Crypto & Web3·Aug 4, 2026

Ledger Says Coldcard Exploit Shows Bitcoin Wallet Security Must Adapt to AI

Ledger CTO Charles Guillemet says the Coldcard exploit underscores why certified hardware randomness matters—and why AI is reshaping wallet security.

Decrypt3 min readVerified
Ledger Says Coldcard Exploit Shows Bitcoin Wallet Security Must Adapt to AI
Image · Decrypt
The gist
5-point summary · 1 min

Ledger CTO Charles Guillemet says the Coldcard exploit underscores why certified hardware randomness matters—and why AI is reshaping wallet security.

  • In brief Ledger says the Coldcard exploit is a warning for the hardware Bitcoin wallet industry but says its own devices were not affected.
  • The company argues independently certified hardware random number generators are essential for securely creating wallet recovery phrases.
  • Ledger says AI is accelerating vulnerability discovery and forcing security teams to defend at machine speed.
  • "That generator produces the full 256 bits of entropy for every seed."For Ledger, the incident raises broader questions about how hardware wallet security is evaluated."Open source and reviewed are not the same thing," Guillemet said.
  • "It has to be certified by people whose job is trying to break that claim, not just asserted by the vendor."Daily Debrief NewsletterStart every day with the top news stories right now, plus original features, a podcast, videos and more.
$130 million40%March 2021
In this article

In brief Ledger says the Coldcard exploit is a warning for the hardware Bitcoin wallet industry but says its own devices were not affected. The company argues independently certified hardware random number generators are essential for securely creating wallet recovery phrases. Ledger says AI is accelerating vulnerability discovery and forcing security teams to defend at machine speed. Hardware wallet maker Ledger says the recent Coldcard exploit should serve as a warning for the cryptocurrency industry.According to Ledger CTO Charles Guillemet, the incident exposed weaknesses in how some devices, in this case hardware cryptocurrency wallets, generate cryptographic randomness while showing how artificial intelligence is reshaping both cyberattacks and digital defenses."We're treating this as a serious reminder of how the whole security model of a hardware wallet lives or dies on randomness," Guillemet told Decrypt. "Cryptography is hard and implementing it securely is harder. This week's Coldcard incident made that visible in the most expensive way possible."The comments come as the fallout from the Coldcard exploit continues to grow.Last week, Coldcard maker Coinkite disclosed a flaw in the air-gapped Coldcard Bitcoin hardware wallet that traces back to a March 2021 firmware build. The bug used a software fallback instead of the device's hardware random number generator to create wallet recovery seeds, making some private keys guessable and allowing thieves to steal user Bitcoin.To date, losses have reached roughly $130 million while other thefts remain under investigation. On Sunday, Coinkite released patched firmware and urged affected users to move funds to newly generated wallets.Coinkite did not respond to Decrypt's request for comment for this story.Ledger said its own hardware wallets were not affected because they generate recovery phrases differently."Ledger hardware wallets draw their root secret (the 24-word Secret Recovery Phrase) from a true hardware random number generator built directly into a certified Secure Element, with no software fallback path," Guillemet said. "That generator produces the full 256 bits of entropy for every seed."For Ledger, the incident raises broader questions about how hardware wallet security is evaluated."Open source and reviewed are not the same thing," Guillemet said. "This flaw sat in public code for more than five years until, reportedly, an adversary used AI to find it, a reminder that being open and being reviewed are two different things."He said AI is changing cybersecurity by allowing attackers to scan code, search for configuration errors, and identify vulnerabilities "at machine speed.""That means defense has to move at the same speed," he said. "It needs to come from security by design, hardware, and math."In May, a security researcher using Claude Opus 4.8 discovered a four-year-old vulnerability that could have fueled unlimited minting of Zcash, leading to large-scale investor panic and sending Zcash down more than 40% in a single day in response.According to Guillemet, Ledger says it has spent the past two years using AI alongside human security engineers and cryptographers to review code and identify vulnerabilities before attackers can exploit them.“We also don't just rely on our own word for it,” he explained. “Our Donjon research lab exists to try to break our products before anyone else can.”To mitigate future risk, Guillemet said users evaluating any hardware wallet should understand how it generates randomness and whether that process has been independently certified."Randomness has to come from physics, not a formula," he said. "It has to be certified by people whose job is trying to break that claim, not just asserted by the vendor."Daily Debrief NewsletterStart every day with the top news stories right now, plus original features, a podcast, videos and more.

Integrity note  ·  Xela does not rewrite or paraphrase article content. The excerpt above is the source publication's own words, sanitized for display. For the full piece — including any quotes, charts, or images — read it at Decrypt. Xela's rewritten version is off for this story, so there's no editorial angle attached — you're getting the source's reporting unfiltered. When the rewrite is on, we add a What this means block underneath with the operator/trader takeaway.

What people are saying

Discussion

Hot takes

0/280

Loading takes…

Comments

Discussion · 0

Sign in to comment, like, and save articles.

Sign in

Loading comments…

Newsletter

Track crypto & web3 every morning.

Daily digest tuned to this beat. The 5 stories most worth your time. Unsubscribe anytime.