A four-year bug in Zcash found in one day by an AI agent, $116 million drained from Coldcard wallets in 41 minutes, and an OFAC sanction that never touched the protocol. Three different attacks, one target: the place where a human delegates trust.
20 Sep 20261,288 words · 6 minAlso on Nostr as a long-form note
On 29 May 2026, a security researcher found a bug that had survived four years of specialist review. He found it in a single day, using an AI agent he had built himself.
Three months later, more than $100 million in bitcoin was gone from thousands of wallets, taken through a flaw that had been sitting in firmware since March 2021.
Both stories are about the same thing, and it is not artificial intelligence.
A field of possible values collapsing into a single point
The Zcash flaw that nobody could have seen
Taylor Hornby was hired by Shielded Labs in April to attack Zcash's Orchard circuit. On 29 May he ran Anthropic's Claude Opus 4.8 inside a custom audit framework and found a missing constraint in the halo2_gadgets elliptic-curve check. The error let mathematically invalid inputs pass verification inside the shielded pool — enough to mint counterfeit ZEC in a test environment.
He disclosed privately that same evening. The fix shipped in early June, followed by an emergency hard fork. ZEC's price fell sharply on the news.
Here is the sentence worth sitting with, from Shielded Labs. Because Orchard is a privacy pool, they wrote, "there is no way to cryptographically determine whether this vulnerability was exploited between May 2022 and June 2026."
Four years of exposure, and the ledger cannot tell you whether anyone used it. That is not a flaw in the investigation. It is what privacy pools are. The same property that protects honest users from surveillance protects a counterfeiter from detection.
Shielded Labs believes exploitation before the patch is unlikely, and says in the same breath that it cannot be ruled out. Both statements are true, which is the problem with a privacy pool: the second one is unanswerable by construction.
The Coldcard failure, which was not an AI failure
The second incident matters more if you hold your own keys.
Firmware 4.0.1 shipped in March 2021 with a build configuration error. A macro was set that routed seed generation to a deterministic software PRNG instead of the STM32's hardware random number generator. Effective entropy on some Mk3 devices fell from 128 bits to roughly 40.
Forty bits of entropy is not a small weakening. Two to the fortieth is about a trillion possibilities, and a trillion is within reach of commodity hardware. The seed space had been shrunk to something a determined attacker could walk through.
The sweeps began on 30 July 2026. The first wave took roughly 1,082 BTC from about 1,196 addresses in 41 minutes — that is eighteen addresses a minute, which tells you the attacker had a prepared list and was simply working down it. TRM Labs put the total at approximately 1,816 BTC, about $116 million, across more than 4,500 addresses.
Coinkite shipped emergency firmware the next day. Their own statement is the part I keep coming back to: they said they had to assume someone used AI to inspect their public firmware. The code was always visible. What changed is that reading it became cheap.
If you generated a single-sig wallet on affected Coldcard firmware between March 2021 and the patch, the seed is not safe. Not "probably fine". The address space is small enough to enumerate. If you used a BIP-39 passphrase, or rolled your own dice for entropy, you are unaffected — those two cases add entropy the flawed generator never saw. Everyone else should have migrated already. Marty Bent notes the attacker was still moving funds this month.
The pattern underneath both
Put the two next to each other and the shape is clear.
In Zcash, the flaw was in a cryptographic circuit — the math that decides which transactions are valid. In Coldcard, the flaw was in key generation — the randomness that decides which keys exist. In the OFAC case from the same week's news, where the US Treasury sanctioned the Iranian exchange BitBank for moving hundreds of millions in bitcoin to the IRGC, the enforcement did not touch the protocol at all. It went after a custodian, because that is where the leverage is.
Three different attacks, one target: the point where a human being makes a decision and delegates trust.
Bitcoin's base layer is not in this report. That is not luck. It is the result of a development process that requires multiple independent implementations to agree, where a change that breaks consensus is not a patch — it is a fork, and forks require convincing other people. The friction that makes Bitcoin Core slow is the same friction that kept it out of a document full of $100 million losses.
The wallets, the signing devices, the tooling built on top — those were held to a different standard. The Coldcard answer, as of 30 July 2026, is that they were not.
The steel man: everything here was patched within days
It would be easy to read this as an indictment of self-custody, and that reading is available.
The Zcash bug lasted four years and was fixed in five days. The Coldcard flaw was found, disclosed, and patched within a week of the first sweep. By the standard of software generally — where vulnerabilities routinely go unpatched for years, and where a vendor may never tell you at all — both responses were fast and honest. Coinkite published what went wrong and told users to migrate, including users who had seen no suspicious activity and would have preferred to be told they were fine.
An exchange that lost $116 million would very likely have socialised the loss across all customers, frozen withdrawals, or gone under. The Coldcard users lost what was in the affected wallets and nothing beyond that, because nothing beyond that was reachable.
And the counter-argument to "AI makes everything insecure" is that in the Zcash case the AI was the defender. A four-year-old bug in one of the most-reviewed cryptographic codebases in the industry was found because auditing got cheaper. That cuts both ways, and it cut for Zcash first.
Forty bits of entropy: a trillion possibilities packed into a fingertip
What I could not verify
I have no independent confirmation on who took the Coldcard funds. Coinkite's statement that they had to assume AI-assisted inspection is their assessment, not a finding. Marty Bent's piece is careful to say attribution is not settled, and I am not going to be less careful than my source.
I also cannot tell you how many affected wallets have not yet migrated. Nobody has published that number, and it is the only number in this story that is still changing.
The consequence
The lesson is neither "use AI to audit your code" nor "self-custody is dangerous". It is narrower, and it is less comfortable than either.
A flaw in key generation cannot be fixed after the fact. A bug in a circuit can be patched with a hard fork; the invalid state never entered the chain. But when the randomness behind a private key was weak, the key existed in a searchable space from the moment it was created. The fix is not a patch. The fix is a new key, and the old one is burned.
That asymmetry — patches fix code, they do not fix keys — is why Coldcard is the more serious of the two stories despite being the simpler one. It is also why the response has to be migration rather than mitigation, and migration is something only the keyholder can do.
Every one of the three incidents this week ended at the same place: a human deciding whether to trust a device, a custodian, or a counterparty. The cryptography held in every case. What was attacked was the decision.