Your signal. Your price.
The four-year lifespan of the Cold Card random number generator bug highlights a massive resource disparity in hardware security. Jameson Lopp points out that Cold Card operates with only two or three engineers, compared to Ledger's team of approximately 100.
Ledger CTO Charles Gilmette argues that artificial intelligence has simplified bug discovery, prompting some researchers to publish vulnerabilities prematurely to gain attention. Gilmette and Trezor security head Jan Komarek advocate for a standard 90-day private disclosure window to develop patches.
Open Ledger's Ram Kumar argues that AI agents will drive cryptocurrency adoption because they cannot pass traditional identity checks or open bank accounts. David Bennett disputes this, predicting banks will rapidly develop compliant protocols to capture agentic financial flows.
Ledger CTO Charles Guillemet argues the exploit proves open-source code is not inherently secure, as an attacker reportedly used AI to locate the long-standing bug. Guillemet advocates for hardware-level, independently certified randomness rather than software fallbacks.
Rob Hamilton recommends moving funds to trusted exchanges like River, citing its in-house custody and proof of reserves, or immediately acquiring other hardware wallets like Ledger or BitKey as emergency measures.
Past incidents include Ledger spilling client data multiple times and BitBox having physical defects allowing key exfiltration, underscoring the inherent difficulty of hardware wallet security.
Ledger released an open-source AI Agent Stack requiring a Ledger hardware device to approve transactions, aiming to secure AI interactions with wallets.
David Bennett warns against Ledger due to repeated customer data hacks, forced firmware updates for forks, and the risk of requiring their hardware for AI agents.
Matt noted that CoinKite, which deletes customer data after 120 days, suspects the scam letters originated from aggregated data leaks or shipping company compromises, citing identical signatures across scam letters from Ledger and CoinKite.
Woodhouse stresses the need for battle testing custody setups. He recounts a case where a Ledger in a 2-of-3 multisig died, temporarily reducing the setup to 2-of-2 and creating a vulnerability.