Hardware Wallets Aren’t the Problem, Says Ledger Exec. AI Attackers Are
The $116 million Coldcard hack rattled Bitcoin holders last week. Ledger's top security executive says the headline missed the point entirely.
Speaking to Bloomberg, Ian Rogers, Ledger's Chief Human Agency Officer, argued the attack was not evidence that self-custody or hardware wallets are inherently risky. The real story, he said, is what AI lets attackers do to systems built on weak randomness.
Why Ledger Was Not Affected
The Coldcard vulnerability traced back to a 2021 firmware bug that routed seed generation through a software pseudorandom number generator instead of the device's hardware chip.
That produced entropy of roughly 40 to 72 bits, a small enough address space for an AI-powered attacker to scan systematically and locate private keys. TRM Labs traced 1,082 BTC drained in the first wave's 41-minute sweep on July 30.
Ledger generates entropy entirely in hardware, Rogers told Bloomberg, using a certified secure chip with no software fallback. The resulting address space is, in his words, "the number three with 67 zeros behind it." No attacker can brute-force that.
… Continue reading the full article at the original source below.


