Ledger CTO argues Coldcard exploit highlights the need for certified hardware randomness and AI-driven wallet security improvements.
Security & Exploits ·
Ledger's CTO Charles Guillemet has characterized the recent Coldcard exploit as instructive for hardware wallet security, arguing that independently certified hardware random number generators are critical for safe creation of wallet recovery phrases. The Coldcard flaw, which affected devices using a firmware build from March 2021, relied on a software fallback rather than the device's dedicated randomness source when generating private keys, enabling theft totaling roughly $130 million. Guillemet emphasized that Ledger's own devices avoid this vulnerability by drawing recovery phrases directly from a certified hardware random number generator built into a Secure Element, with no software alternative path.
Beyond the immediate incident, Guillemet framed the exploit as evidence that artificial intelligence is fundamentally altering both attack and defense strategies in cryptography. He noted that the flaw remained undetected in publicly available code for over five years until an adversary reportedly used AI tools to locate it—a shift that forces security teams to operate at comparable machine speed. Ledger states it has deployed AI alongside human engineers and cryptographers over the past two years to proactively identify vulnerabilities, supplementing these efforts through its Donjon research laboratory.
Questions remain about how hardware wallet security will be systematically evaluated going forward and whether industry-wide standards for certified randomness and AI-assisted auditing will emerge.