Alexander Grinshpun found the entry point in Coldcard's MK4 and MK3 hardware wallets. The attack requires physical access. The device's seed can be extracted under an "evil maid" scenario — the one where an attacker handles your hardware while you are not watching. Coinkite acknowledged the finding and shipped a firmware update.

That is a legitimate security disclosure. Specific. Bounded. Actionable.
Then Ledger's CTO spoke. Certified hardware randomness is critical. AI is reshaping wallet security. Security solutions must adapt to the AI era.
None of those statements address the Coldcard vulnerability. They are a pitch. I do not trust the pitch; I audit the structure. The structure here: a competitor's exploit converted into brand positioning. The timing is calculated. The framing is selective.
The hardware wallet industry runs on one assumption: private keys never exit the physical device. Everything else is supporting detail. Ledger controls roughly sixty to seventy percent of that market. Coldcard occupies the smaller, sharper segment — Bitcoin-only, fully open source, built for users who treat code as documentation and marketing as noise. Trezor sits between them.
These are not interchangeable products. Ledger sells regulated convenience: closed firmware, secure elements, a decade of accumulated trust. Coldcard sells radical auditability: open hardware, open firmware, a threat model that assumes the adversary has time, resources, and physical access.
The exploit lands at that boundary. A device marketed as the apex of paranoid self-custody can be compromised by someone who touches it. That finding undermines the "fixed device equals absolute safety" assumption.
I audited ICO smart contracts in 2017. I watched teams confuse fundraising momentum with engineering discipline. The pattern is identical: one party discloses a flaw and ships a fix; the other issues a vision statement. Coinkite did the former. Ledger did the latter.
Examine Ledger's three claims as a sequence.
One: certified hardware randomness. The position is correct and unremarkable. Private keys derive from random number generators. A biased or predictable RNG renders all downstream cryptography meaningless. That is why TRNG certification exists — NIST SP 800-90B, Common Criteria EAL, FIPS 140-2. The standards are settled.
Any vendor that ships a serious hardware wallet sources certified RNG components. Trezor does. Coldcard does. Ledger does. This claim does not separate Ledger from competitors. It describes the minimum condition for participation. Advertising baseline compliance as a security advantage is a concession, not a differentiator.
Two: AI is reshaping wallet security. This is where the information density collapses. No product. No architecture. No named research team. No public audit. No release date. The phrase is a trajectory, not a deliverable.
I spent 2022 working through zero-knowledge proof systems — Plonk, Spartan, the mathematics of verifiable computation. I know what real cryptographic progress looks like: papers, open implementations, reproducibility, external verification. Nothing in Ledger's AI statements meets that bar. An unverifiable security claim is indistinguishable from a false one.
What could "AI in wallet security" mean? Malicious transaction detection. Anomaly scoring on signing requests. Automated firmware fuzzing. Defense against machine-generated phishing. Each is plausible. None was specified.
Three: security must adapt to the AI era. Accept the premise. AI makes social engineering cheaper. It accelerates vulnerability discovery. It scales targeted attacks. The threat landscape is shifting.
The Coldcard exploit, however, contains no AI component. A human researcher found a physical attack path. The fix is a firmware update. The threat model is physical compromise. No machine learning was required to extract a seed.
That mismatch is the structural flaw in Ledger's response. They received evidence that hardware assumptions require revision. They answered with a vision dependent on an unbuilt system. The exploit is a finding; the AI statement is a sales forecast. Those are not comparable facts.
I analyzed DeFi yield schemes in 2020. The ones that failed shared a trait: they wrapped unsustainable mechanics in ambitious language. Marketing narratives disguised as innovation. That is exactly how "AI-powered wallet security" reads until a protocol is shipped and audited. The burden of proof sits with the vendor.
The industry's real lesson is not that wallets need an AI layer. It is that single-device custody has a physical limit. Liquidity is a mirage; solvency is the only truth. The hardware wallet equivalent: convenience is a mirage; threat modeling is the only truth.
The correct response to a physical compromise vector is architectural. Multi-party computation. Threshold signatures that split custody across devices and locations. Multi-sig arrangements using hardware from multiple vendors. Ledger has invested in MPC technology and operates its own recovery product. They understand this market direction. The AI narrative diverts attention from the structural shift their own roadmap requires.
Transparency asymmetry compounds the problem. Coldcard's firmware is open source. The vulnerability was found externally, disclosed, and patched in public. The process worked. Ledger's firmware remains closed to the same scrutiny. A company whose code you cannot independently review cannot reduce your risk by asking for more trust. It can only expand its authority over your security.
Emotion is a variable I exclude from the equation. Coldcard owners will feel exposed. Ledger's marketing team will sense opportunity. Neither response is a technical fact. What distinguishes the two companies is falsifiability. Coldcard's claims can be tested. That is why this week will reinforce, not erode, its user base's confidence.
Now the part where the bulls hold ground.
The Coldcard disclosure is a genuine warning. The evil maid scenario — physical access, the device out of your sight — defeats a wallet designed for hostile environments. That matters regardless of who commented on it. Every self-custody user should reassess operational assumptions. The exploit does not make Coldcard obsolete. It makes its security properties known. For users who operate on first principles, a known limitation is worth more than an unknown assurance.
AI-assisted wallet security is not worthless as an idea. An auditable anomaly detection layer could intercept phishing transactions a human might miss. But the idea must materialize as verifiable software: published models, reproducible inference, explicit user controls. Nothing less satisfies the standard the Coldcard disclosure set.
Ledger's engineering history is real. Years of hardware security work should not be dismissed because of one rhetorical maneuver. Their threat model is different from Coldcard's. It is not weaker. The question is what they ship next — and whether anyone outside their payroll can verify it.
File the Coldcard exploit where it belongs: a data point about physical attack surfaces. File Ledger's AI commentary where it belongs: a brand position, not an audit finding.
Demand specifications. Demand open code. Demand third-party verification. If Ledger delivers a transparent AI security product, assess it on its mechanics. Until then, treat the narrative as a vision statement.
The next failure will not arrive announced by artificial intelligence. It will arrive as a firmware advisory, a researcher's notes, a slow realization that an assumption was wrong. Self-custody survives by auditing those assumptions.
The pitch arrives first, every time. Read the patch notes instead.