Coinkite Coldcard Wallet Hack Exposes Vulnerability in AI-Dependent Security Measures
A recent hacking incident has left cryptocurrency investors deeply unsettled after hackers exploited a software vulnerability in the Coldcard wallet, owned by Coinkite Inc., resulting in losses of approximately $130 million. The company, headquartered in Canada, stated that artificial intelligence (AI) failed to detect the vulnerability, which served as an interaction between two independent software components within the firmware.
Coinkite emphasized that the broader ecosystem needs to understand how this vulnerability arose and why it managed to evade detection, 'in order to prevent similar outcomes.' The company conducted AI-assisted reviews of critical codebases, including several weeks before the attack occurred, but none of the models detected the vulnerability.
Nikhil Raghuveera, CEO of Predicate, a provider of blockchain compliance infrastructure, stated: 'Self-custody is a hallmark of digital assets, yet the Coldcard incident demonstrates that even a single point of failure can undermine public confidence in this model. Its repercussions may continue to unfold.'