According to Coinkite, the Coldcard manufacturer, AI-assisted code reviews—including tests with Kimi K3, Claude Fable, and Codex 5.6—failed to identify a critical vulnerability that led to hacking incidents. The company stated it had conducted AI-aided reviews of core codebases weeks before the vulnerability was exploited but the flaw went undetected.
Coinkite highlighted that the vulnerability existed in interactions between two separate firmware components rather than in parent code or cryptographic logic typically scrutinized by reviewers, serving as an industry-wide caution for Bitcoin hardware and software developers. According to Galaxy Research's latest analysis, the suspected four-wave attacks in the Coldcard incident resulted in approximately $130 million in losses.