Advantus Media, Inc. and QuoteInspector.com
Over 4,500 of these wallets have been compromised.
Coinkite, the Canadian supplier for Coldcard, informed users late last week about a significant vulnerability and the breach of certain wallets.
"The source code of Coldcard has always been open and accessible to the public, leading us to believe that someone utilized AI to examine earlier firmware versions and discovered this vulnerability," the blog of the company mentions. "Several weeks prior, we employed one of the finest AI models to examine the code for security vulnerabilities, and it failed to detect this bug or any significant issues."
"Those executing attacks and those countering them possess identical AI tools, but today, it didn’t assist us; it solely aided the perpetrators," Coinkite remarked.
Engineers at Block Inc., a fintech firm founded by Twitter co-founder Jack Dorsey, reported a flaw in Coldcard that resulted in the predictability of the seed phrase—a lengthy series of words utilized to access the wallet.
They think the problem occurred due to the way Coinkite executed the random number generator that creates these phrases. In particular, one of the wallet's features created keys utilizing set values, like the serial number of the device.
Coinkite has issued a firmware update to resolve the problem.
source: bloomberg.com
Coinkite, the Canadian supplier for Coldcard, informed users late last week about a significant vulnerability and the breach of certain wallets.
"The source code of Coldcard has always been open and accessible to the public, leading us to believe that someone utilized AI to examine earlier firmware versions and discovered this vulnerability," the blog of the company mentions. "Several weeks prior, we employed one of the finest AI models to examine the code for security vulnerabilities, and it failed to detect this bug or any significant issues."
"Those executing attacks and those countering them possess identical AI tools, but today, it didn’t assist us; it solely aided the perpetrators," Coinkite remarked.
Engineers at Block Inc., a fintech firm founded by Twitter co-founder Jack Dorsey, reported a flaw in Coldcard that resulted in the predictability of the seed phrase—a lengthy series of words utilized to access the wallet.
They think the problem occurred due to the way Coinkite executed the random number generator that creates these phrases. In particular, one of the wallet's features created keys utilizing set values, like the serial number of the device.
Coinkite has issued a firmware update to resolve the problem.
source: bloomberg.com




