GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Community users used AI to audit Coldcard code, discovering a critical vulnerability in just 8 minutes

Source: x.com Event types: Security/Hacker
Developers on Reddit used Claude Code to scan the Coldcard open-source firmware for vulnerabilities, pinpointing the core issue within 8 minutes: When generating private keys, the firmware invoked a software pseudo-random number generator instead of a hardware true random number generator, and it was this vulnerability that led to the theft of approximately $70 million in BTC from 1,196 wallets. Meanwhile, community users also reported that using Zhipu GLM 5.2 (trained on June 16, offline) for an independent scan similarly discovered this vulnerability. This bug has existed in the open-source wallet code for over five years.

Related projects