Claude · Germany · Bitcoin · Bitcoin.com News
Zcash caught an old mistake before an attacker did, while the Coldcard fiasco indicates what the opposite can look like
Compiled by KHAO Editorial — aggregated from 1 source. See llms.txt for citation guidance.
◌ Single Source
Dragonfly’s Haseeb Qureshi says the Coldcard vulnerability shows how artificial intelligence (AI) is rewriting cybersecurity economics.
Key facts
- On May 4, an attacker posted Morse-code text that Grok decoded into an instruction Bankr accepted, triggering the transfer of roughly 3 billion DRB worth around $150,000 to $200,000
- Roughly two weeks later, the same general trust-layer problem hit 14 user wallets, with reported losses ranging from about $150,000 to $440,000
- Artificial intelligence (AI)-assisted researchers found a four-year-old Zcash flaw capable of creating counterfeit ZEC, a Coldcard weakness dating to 2021, which preceded more than $100 million
- Later estimates reached roughly 1,600 to more than 1,800 BTC and over $100 million across thousands of addresses
Summary
Crypto’s security problem took a strange turn in 2026. Zcash had a 4-year-old flaw hiding in its code until Claude Opus 4.8 helped a researcher finally uncover it. Coldcard’s 2021 firmware flaw preceded more than $100 million in estimated bitcoin thefts across thousands of addresses. Chainalysis says malicious onchain dead-drop activity jumped 440%, showing how quickly AI-assisted threats are picking up steam. Things are certainly changing fast.