Ledger says the $116 million Coldcard hack stemmed from weak seed generation, not an inherent flaw in self-custody or hardware wallets. Ian Rogers, Ledger's Chief Human Agency Officer, told Bloomberg that a 2021 firmware bug sent seed creation through a software pseudorandom number generator instead of Coldcard's hardware chip, reducing entropy to roughly 40 to 72 bits and leaving a small enough space for attackers to brute-force private keys. TRM Labs said 1,082 BTC was drained in the first 41-minute sweep on July 30. Rogers contrasted that with Ledger's use of a certified secure chip and no software fallback for entropy generation. He said the episode also highlights wider AI-era security risks: better automated vulnerability hunting, faster AI-assisted coding that expands attack surfaces, and enterprise agents being given access to internal secrets such as email, Slack and credentials. Ledger said it previously found a similar flaw in Trust Wallet in 2022 and helped users move funds through responsible disclosure.