Ledger says weak key generation drove $116 million Coldcard hack

Ledger says the $116 million Coldcard hack stemmed from weak seed generation, not an inherent flaw in self-custody or hardware wallets. Ian Rogers, Ledger's Chief Human Agency Officer, told Bloomberg that a 2021 firmware bug sent seed creation through a software pseudorandom number generator instead of Coldcard's hardware chip, reducing entropy to roughly 40 to 72 bits and leaving a small enough space for attackers to brute-force private keys. TRM Labs said 1,082 BTC was drained in the first 41-minute sweep on July 30. Rogers contrasted that with Ledger's use of a certified secure chip and no software fallback for entropy generation. He said the episode also highlights wider AI-era security risks: better automated vulnerability hunting, faster AI-assisted coding that expands attack surfaces, and enterprise agents being given access to internal secrets such as email, Slack and credentials. Ledger said it previously found a similar flaw in Trust Wallet in 2022 and helped users move funds through responsible disclosure.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.