cd /news/ai-safety/ledger-says-coldcard-exploit-shows-b… · home topics ai-safety article
[ARTICLE · art-86774] src=decrypt.co ↗ pub= topic=ai-safety verified=true sentiment=· neutral

Ledger Says Coldcard Exploit Shows Bitcoin Wallet Security Must Adapt to AI

Ledger CTO Charles Guillemet said the Coldcard exploit, which has led to roughly $130 million in losses, underscores the need for hardware Bitcoin wallets to use independently certified hardware random number generators and adapt to AI-driven security threats. Ledger stated its own devices were not affected because they generate recovery phrases using a true hardware random number generator built into a certified Secure Element with no software fallback. Guillemet noted that AI is accelerating vulnerability discovery, forcing security teams to defend at machine speed.

read3 min views1 publishedAug 4, 2026
Ledger Says Coldcard Exploit Shows Bitcoin Wallet Security Must Adapt to AI
Image: Decrypt (auto-discovered)

In brief

  • Ledger says the Coldcard exploit is a warning for the hardware Bitcoin wallet industry but says its own devices were not affected.
  • The company argues independently certified hardware random number generators are essential for securely creating wallet recovery phrases.
  • Ledger says AI is accelerating vulnerability discovery and forcing security teams to defend at machine speed.

Hardware wallet maker Ledger says the recent Coldcard exploit should serve as a warning for the cryptocurrency industry.

According to Ledger CTO Charles Guillemet, the incident exposed weaknesses in how some devices, in this case hardware cryptocurrency wallets, generate cryptographic randomness while showing how artificial intelligence is reshaping both cyberattacks and digital defenses.

"We're treating this as a serious reminder of how the whole security model of a hardware wallet lives or dies on randomness," Guillemet told Decrypt. "Cryptography is hard and implementing it securely is harder. This week's Coldcard incident made that visible in the most expensive way possible."

The comments come as the fallout from the Coldcard exploit continues to grow. Last week, Coldcard maker Coinkite disclosed a flaw in the air-gapped Coldcard Bitcoin hardware wallet that traces back to a March 2021 firmware build. The bug used a software fallback instead of the device's hardware random number generator to create wallet recovery seeds, making some private keys guessable and allowing thieves to steal user Bitcoin.

To date, losses have reached roughly $130 million while other thefts remain under investigation. On Sunday, Coinkite released patched firmware and urged affected users to move funds to newly generated wallets.

Coinkite did not respond to Decrypt's request for comment for this story.

Ledger said its own hardware wallets were not affected because they generate recovery phrases differently.

"Ledger hardware wallets draw their root secret (the 24-word Secret Recovery Phrase) from a true hardware random number generator built directly into a certified Secure Element, with no software fallback path," Guillemet said. "That generator produces the full 256 bits of entropy for every seed."

For Ledger, the incident raises broader questions about how hardware wallet security is evaluated. "Open source and reviewed are not the same thing," Guillemet said. "This flaw sat in public code for more than five years until, reportedly, an adversary used AI to find it, a reminder that being open and being reviewed are two different things."

He said AI is changing cybersecurity by allowing attackers to scan code, search for configuration errors, and identify vulnerabilities "at machine speed."

"That means defense has to move at the same speed," he said. "It needs to come from security by design, hardware, and math."

In May, a security researcher using Claude Opus 4.8 discovered a four-year-old vulnerability that could have fueled unlimited minting of Zcash, leading to large-scale investor panic and sending Zcash down more than 40% in a single day in response.

According to Guillemet, Ledger says it has spent the past two years using AI alongside human security engineers and cryptographers to review code and identify vulnerabilities before attackers can exploit them.

“We also don't just rely on our own word for it,” he explained. “Our Donjon research lab exists to try to break our products before anyone else can.”

To mitigate future risk, Guillemet said users evaluating any hardware wallet should understand how it generates randomness and whether that process has been independently certified.

"Randomness has to come from physics, not a formula," he said. "It has to be certified by people whose job is trying to break that claim, not just asserted by the vendor."

── more in #ai-safety 4 stories · sorted by recency
── more on @ledger 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/ledger-says-coldcard…] indexed:0 read:3min 2026-08-04 ·