Skip to main content
BTC / USDT——ETH / USDT——SOL / USDT——BNB / USDT——XRP / USDT——DOGE / USDT——TON / USDT——AVAX / USDT——LINK / USDT——ADA / USDT——TRX / USDT——DOT / USDT——BTC / USDT——ETH / USDT——SOL / USDT——BNB / USDT——XRP / USDT——DOGE / USDT——TON / USDT——AVAX / USDT——LINK / USDT——ADA / USDT——TRX / USDT——DOT / USDT——
Pricing
cryptoAug 5, 2026, 11:08 AM

Ledger CTO: Coldcard Flaw Exposes Limits of Open Source Verification

A five-year-old bug in Coldcard’s public code lay undetected until targeted attacks, undermining the “open source means verified” assumption, says Ledger CTO Charles Guillemet. He points to Ledger’s hardware-based entropy as a safer alternative.

Ledger’s chief technology officer Charles Guillemet highlighted a long-hidden flaw in the Coldcard hardware wallet as a cautionary case. The vulnerability sat in Coldcard’s public GitHub repository for more than five years, but only drew attention when attackers began exploiting it. According to Guillemet, this challenges the common belief that open-source code is inherently secure because it can be inspected by anyone.

He contrasted Ledger’s design: the device’s Secure Element generates 256 bits of entropy directly in hardware, without relying on a software fallback path like the one that caused the Coldcard issue. This approach, Guillemet argued, prevents similar long-dormant bugs from lingering in the codebase.

The company also commented on the growing role of artificial intelligence in security. AI tools can speed up vulnerability discovery for both hackers and defenders. However, Ledger noted there is currently no direct evidence that the Coldcard attackers used AI techniques.

Source: ForkLog