• Hey Guest. Check out your NeoGAF Wrapped 2025 results here!

Coldcard Wallet Drain (ongoing)

Mr1999

Member
Is anyone else following this? I was led to this after seeing posts today and yesterday of people saying they had lost all their money. The TLDR version seems to be that a flaw in the code updated in 2021 for their hardware based cold wallet may have caused the entropy generation to be too predictable, allowing an attacker to guess the seeds where they checked to see which had money and then started draining them when they had stocked up on it. Link below explains what happened in detail. Attackers have reportedly drained around $80 million worth of funds from wallets so far and its going to continue. There are quite a few victims saying how much they lost, including some very large amounts. Personally I don't know how people manage to lose that amount of money. Id have to live with the shades down my entire life with such a hit, 60K, 80K, 1 million dollars, and its always the same story, they woke up to check to see the money and it was gone.

4mEjpyCc8Iu26q1s.jpg
xJgerhNie6HvkuGf.jpg

EYZMf72Q1ojYZaZk.jpg
zn4bqjJkVfsqfbyz.jpg
vhwEWLLaSHktEAev.jpg
JvvGcKoIYaWtWFw8.jpg

kOZr1EvW5ugDi2rf.jpg
CyFRO0KRB1bEx7yI.jpg



There's also this


and

GLM-5.2 (trained June 16th, before anyone knew, no internet access) correctly identified the vulnerability independently after ~20 minutes of thinking

 
Last edited:
The security flaw was that a firmware bug introduced in 2021 caused seed generation to fall back to a weak software pseudo-random number generator instead of the hardware's true/intended RNG. So instead of being 128-bit it was ~40-bit encryption(?) which reduced complexity and made it brute-forceable.

For the Claude piece, the firmware of the Coldcard devices is open-source. So a user (not the hackers) found he was able to dump it into Claude Opus 5 to identify and reproduce that vulnerability. Coinkite (the Coldcard company) themselves think AI/LLMs were involved in the hack.

This is wild stuff, and I bet we're only getting started with AI-assisted hacks.
 
Last edited:
There's also a rumor, actually i'm pretty much convinced, that someone took an offline version of claudes llm from an earlier date before any of this was found, and it specifically found the code that led to the hack.

Any other details you can provide here? "Offline version of claudes llm" is this referring to the leak they experienced earlier in the year, or a local LLM built off of training data used by Claude at some point? Not looking for all the answers just looking for some details on the rumor/where I could find out more info.

Thanks.
 
Any other details you can provide here? "Offline version of claudes llm" is this referring to the leak they experienced earlier in the year, or a local LLM built off of training data used by Claude at some point? Not looking for all the answers just looking for some details on the rumor/where I could find out more info.

Thanks.
Yea i got that part wrong its updated now
 
The security flaw was that a firmware bug introduced in 2021 caused seed generation to fall back to a weak software pseudo-random number generator instead of the hardware's true/intended RNG. So instead of being 128-bit it was ~40-bit encryption(?) which reduced complexity and made it brute-forceable.

For the Claude piece, the firmware of the Coldcard devices is open-source. So a user (not the hackers) found he was able to dump it into Claude Opus 5 to identify and reproduce that vulnerability. Coinkite (the Coldcard company) themselves think AI/LLMs were involved in the hack.

This is wild stuff, and I bet we're only getting started with AI-assisted hacks.
Might be a stupid question, but do you think stuff like this is the reason why Mythos 5 was banned from regular use?
 
Might be a stupid question, but do you think stuff like this is the reason why Mythos 5 was banned from regular use?
Personally, yeah, as well as them taking it "offline" being a selling point for businesses they want to sell access to. "This model is so good it can catch security flaws no one else ever has before! We can't let this go into the hands of the bad actors/hoi polloi!"
 
Last edited:
Personally, yeah, as well as them taking it "offline" being a selling point for businesses they want to sell access to. "This model is so good it can catch security flaws no one else ever has before! We can't let this go into the hands of the bad actors/hoi polloi!"
That's crazy, imagine having this kind of tech back in the 90s, someone could potentially terrorize the entire internet and nobody would even know how to stop them, would be LulzSec level of hacks but on steroids, It honestly sounds like the plot of a cyberpunk movie. Even still, I'm sure the tools that are already available are more than capable of finding plenty of low hanging fruit and vulnerabilities that people thought no big deal about, but yes right now its extremely restrictive, but I'm sure eventually all of this is going to be open, and then what lol. We'll wait and see I guess.
 
Last edited:
That's crazy, imagine having this kind of tech back in the 90s, someone could potentially terrorize the entire internet and nobody would even know how to stop them, would be LulzSec level of hacks but on steroids, It honestly sounds like the plot of a cyberpunk movie. Even still, I'm sure the tools that are already available are more than capable of finding plenty of low hanging fruit and vulnerabilities that people thought no big deal about, but yes right now its extremely restrictive, but I'm sure eventually all of this is going to be open, and then what lol. We'll wait and see I guess.

Right now, they saw what they could do, so took them offline. That way they can work on identifying and patching those vulnerabilities internally before the bad actors can attack. So, imo, if all these companies are doing that to the point that the LLMs can no longer find vulnerabilities, then we might get to a sort of stasis and security. But right now, it's the Wild West.
 
Last edited:
Security through obscurity is a finally a dead concept. It should have been a long time ago, but today the idea is pure suicide.

Doesn't sound like that was exactly the case here, but these stories are daily affairs now. One thing that will help prop up the AI industry is a war like scenario where if you stop spending and your opponent doesn't then you lose. Perhaps there's a way of writing perfect software that has no flaws, but new tricks and entire new concepts of attack keep being discovered which requires reengineering, which causes new issues that can be attacked.

It sucks to hear that hardware wallets are getting hit because in general these are people doing "the right thing" and making an effort to secure their assets. I'm less trusting in off the shelf solutions to things because you expose your process to the world and give attackers many chances of success. But we'll never be in a world where everyone can engineer their own solution to security.
 
Security through obscurity is a finally a dead concept. It should have been a long time ago, but today the idea is pure suicide.
I think in this case, the wallet had some source available parts, but the firmware itself was closed.

Security through obscurity is super dead in the AI era.
 
Last edited:
Top Bottom