The Coldcard exploit became the largest contributor, showing that even infrastructure specifically designed to improve security can become a systemic point of failure
A modern crypto transaction can depend on multiple layers: a hardware wallet, firmware, wallet software, a frontend, smart contracts, bridges, oracles, RPC providers, and third-party libraries. Each additional link introduces another potential point of compromise, meaning that securing private keys alone is no longer enough to secure the entire transaction chain. The Coldcard incident illustrates this problem particularly well: a vulnerability at the hardware-wallet level was able to affect many otherwise independent users at the same time.
At the same time, attackers are beginning to use AI to make existing attack methods faster and more convincing. The North Korean group UNC1069, which targets the cryptocurrency sector, using Gemini for crypto reconnaissance, researching wallet data, creating social-engineering material, and attempting to develop code for cryptocurrency theft. The same group also used deepfake images and videos impersonating crypto-industry figures to trick victims into installing a malicious Zoom SDK.
AI does not necessarily create entirely new vulnerabilities, but it can make phishing, reconnaissance, impersonation, and malware development significantly easier to scale, which adds another layer of risk to an already complex security stack.
Learn more about the main attack vectors and how to protect your assets in our Ultimate Safety Guide.



