Coinkite's AI Code Review Failed to Detect Coldcard Vulnerability, Causing $130M in Losses

BTC0.52%

According to Coinkite, the Coldcard manufacturer, AI-assisted code reviews—including tests with Kimi K3, Claude Fable, and Codex 5.6—failed to identify a critical vulnerability that led to hacking incidents. The company stated it had conducted AI-aided reviews of core codebases weeks before the vulnerability was exploited but the flaw went undetected.

Coinkite highlighted that the vulnerability existed in interactions between two separate firmware components rather than in parent code or cryptographic logic typically scrutinized by reviewers, serving as an industry-wide caution for Bitcoin hardware and software developers. According to Galaxy Research's latest analysis, the suspected four-wave attacks in the Coldcard incident resulted in approximately $130 million in losses.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments