AI exploits force Bitcoin holders into institutional custody
- Coldcard firmware bugs enabled attackers to brute-force predictable keys and steal over $130 million in Bitcoin.
- Attackers used AI models to find code flaws and front-run transactions in the public mempool.
- The crisis is forcing self-custody holders toward multi-vendor multisig setups or institutional custodians.
A preprocessor macro error in Coldcard firmware destroyed single-signature Bitcoin self-custody overnight. Cryptographic signatures link 58 flawed GitHub commits directly to CoinKite CTO Peter Gray's GPG key, revealing a disabled random number generator that defaulted to 32 bits of predictable entropy. What began as a hardware failure expanded into an automated systemic crisis as AI agents weaponized the flaw across public blockchains.
On TFTC, Galaxy Research head Alex Thorn tracked automated drain waves moving through compromised keys to sweep over 1,500 Bitcoin. The first wave hit with programmatic precision, consolidating outputs using hardcoded fee rates. While early attackers inadvertently exposed themselves through commercial RPC endpoints, the sheer speed of key grinding demonstrated how cheap GPU clusters and unrestricted large language models turned latent code bugs into automated execution scripts.
"Wave one alone swept through 41 minutes of programmatic drains, consolidating unspent outputs into holding addresses with rigid 30 sat/vbyte fees."
- Alex Thorn, TFTC: A Bitcoin Podcast
The fallout extended beyond stolen wallet balances. On Bitcoin And, reports surfaced that automated AI probes bombarded swap provider Boltz Exchange and Zeus Lightning with rapid-fire infrastructure probes. The overwhelming volume of machine-speed security queries forced Boltz to suspend operations indefinitely, illustrating how small open-source development teams are unable to defend public endpoints against relentless AI scanning.
Attempting to rescue exposed UTXOs triggered secondary battles inside the Bitcoin mempool. On Ungovernable Misfits, Mempool.space researcher Orange Surf explained how mempool snipers monitored public transactions from flawed addresses to execute replace-by-fee front-running attacks. To bypass public front-runners, distressed holders routed more than 5,600 Bitcoin through Marathon's Slipstream private transaction relay, using non-public mining paths to execute emergency multi-signature key rotations.
The crisis rapidly shifted from defensive triage to aggressive code audits across the ecosystem. On Stacker News Live, developer Rob Hamilton ran open-weight Chinese LLMs like Kimi K3 against open-source repositories. A coalition named the Bitcoin Red Team spent $40,000 on API tokens to scan 390 repositories, processing 171,000 lines of code. On Bitcoin And, host David Bennett detailed how the automated harness surfaced nearly 5,000 security flaws across core infrastructure.
"The automated harness flagged 4,962 security findings, including 85 critical and 635 high-severity vulnerabilities."
- David Bennett, Bitcoin And | Bitcoin & Economic News
These automated findings exposed a fundamental paradox in open-source security. While open code historically enabled public verification, accessible repositories now allow hostile LLMs to uncover vulnerabilities faster than human maintainers can write patches. On Citadel Dispatch, Matt Odell noted that open-source maintainers must now operate under the assumption that hostile AI models are continuously auditing every published line of code for exploit vectors.
The failure of top-tier hardware shattered long-standing self-custody assumptions among long-term holders. On Bitcoin And, David Bennett observed that loss of faith in single-vendor hardware is driving non-custodial holders toward regulated custodians like Unchained and Coinbase or Wall Street spot ETFs. While institutional migration offers capital safety, it forces previously un-KYC'd Bitcoin holders back into identity-tracked regulatory systems.
Single-signature cold storage under a mattress is dead. The intersection of flawed vendor hardware and machine-speed code exploitation marks a permanent end to single-device trust in Bitcoin.
Source Intelligence
- Deep dive into what was said in the episodes
CATASTROPHIC COLDCARD BUG • Aug 3
- The bug, which existed for five years, appears to have been recently identified with assistance from AI, possibly through OpenAI's Cypher program utilized by Rob Hamilton's team for auditing Bitcoin projects.
Also discussed on this episode: (12)
Custody (6)
- A critical vulnerability in Coldcard hardware wallets (versions 4.0.1 and later, or any model after 4.0.0) compromises private keys due to a faulty random number generator.
- The catastrophic Coldcard bug, introduced in March 2021, compromises seeds generated on any device after that date unless sufficient dice roll entropy (over 100 rolls) or a passphrase was used.
- Hosts advise all Coldcard users to immediately move their funds off the devices and to cease using the product entirely, regardless of previous protective measures like passphrases or multisig.
- The hosts had previously conducted Coldcard workshops since December 2019 at Chaincode Labs with figures like Evan Kaludis and James O'Byrne, demonstrating features like dice rolls and passphrases.
- Hosts concede to complacency, having placed too much trust in CoinKite's NVK and Peter; they now believe the concept of a "magic bullet" beginner-friendly solution for high-value self-custody is dead.
- The hosts will now refrain from directly recommending specific custody solutions, instead laying out options and emphasizing multi-vendor multisig and robust passphrases as critical for long-term secure Bitcoin storage.
Media (2)
- The hosts express deep regret and take accountability for recommending Coldcard for seven years, admitting their past confidence was misplaced despite consistently advocating "don't trust, verify."
- The Coldcard vulnerability was publicly disclosed on August 3, 2023, at Bitcoin block height 960885, prompting hosts to release this podcast immediately to maximize user notification efforts.
Safety (4)
- The Bitcoin community has rallied to assist affected users, with Rob Hamilton (@Roboneham on X) publishing an extensive guide detailing Coldcard vulnerabilities, migration options, and recovery steps.
- Attackers are actively brute-forcing compromised Coldcard seeds using GPUs, while authorities are investigating an attacker who reportedly pinged a centralized API provider to look up vulnerable addresses.
- The hosts clarify the vulnerability is entirely CoinKite's responsibility, stating their firm 1031 is a minority investor (under 10%) with NVK and Peter maintaining majority ownership and control.
- Users are strongly advised not to update Coldcard firmware, as new releases may brick devices; instead, the immediate priority should be transferring all funds off the compromised hardware.
