By Tyler Warner
5 min read
Morning Minute is a daily newsletter written by Tyler Warner. The analysis and opinions expressed are his own and do not necessarily reflect those of Decrypt.
GM!
Today’s top news:
Coldcard is one of the most trusted hardware wallets in Bitcoin, the kind of air-gapped, offline device serious holders use to keep coins in deep cold storage. Last week, it became the center of one of the largest self-custody thefts ever. Attackers began systematically draining Bitcoin from Coldcard wallets, exploiting a flaw that let them regenerate users’ private keys without ever touching the physical device.
The cause is a firmware flaw, not phishing. A March 2021 Coldcard update drew wallet seeds from a weak software fallback instead of the hardware random generator, collapsing an Mk3’s key security to about 40 bits from the intended 128. That made the keys guessable, which is why coins that sat untouched for years are being swept from wallets that never connected to the internet. One Canadian victim lost 18.25 BTC from keys kept in a safety deposit box, writing that the hardest part was that he “did everything right.”
The theft grew all weekend. What started Thursday as an estimated $38 million drain kept climbing as researchers traced more of it. Galaxy Research now tracks roughly 1,367 BTC stolen, about $88.6 million, across 4,585 addresses in three distinct waves, and flagged the newest wave Saturday. Galaxy is warning that the exploit is ongoing and that every vulnerable device will eventually be emptied, and it has handed roughly 600 suspected attacker addresses to federal investigators. A potential 4th wave of attacks has the damage nearing $114M though researchers say some of the latest attacks may be avoidable by front-running the transaction settlements in the mempool.
Coinkite, Coldcard’s maker, said it has to assume an attacker used AI to comb its open-source firmware for the flaw, and admitted its own AI review of the same code weeks earlier “did not find this bug or anything serious.” Galaxy’s head of research Alex Thorn said the sweeps look programmatic and were “probably orchestrated with a large language model.” Defenders and attackers had the identical tool, and this time it only worked for the attacker.
In barely a week, an AI model cracked a post-quantum cryptography candidate humans couldn’t break, OpenAI’s models escaped a sandbox to breach other companies’ servers, and now attackers have used AI to drain $89 million from wallets sold as the gold standard of self-custody. AI is quickly becoming crypto’s biggest enemy. And one of crypto’s fundamental pillars, self-storage which makes one sovereign and in control of their wealth, is not under serious attack.
Decrypt-a-cookie
This website or its third-party tools use cookies. Cookie policy By clicking the accept button, you agree to the use of cookies.