A major Bitcoin hacking incident has prompted a stark warning from the affected company, Coinkite Inc., which states that artificial intelligence (AI) failed to detect a software vulnerability exploited to steal approximately $130 million in user funds.
The breach targeted the Coldcard wallet, manufactured by Canada-based Coinkite Inc., which was drained late last week. The company noted that the flaw exploited by hackers "serves as a wake-up call for all companies building Bitcoin hardware and software, not just us."
In a blog post, Coinkite urged all businesses relying on AI to monitor security-critical code to launch an immediate comprehensive review. "If your team depends on AI to audit security-critical code, we recommend specifically testing build boundaries and submodule boundaries," the company wrote. "We believe many Bitcoin projects, including those relying on open-source code, need an immediate review."
The Coldcard hack has deeply unsettled cryptocurrency investors, as hardware wallets are widely considered one of the most secure methods for protecting digital assets. These wallets store private keys on physical hardware that remains offline. The exposure of this vulnerability also challenges the core Bitcoin concept of "self-custody."
Nikhil Raghuveera, CEO of blockchain compliance infrastructure provider Predicate, commented: "Self-custody is a hallmark of digital assets, but the Coldcard incident shows that even a single point of failure can shake overall trust in the model. The impact may continue to ripple, as the entire ecosystem is built on the promise of being 'trustless.' The greater long-term risk is that investors may abandon digital assets entirely."
According to a recent analysis by Galaxy Research, the Coldcard hack appears to have involved four waves of attacks, resulting in losses of roughly $130 million. Coinkite stated that the vulnerability seemed to exist in the interaction between two separate software components within the firmware, rather than in the main code or encryption logic, which typically receives more rigorous scrutiny.
Coinkite emphasized that the broader ecosystem needs to understand how the flaw emerged and why it evaded detection "to prevent similar consequences." "We had conducted AI-assisted reviews of critical codebases, including just weeks before the attack," the company said. "But the AI did not catch this vulnerability."
After the incident, Coinkite tested the code with multiple advanced AI models, and the company reported that "none of the models identified the flaw." "This is a warning for us and all teams relying on AI tools—we must clearly understand what AI can currently detect and where its blind spots may lie," the company added.
Comments