According to developers and security researchers, Anthropic’s Claude Code independently discovered the vulnerability responsible for the Coldcard exploit after being asked only to inspect the wallet’s source code for security flaws. The AI reportedly required roughly eight minutes of analysis before flagging the issue.
A Reddit post claims that Claude Code was able to independently identify the same wallet vulnerability used in the attack after just eight minutes of reasoning.
“Claude Code found the COLDCARD wallet vulnerability with a single prompt, in just 8 minutes of thinking. We’re not ready for what’s coming,” researcher Medusa wrote on X.
The vulnerability reportedly stems from the way affected Coldcard firmware generated cryptographic randomness.
Random number generation is one of the most important security components for crypto wallets. They rely on unpredictable random values when creating private keys and producing digital signatures. If that randomness becomes predictable or lacks sufficient entropy, wallets become vulnerable.
The flaw has been linked to one of the largest hardware wallet compromises in Bitcoin’s history. Initial estimates show attackers stole more than 1,080 BTC in under an hour. More recent estimates circulating within the community place total losses above $100 million.
As reported by U.Today, BlockTower Capital founder Ari Paul recently argued that the Coldcard compromise exposed a fundamental weakness shared across the entire industry rather than a failure unique to one manufacturer.
Another wave of attacks
Unfortunately for Coldcard owners, the attack might not be over yet.
Alex Thorn, head of research at Galaxy, said on X that on-chain activity points to a fourth organized wave of Coldcard-related attacks.
According to Thorn, Bitcoin blocks 960,778 through 960,792 contained 218 suspicious transactions affecting 462 victim addresses and moving nearly 389 BTC.
He stressed that Coldcard users must immediately move any remaining funds off affected devices. They have also been advised to use transaction fees to maximize the chances of beating attackers to confirmation.





Be the first to comment