A 2021 firmware flaw in Coldcard hardware wallets left some recovery seeds with insufficient randomness, and attackers have moved about 1,600 to 1,800 BTC from affected wallets since July 30, across thousands of addresses. According to Odaily, the stolen bitcoin is valued at more than $100 million.

Coldcard maker Coinkite said it must assume someone used AI to review its public firmware, while noting that the bug had existed for about five years and that AI involvement in the attacks has not been confirmed.

Shielded Labs researcher Taylor Hornby used a Claude Opus 4.8 audit agent to find a vulnerability in the Zcash Orchard shielded pool circuit that began in 2022. In testing, he was able to generate unlimited fake ZEC without detection, and developers fixed the issue within days; no theft was confirmed.

Blockchain analytics firm Chainalysis said the daily number of on-chain writes carrying malware instructions and command-and-control information rose from about 2.06 to 11.1, an increase of 440%.

ZEC
ZEC
1,526.63
+6.01%
BTC
BTC
85,660.89
+6.27%