Malicious actors will use new tools to identify the smallest software flaws, the maker of high-security Bitcoin wallets has warned

The theft of at least $89 million in cryptocurrency that was supposedly safely stored in high-security hardware wallets has prompted the producer to warn that a “new AI paradigm” is redefining cybersecurity.

Hardware wallets are physical devices that store the private keys needed to access cryptocurrency and have long been considered safer than leaving digital assets on exchanges.
Last week, however, users of some Coldcard wallets saw their funds drained by unidentified perpetrators in a series of attacks.

The theft was unusual because the attackers managed to determine users’ keys after discovering that the wallets’ algorithm did not generate sufficiently random numbers. The devices themselves were not hacked and were not connected to the Internet, as is typical with so-called cold storage.




Cryptocurrencies function through distributed ledgers that record transactions, while secret cryptographic keys are used to verify that a transfer was authorized by the legitimate owner.

“We believe this is a sober reality of the new AI paradigm,” Rodolfo Novak, CEO of the Canadian company Coinkite Inc., wrote Friday in a message apologizing for the flaw in Coldcard devices.

“AI-assisted code review can now find latent bugs at a speed that is outpacing even the industry’s most seasoned experts,” he added. “If your firmware is open-source or has ever been public, assume it’s already being read by attackers and defenders alike.”

Coinkite issued its first warning to customers on Thursday, urging them to spread the word that users needed to update the affected firmware, originally released in March 2021, and move their Bitcoin to new accounts protected by newly generated seeds.

By Sunday, digital financial platform Galaxy said it had identified three separate waves of attacks against Coldcard users, resulting in the theft of 1,367.05 BTC, worth about $88.6 million at the time. On Monday, it warned of a likely fourth attack and estimated that the losses could rise to 2,055 BTC, valued at roughly $130 million.

The incident demonstrated that hardware wallets carry risks of their own and are not necessarily safer than centralized cryptocurrency storage services. Some industry observers remain hopeful that the transparent nature of blockchain transactions will make it more difficult for the thieves to convert the stolen assets into cash.

“If your goal was wealth there may still be one path that leaves everyone better off,” one such commentator urged. “Return the funds. Accept a negotiated security bounty with CoinKite.”

Read the full article here

Share.
Leave A Reply

Exit mobile version