What happened

Coinkite warned customers that seeds generated by affected Coldcard firmware could be at risk and instructed users to move funds, update firmware, and create new seed material. Independent analysis traced the problem to a predictable random-number fallback and insufficient reseeding in older firmware paths.

The practical failure was not an online compromise of a wallet sitting in storage. Once a seed comes from a dramatically smaller search space, an attacker can enumerate candidates elsewhere and move funds without touching the physical device.

The AI claim needs a boundary

Public discussion quickly suggested that AI may have helped find or scale exploitation of the flaw. That is plausible, but it is not the same as demonstrated attribution. The verified facts are the weak seed-generation path, the affected firmware range, and the resulting wallet risk.

Threat intelligence should separate observed behavior from hypotheses about tooling. Otherwise, ‘AI attack’ becomes an unfalsifiable label attached to any fast or technically competent campaign.

What Vallum would—and would not—change

Vallum protects bounded HTTP API responses and application-authorized browser traffic. It would not repair hardware entropy, recover a wallet, or prevent a private key derived from a weak seed from being guessed.

The transferable lesson is fail-closed generation: when security material cannot be produced with the required entropy, the system must refuse to continue. Vallum applies that same principle to protected response paths, admission proof, and required storage dependencies.

Scope note

Vallum is a response-resistance and origin-admission layer for bounded HTTP(S) exchanges. It is not a WAF, endpoint agent, sandbox, identity provider, or secure enclave.

← Back to all threat intelligence