The exploitation of a vulnerability in Coldcard has underscored the need to reevaluate the testing of random number generators in Bitcoin storage devices. This was stated by Ledger's CTO, Charles Guillemet, as reported by Decrypt.
He highlighted that the incident revealed the limitations of the principle that "open code means verified code." Guillemet pointed out that the flaw had been publicly accessible for over five years yet went unnoticed until the attacks began.
"Open code and verified code are not the same thing," said Ledger's CTO.
According to Ledger's documentation, the company's devices generate 256 random bits through a hardware generator located in the Secure Element. Guillemet noted that this architecture lacks a software backup path, which became an issue in the Coldcard case.
Ledger linked the incident to the increasing role of AI tools in code analysis. Guillemet remarked that such systems expedite the identification of vulnerabilities for both attackers and defenders. However, as of this writing, there is no public evidence that the hackers actually employed artificial intelligence.
In a report by U.Today, users on Reddit and X noted claims that Claude Code purportedly identified the vulnerability in about eight minutes after a request to check the source code.
this is insane
claude code found the COLDCARD wallet vulnerability with a single prompt, in just 8 minutes of thinking
we're not ready for what's coming pic.twitter.com/wh1LtEWuje
— Medusa (@MedusaOnchain) August 2, 2026
Previously, Hasib Qureshi, managing partner at venture fund Dragonfly, indicated that the attack on Coldcard's cold wallets could have been averted with a $2 code review using artificial intelligence.
Research from Galaxy indicates that at least 15 different attackers exploited the vulnerability, with analysts estimating losses from three confirmed waves to be around $100 million. With a potential fourth wave, the total could rise to approximately $130 million.
On August 4, hardware wallet manufacturers Trezor and Foundation alerted users about phishing attacks related to this incident. In some instances, scammers have sent emails pretending to be from manufacturers, offering to conduct a "hardware audit."
