Price:

Coldcard bug drains 1,400 BTC as AI exploits spread

Aug 18, 2026Summary from 2 podcasts.
  • A five-year Coldcard firmware flaw let thieves drain up to 1,800 Bitcoin.
  • Automated AI tools are auditing open-source Bitcoin code to exploit zero-day vulnerabilities.
  • A Trezor logistics data breach exposed 11,000 buyers to physical safety threats.

Hardware self-custody is facing a double crisis. A silent five-year firmware flaw in Coinkite's Coldcard allowed attackers to sweep up to 1,800 Bitcoin, while automated AI scanners simultaneously probe open-source code for instant exploits.

On Ungovernable Misfits, co-host Q detailed how a flawed 2021 code change caused Coldcards to silently revert to a weak, software-based random number generator during seed creation. Unless users added manual entropy like dice rolls, automated scripts easily brute-forced the generated keys. Criticism mounted after Coinkite leadership deleted historical social media posts and on-chain sleuths caught lead developer Doc Hex using a secondary online persona to approve his own code libraries.

"Anyone using Coldcard seeds generated without manual entropy must rotate their keys immediately."

- Q, Ungovernable Misfits

The hardware flaw coincides with an escalating AI assault on Bitcoin software layer infrastructure. An unauthenticated bug in BTCPay Server exposed critical node credentials, letting automated scripts force close Lightning channels and steal funds from operators, including Foundation Devices. The pressure forced swap provider Bolts.exchange to permanently shut down.

Uncensored open-weight models like Kimi k3 have effectively given attackers institutional-grade auditing power. In response, Anchor Watch CEO Rob Hamilton launched the volunteer Bitcoin Red Team, spending tens of thousands of dollars scanning 500 open-source repositories to disclose flaws before bad actors exploit them. On Bitcoin And, researcher Cali warned that decades of legacy C code are now collapsing under continuous AI scanning.

"The tools finding software bugs are now leaking their own secrets."

- David Bennett, Bitcoin And

The security tools themselves carry vulnerabilities. Researcher Alexander Panfilov discovered that major AI providers encrypted internal model reasoning traces using provider-wide keys rather than session-specific keys. By passing an encrypted reasoning block from Claude Opus into Claude Haiku, researchers bypassed safety guardrails, leaking 182 stolen credentials and 62 active API keys from public session logs.

Three days after the initial Coldcard disclosures, physical security risks compounded the crisis. A third-party logistics breach exposed records for over 11,000 Trezor customers, leaking full names, phone numbers, and home addresses. Foundation CX head q warned on Ungovernable Misfits that third-party leaks transform digital privacy breaches into direct physical extortion threats, prompting co-host Max to urge buyers to purchase hardware in person using cash or Lightning.

To counter both data leaks and code exploits, teams are pulling their auditing infrastructure in-house. Cake Wallet COO Seth explained that his team transitioned to running local open-weight AI models on NVIDIA DGX Spark units. Running local clusters allows developers to audit code and scan for vulnerabilities without exposing sensitive repository data or prompt histories to external cloud providers.

The illusion of set-it-and-forget-it security is shattered. Between hardware entropy failures, AI zero-day scanners, and shipping leaks, sovereign storage now requires relentless operational vigilance.