Someone likely used AI to drain nearly 600 BTC, worth $38 million, from roughly 500 dormant wallets yesterday as part of a seed phrase exploit targeting Coldcard hardware wallets. The attack took just 25 minutes to move the BTC from 500 single-signature addresses into a single address. Coldcard maker Coinkite confirmed that seed generation within its Mk3 wallet and subsequently updated versions beyond March 2021 may not have been random at all. The company believes AI was used to discover the exploit. The bug was traced to a mis-written compile-time check where a macro was set to zero, causing the firmware to fall back to a weak pseudo-random number generator instead of the hardware random number generator.
Source: Read the original article

