Hardware Wallets Aren’t the Problem, Says Ledger Exec. AI Attackers Are
The $116 million Coldcard hack rattled Bitcoin holders final week. Ledger’s high safety government says the headline missed the level completely.
Speaking to Bloomberg, Ian Rogers, Ledger’s Chief Human Agency Officer, argued the assault was not proof that self-custody or {hardware} wallets are inherently dangerous. The actual story, he stated, is what AI lets attackers do to methods constructed on weak randomness.
Why Ledger Was Not Affected
The Coldcard vulnerability traced again to a 2021 firmware bug that routed seed technology by a software program pseudorandom quantity generator as an alternative of the gadget’s {hardware} chip.
That produced entropy of roughly 40 to 72 bits, a sufficiently small deal with house for an AI-powered attacker to scan systematically and find non-public keys. TRM Labs traced 1,082 BTC drained in the first wave’s 41-minute sweep on July 30.
Ledger generates entropy completely in {hardware}, Rogers advised Bloomberg, utilizing an authorized safe chip with no software program fallback. The ensuing deal with house is, in his phrases, “the quantity three with 67 zeros behind it.” No attacker can brute-force that.
It isn’t the first time Ledger has caught this type of flaw. In 2022, the company recognized the same bug in Trust Wallet and labored by accountable disclosure to assist customers transfer funds to security. BeInCrypto’s protection of Coldcard’s ongoing theft waves reveals how briskly and systematic the exploitation turned as soon as the vulnerability was recognized.
3 Ways AI Has Changed the Threat
Rogers laid out three compounding threats.
First, AI offers attackers extra firepower to search out vulnerabilities in any system, not simply crypto. He cited assaults on US water infrastructure as a part of the similar pattern, since the underlying instruments are basic function.
Second, AI-assisted growth means extra code ships sooner throughout the business, increasing the assault floor for everybody. BeInCrypto reported on how AI-powered smart contract exploits now outpace the instruments constructed to detect them.
Third, and that is the place Rogers goes past the Coldcard story, enterprises are deploying brokers that maintain entry to inside secrets and techniques like e-mail, Slack, and credentials. Bloomberg framed the Coldcard exploit as a {hardware} story. Rogers frames it as an early sign of a wider AI-era safety drawback.
The Agentic Threat Rogers Warned About
At the finish of final yr, Rogers described a future the place folks hand AI brokers their passwords, bank cards, and identities as a harmful, unmanaged danger. Few folks understood what he meant at the time. They do now.
His analogy compares AI brokers and secrets and techniques to a teen and automotive keys. The keys don’t reside in the teenager’s room. A mother or father decides, based mostly on context, when entry is acceptable. A Monday morning drive to high school is ok. A Friday night time after a celebration isn’t. The similar logic, Rogers argues, should govern what any agent can entry and when.
Ledger already presents instruments that allow an agent maintain a pockets with out holding the non-public keys. The precept is the similar one which has all the time ruled {hardware} safety: safety by design, not by coverage.
Wherever your belongings are saved, try to be keen on the stage of safety that’s defending them.
Rogers advised Bloomberg.
The submit Hardware Wallets Aren’t the Problem, Says Ledger Exec. AI Attackers Are appeared first on BeInCrypto.
