Summary
- Ledger highlights the Coldcard exploit as a cautionary tale for the hardware Bitcoin wallet sector, asserting that its own devices remain secure.
- The firm emphasizes the necessity of independently verified hardware random number generators for the secure creation of wallet recovery phrases.
- Ledger points out that AI is hastening the discovery of vulnerabilities, compelling security teams to respond at unprecedented speeds.
Ledger, a manufacturer of hardware wallets, has issued a warning to the cryptocurrency sector in light of the recent Coldcard exploit.
Charles Guillemet, the Chief Technology Officer at Ledger, stated that the incident has revealed vulnerabilities in the way certain devices, particularly hardware cryptocurrency wallets, produce cryptographic randomness, while also demonstrating how artificial intelligence is transforming both attacks and defenses in the digital realm.
"This serves as a significant reminder that the entire security framework of a hardware wallet hinges on randomness," Guillemet told Decrypt. "Implementing cryptography securely is a complex challenge, and the Coldcard incident has starkly highlighted this issue in a costly manner."
These remarks come as the repercussions of the Coldcard exploit continue to unfold.
Recently, Coinkite, the creator of Coldcard, revealed a vulnerability in its air-gapped Bitcoin hardware wallet, dating back to a firmware update from March 2021. This flaw allowed the device to use a software fallback instead of its hardware random number generator to create wallet recovery seeds, making some private keys susceptible to guessing and enabling theft.
As of now, losses attributed to this issue have reached approximately $130 million, with additional thefts still under investigation. On Sunday, Coinkite issued a firmware update to address the vulnerability and urged users to transfer their funds to new wallets.
Coinkite did not respond to Decrypt's request for comment regarding this incident.
Ledger has confirmed that its hardware wallets were unaffected due to a different method of generating recovery phrases.
"Our hardware wallets derive their root secret (the 24-word Secret Recovery Phrase) from a true hardware random number generator embedded directly within a certified Secure Element, without any software fallback options," Guillemet explained. "This generator ensures that every seed has a full 256 bits of entropy."
This incident raises broader concerns regarding the assessment of security for hardware wallets, according to Ledger.
"Open source does not equate to being reviewed," Guillemet remarked. "This flaw existed in publicly available code for over five years until an adversary reportedly utilized AI to uncover it, underscoring that openness and thorough review are not synonymous."
He noted that AI is revolutionizing cybersecurity by enabling attackers to quickly scan code, identify configuration errors, and detect vulnerabilities at unprecedented speeds. "As a result, defensive measures must evolve to match this pace," he said, emphasizing the need for security to be integrated into design, hardware, and mathematics.
In May, a security researcher utilizing Claude Opus 4.8 uncovered a four-year-old vulnerability that could have allowed for unlimited minting of Zcash, leading to widespread panic among investors and a more than 40% drop in Zcash’s value in a single day as a result.
