A recent Bitcoin hacking incident has prompted a warning from the core company involved, stating that artificial intelligence (AI) failed to detect the exploited software vulnerability, which has led to approximately $130 million in user funds being stolen. The affected Coldcard wallet, owned by Canada-based Coinkite Inc., was drained late last week.
Coinkite stated that the vulnerability exploited by hackers "serves as a wake-up call for all companies building Bitcoin hardware and software, not just ourselves." In an official blog post, the company called for an immediate comprehensive review by any enterprise that relies on AI for monitoring security-critical code. Coinkite wrote in the blog: "If your team relies on AI to audit security-critical code, we recommend you specifically test for boundary and sub-module boundary issues. We believe many Bitcoin projects, including those relying on open-source code, need an immediate review."
The Coldcard hack has deeply unsettled cryptocurrency investors, as so-called "hardware" wallets are considered one of the safest ways to protect digital assets. These wallets store private keys on physical hardware and are not connected to the internet. The exposure of this vulnerability has also put the core Bitcoin principle of "self-custody" under severe scrutiny. Nikhil Raghuveera, CEO of blockchain compliance infrastructure provider Predicate, stated: "Self-custody is a hallmark feature of digital assets, but the Coldcard incident shows that even a single point of failure can shake overall trust in this model. The impact could continue to ripple through the ecosystem, which is built on the promise of 'trustlessness.' In the long term, the greater risk is that investors may completely shy away from digital assets."
According to a recent analysis from Galaxy Research, the Coldcard hack appears to have involved four waves of attacks, currently resulting in about $130 million in losses. Coinkite indicated that the vulnerability seems to exist in the part of the firmware where two separate software components interact, rather than in the main code or cryptographic logic which is typically subject to intensive review. Coinkite emphasized that it is necessary for the broader ecosystem to understand how this vulnerability was created and how it evaded detection, "to avoid similar consequences."
"We had conducted AI-assisted reviews of the critical codebase, including just weeks before the attack," Coinkite stated. "But the AI did not catch this vulnerability." After the incident, Coinkite also tested the code with multiple leading AI models, and the company said "none of the models found the vulnerability." "This is a warning sign for us and for all teams relying on AI tools. We must clearly understand what AI can currently detect and where its blind spots may lie."
Comments