How AI Is Reshaping Crypto Security, with Michael Coates
A hardware wallet flaw exposed 5,200 Coldcard users to $116 million in Bitcoin theft, prompting a shift in crypto security strategies amid rising AI-driven threats.
A July 30 attack drained $116 million from over 5,200 Coldcard wallets by exploiting a predictable seed phrase generation flaw introduced in 2021. The vulnerability stemmed from a code change that replaced a secure hardware random number generator with a weaker software-based alternative, reducing seed entropy from 128 bits to roughly 40. The flaw evaded detection for over four years, becoming the largest hardware-wallet exploit on record.
Michael Coates, Solana Foundation’s chief information security officer and former Twitter CISO, argues that self-custody security requires more than just hardware wallets. He emphasizes multi-signature setups, where multiple keys from different devices or trusted individuals are needed to authorize transactions, reducing single points of failure. Coates also highlights the need for geographic distribution of keys, such as storing one device in a safe deposit box, to mitigate physical threats like the 'wrench attack.'
Coates warns that AI is accelerating both offensive and defensive capabilities in cybersecurity, with attackers leveraging open-source models to improve their tactics. He notes that defenders are struggling to keep pace, as frontier AI tools for security are often gated or inaccessible. The gap between offensive AI advancements and defensive readiness is widening, creating a 'cat and mouse' dynamic where attackers gain an advantage.
To counter sophisticated threats like deepfake impersonations, Coates proposes hardware-based authentication solutions, such as YubiKey, which prevent unauthorized access even if users are tricked. He also advocates for automated security measures, including continuous rating programs like Solana Foundation’s STRIDE, launched in April for DeFi protocols, and circuit breakers that trigger automatically during anomalies. Coates stresses that security must evolve from human-scale responses to real-time, automated defenses to counter state-level threats.