Hackers have stolen about $86 million worth of bitcoin from Coldcard hardware cryptocurrency wallets after exploiting a security vulnerability that compromised more than 4,500 devices, Bloomberg reports, citing Galaxy Research.


Canadian manufacturer Coinkite, which produces Coldcard wallets, alerted users late last week to a key-generation vulnerability that had compromised some devices.


The company said in a blog post that the Coldcard source code has always been open and publicly available, so we can only assume that someone used AI to analyse previous firmware versions and discovered this vulnerability.


It added that a few weeks ago, they used one of the best AI models available to review the code for security issues, and it did not find this bug—or anything else of significance.


Coinkite noted that “both attackers and defenders have access to the same AI tools, but this time they helped only the bad guys, not us.”


According to engineers at fintech company Block Inc., led by Twitter co-founder Jack Dorsey, the vulnerability made the wallets' seed phrases—the sequences of words used to recover access to cryptocurrency holdings—predictable.


They made it clear that the flaw stemmed from Coinkite’s implementation of the random number generator used to create seed phrases. One mechanism reportedly generated wallet keys using predetermined values, including the device’s serial number.


Coinkite has since released a firmware update to address the vulnerability.


Coldcard devices are so-called cold wallets, which remain offline and disconnected from the internet. They have long been regarded as one of the most secure methods of storing cryptocurrencies.


By Bakhtiyar Abbasov