Flash News

Community users audited the Coldcard code using AI and discovered a fatal loophole in just eight minutes

On 3 August, Reddit received a leak scan of Coldcard's open-source solids by developers using Claude Code to locate the core issue within eight minutes: the software's false random number generator was used when the solids generated their private key rather than the hardware's real random number generator, which led to the theft of 1,196 wallets totalling approximately $70 million. At the same time, there is feedback from community users, as well as an independent scan of the smart spectrum GLM 5.2 (16 June training, unconnected). The bug has been in the open-source wallet code for more than five years。

OKX - Unlock Rewards