Hardware Wallets Aren’t the Problem, Says Ledger Exec. AI Attackers Are

The $116 million Coldcard hack rattled Bitcoin holders last week. Ledger’s top security executive says the headline missed the point entirely.
Speaking to Bloomberg, Ian Rogers, Ledger’s Chief Human Agency Officer, argued the attack was not evidence that self-custody or hardware wallets are inherently risky. The real story, he said, is what AI lets attackers do to systems built on weak randomness.
Why Ledger Was Not Affected
The Coldcard vulnerability traced back to a 2021 firmware bug that routed seed generation through a software pseudorandom number generator instead of the device’s hardware chip.
That produced entropy of roughly 40 to 72 bits, a small enough address space for an AI-powered attacker to scan systematically and locate private keys. TRM Labs traced 1,082 BTC drained in the first wave’s 41-minute sweep on July 30.
Ledger generates entropy entirely in hardware, Rogers told Bloomberg, using a certified secure chip with no software fallback. The resulting address space is, in his words, “the number three with 67 zeros behind it.” No attacker can brute-force that.
It is not the first time Ledger has caught this kind of flaw. In 2022, the company identified a similar bug in Trust Wallet and worked through responsible disclosure to help users move funds to safety. BeInCrypto’s coverage of Coldcard’s ongoing theft waves shows how fast and systematic the exploitation became once the vulnerability was known.
3 Ways AI Has Changed the Threat
Rogers laid out three compounding threats.
First, AI gives attackers more firepower to find vulnerabilities in any system, not just crypto. He cited attacks on US water infrastructure as part of the same trend, since the underlying tools are general purpose.
Second, AI-assisted development means more code ships faster across the industry, expanding the attack surface for everyone. BeInCrypto reported on how AI-powered smart contract exploits now outpace the tools built to detect them.
Third, and this is where Rogers goes beyond the Coldcard story, enterprises are deploying agents that hold access to internal secrets like email, Slack, and credentials. Bloomberg framed the Coldcard exploit as a hardware story. Rogers frames it as an early signal of a much broader AI-era security problem.
The Agentic Threat Rogers Warned About
At the end of last year, Rogers described a future where people hand AI agents their passwords, credit cards, and identities as a dangerous, unmanaged risk. Few people understood what he meant at the time. They do now.
His analogy compares AI agents and secrets to a teenager and car keys. The keys do not live in the teenager’s room. A parent decides, based on context, when access is appropriate. A Monday morning drive to school is fine. A Friday night after a party is not. The same logic, Rogers argues, must govern what any agent can access and when.
Ledger already offers tools that let an agent hold a wallet without holding the private keys. The principle is the same one that has always governed hardware security: protection by design, not by policy.
Wherever your assets are stored, you should be interested in the level of security that’s protecting them.
Rogers told Bloomberg.
Source: BeInCrypto
Cryptocurrency News
Random quote about money
"Деньгами надо управлять, а не служить им."













* to search the proxy database, just enter a country name, e.g. Russia, USA, Thailand