AI is reshaping wallet security, Jameson Lopp says after Coldcard thefts

0
1
AI is reshaping wallet security, Jameson Lopp says after Coldcard thefts



AI is reshaping wallet security, Jameson Lopp says after Coldcard thefts

The flaw behind more than $83 million in Coldcard bitcoin thefts is about more than a single hardware wallet failure, according to Casa co-founder Jameson Lopp. It shows a broader change in cybersecurity, with artificial intelligence reducing the time needed for both attackers and defenders to uncover software vulnerabilities.

In The Block’s The Starting Block podcast, Lopp claimed that large language models (LLMs) are changing software security by minimizing the cost of discovering bugs.

“Advancements in large language models are drastically changing the security landscape,” he said, claiming that the Coldcard incident is one of the first examples of the phenomenon, which is expected to have ramifications for many wallets.

A race that cuts both ways

According to Lopp, it is less a case of malfunctioning hardware than that of changing security software. From being the sole privilege of well-funded security teams, AI-powered code analysis has gone mainstream. As a result, attackers can now access public code repositories for missed vulnerabilities prior to developers finding them.

The CEO of Coinkite, Rodolfo Novak, came to the same conclusion while acknowledging his responsibility in relation to the firmware bug. According to him, the incident is “a sober reality of the new AI paradigm,” with AI-assisted audits being able to uncover flaws much faster than traditional manual audits.

Surprisingly, in its previous report, Cryptopolitan mentioned that Coinkite had employed an artificial intelligence application to analyze its coding before being hacked.

As reported by Tradingview, that analysis was unable to detect the weakness, highlighting the fact that both attackers and defenders have access to similar AI technology, which gives an advantage to the one who detects the flaw first.

What actually went wrong inside the device

The weakness emerged due to the method of generating recovery wallet keys in some Coldcard firmware versions. As per information shared by Block’s Bitcoin engineering and security team, reported by the New York Post, the vulnerable devices employed certain predictable chip information (such as processor serial number and clock data) instead of using proper randomness in generating the numbers.

As a result, cybercriminals were able to reconstruct the recovery phrases used in the wallets and to steal the funds without physically accessing the wallet.

The defective firmware was introduced in March 2021 and was repaired only in the release of version 4.21. According to Coinkite, simply updating the firmware doesn’t solve the problem. Individuals who created wallets using the flawed versions should generate a new recovery seed and transfer their money since the vulnerability is closely connected with the previously used seed phrase.

Galaxy Research stated that on July 30, criminals managed to steal 1,082.65 BTC from 1,196 wallets in about 40 minutes. After that, more attacks took place, including the last wave seen by Alex Thorn of Galaxy, which seemed to be directed at multi-sig wallet holders as opposed to the earlier attacks targeted solely at single-sig users.

Popular Bitcoin commentator Guy Swann stated that the incident is “the worst hit in bitcoin history” for cautious owners of the virtual currency.

Where “don’t trust, verify” runs out

For Lopp, the breach also exposes the limits of one of Bitcoin’s best-known principles: “Don’t trust, verify.”

“It’s a good mantra,” he said, “but you have to understand that verification of complex software and hardware is simply not feasible for 99.9% of the population.”

According to Lopp, users will ultimately place their trust in a third party to validate the information. Rather than relinquish the ability to use their own wallets, Lopp advocates for users to diversify their trust by utilizing multiple hardware wallets and software applications.

Zach Herbert, CEO of Foundation, expressed the same opinion on the podcast, stating that it’s “really dangerous” to conclude that self-custody has failed considering just one case. On the contrary, he suggests that the industry needs to improve its security practices.

Lorenzo Valente, who is associated with ARK Invest, claimed that many users have merely traded their exchange counterparty risk for “software risk, hardware risk, supply-chain risk, phishing risk, backup risk.”

The case for independent audits

This occurrence has once again sparked the demand for firmware audits by an independent party in place of total reliance on the vendor’s self-review. Cryptopolitan recently published an article discussing whether open-source code presents adequate security, and the Coldcard incident is further proof of this argument.

According to Andrew Lazutkin, the Chief Technological Officer at Tangem, publicly accessible code should not be assumed to be secure. As he explained, “Security comes from strong architecture, thorough testing and independent verification.”

Lopp commented that major hardware wallet disclosures had occurred “a dozen times” and believed that all those incidents had contributed to the improvement in the industry. The next question that needs to be answered is whether Coinkite will implement its promised technical post-mortem and more widespread independent security assessments before AI-enabled hackers discover the next weakness.

 

Don’t just read crypto news. Understand it. Subscribe to our newsletter. It’s free.



Source link