mortem and pursue more comprehensive independent security assessments — before AI-equipped attackers uncover the next weakness.