AI failed to detect Coldcard wallet vulnerability leading to $100 million bitcoin theft
Translated from Spanish, summarized and contextualized by DistantNews.
At a glance
- Canadian company Coinkite admitted that AI-assisted code reviews failed to detect a vulnerability in its Coldcard wallets, leading to over $100 million in bitcoin theft.
- The flaw was in the interaction between unrelated submรณdulos, not the core code or cryptography, prompting Coinkite to advise other manufacturers to scrutinize inter-module connections.
- An estimated 1,596 bitcoins were stolen across multiple incidents, with potential for more, affecting users who relied on the physical devices to protect their private keys.
Coinkite, a Canadian firm, has acknowledged that its use of artificial intelligence for code reviews did not identify a critical vulnerability in its Coldcard wallets. This oversight allowed for the theft of over $100 million worth of bitcoin. The company stated that even after the attacks, multiple advanced AI models failed to pinpoint the flaw.
The vulnerability reportedly stemmed from an interaction between two unrelated submรณdulos, rather than issues within the main code or cryptographic logic, which are typical focuses of security reviews. Coinkite has urged other hardware manufacturers to pay close attention to the connections between different code modules.
Estimates suggest that at least 1,596 bitcoins, valued at over $100 million, were stolen from approximately 7,300 addresses through confirmed attacks and smaller incidents. A potential fourth wave could increase the total to 2,055 bitcoins, worth around $130 million. The Coldcard wallet is a physical device designed to safeguard the private keys necessary to access bitcoin holdings, keeping them offline.
Originally published by Diario Libre in Spanish. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.