Coinkite Hack Exposes $130M Loss as AI Fails to Detect Vulnerability
A hack into Canada-based Coinkite's Coldcard wallets has exposed users' funds, estimated at $130 million. The company behind the affected hardware warned that artificial intelligence failed to detect the bug exploited by hackers.
The vulnerability was found in the part of the firmware where two separate software components interacted, not in the parent code or cryptographic logic subject to reviews.
Coinkite has stated that its AI-assisted review of critical codebases did not catch this vulnerability. In fact, none of several frontier AI models tested against Coinkite's code after the incident were able to detect it.
Nikhil Raghuveera, CEO of Predicate, a blockchain compliance infrastructure provider, noted that self-custody is a hallmark of digital assets but 'one point of failure can shake trust in the whole model.' The repercussions could be long-lasting as investors may move away from digital assets entirely.