The case is drawing attention because the AI found, in a short time, a wallet vulnerability at a level that could be reproduced and that was used in a real attack. [Photo: Reve AI]

Anthropic's coding-focused AI model Claude Code is reported to have found a key security vulnerability in the Bitcoin hardware wallet Coldcard in just 8 minutes. The vulnerability is known to have been exploited in an actual attack, and some in the cryptocurrency community estimate losses could exceed $100 million.

On Aug. 3 local time, blockchain outlet U.Today reported that developers and security researchers asked Claude Code to review only the Coldcard wallet source code, and it independently identified a vulnerability used in a past attack.

According to a Reddit post, Claude Code reasoned for about 8 minutes before finding the problem area. Security researcher Medusa said on X, formerly Twitter, that "Claude Code found a Coldcard wallet vulnerability with a single prompt" and that "thinking time was 8 minutes. We are not ready for what's coming."

The issue is reported to be related to the way the Coldcard firmware generates cryptographic random numbers. Cryptocurrency hardware wallets use unpredictable random numbers to generate private keys and sign transactions. If sufficient entropy is not secured during random number generation or values become predictable, there is a risk that private keys will be exposed.

The vulnerability is linked to what is described as one of the major breach incidents in the Bitcoin hardware wallet industry. Initial analysis estimated an attacker stole more than 1,080 BTC in less than an hour. The community later raised the possibility that total losses could exceed $100 million.

Some in the industry say the incident goes beyond a single manufacturer's security failure and reveals problems across the hardware wallet industry as a whole.

BlockTower Capital founder Ari Paul argued the Coldcard breach is not just one company's problem but an example showing fundamental security vulnerabilities shared by the cryptocurrency wallet industry. The analysis says a review is needed across core hardware wallet security elements such as random number generation and private key protection structures.

There is also the possibility the attack is still ongoing. Alex Thorn, head of Galaxy Research, said based on on-chain data that a fourth wave of an organised attack related to Coldcard is continuing. He said 218 suspicious transactions were identified between Bitcoin blocks 960,778 and 960,792, and that about 389 BTC moved from 462 victim addresses.

This has prompted calls for urgent action by Coldcard users. Thorn stressed that remaining funds on affected devices should be moved immediately to other wallets. He also advised setting sufficient transaction fees to increase the likelihood that transactions will be confirmed before the attacker’s.

The case shows the possibility that AI can quickly find real cryptocurrency security vulnerabilities, while also highlighting the risk that existing security flaws can lead to large-scale asset theft. Because the issue occurred in random number generation, a core area of wallet security, stronger security verification across the hardware wallet industry is expected to be unavoidable. The scale of losses among Coldcard users and whether further attacks spread are emerging as key market concerns.

Keyword

#Anthropic #Claude Code #Bitcoin #Coldcard #Galaxy Research
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.