Ledger: Error in Coldcard code went unnoticed for more than five years
8/5/2026, 11:24 AM • Евгения Слив

Charles Guillemet, Technical Director of Ledger, commented on the recent exploitation of a vulnerability in Coldcard hardware wallets. The expert emphasized the need for a thorough review of the methods of checking random number generators. In his opinion, this incident clearly demonstrated the limitations of the popular approach to open source. The error has been in the public database for more than five years, remaining completely unnoticed by experts. Charles Guillemet separately noted the difference between just published and really tested code. Ledger devices generate random bits through a dedicated Secure Element hardware module. This architecture completely lacks a software backup path, which has become Coldcard's main problem.
Ledger representatives also attributed the incident to the growing role of artificial intelligence tools. Such neural network systems significantly accelerate the search for vulnerabilities for attackers and defenders. There is no public evidence of hackers using artificial intelligence yet. However, social media users are actively discussing the possibilities of modern language models. The Claude Code neural network allegedly found the vulnerability in about eight minutes after the request. Hasib Qureshi, Managing Partner of the Dragonfly Foundation, had previously estimated the cost of such a check. According to his calculations, it would cost only two dollars to prevent an attack using AI.
The research company Galaxy Research continues to study in detail the scale of the network attacks that have occurred. Analysts have identified at least fifteen different attackers who successfully exploited the vulnerability. Experts estimated the losses from the three confirmed waves of theft at one hundred million dollars. Taking into account the estimated fourth wave, the total damage could rise to one hundred and thirty million. Hardware wallet manufacturers Trezor and Foundation have issued important warnings to customers. Scammers are actively sending phishing emails on behalf of well-known equipment manufacturers. The attackers offer users to undergo a mandatory audit to protect their own savings. Owners of digital assets are advised to ignore such messages and check the firmware themselves.
