Cutting-edge AI left clueless! Bitcoin hardware wallet hacked for $130 million, manufacturer urgently calls for a review of AI reliance.

date
14:55 05/08/2026
avatar
GMT Eight
Recently, a core company involved in a Bitcoin hacking incident issued a warning, stating that artificial intelligence (AI) failed to detect a vulnerability in the software that had led to approximately $130 million in user losses.
Recently, a core company involved in a Bitcoin hacking incident issued a warning, stating that artificial intelligence (AI) failed to detect a software vulnerability that led to approximately $130 million in user funds being stolen. The affected Coldcard wallet, owned by the Canadian-based company Coinkite Inc., was completely emptied late last week. The company stated that the vulnerability exploited by the hackers "serves as a wake-up call for all companies building Bitcoin hardware and software, not just for ourselves." Coinkite urged in a blog post on its official website that any business relying on AI to monitor safety-critical code should immediately conduct a thorough review. Coinkite wrote in the blog: "If your team relies on AI to review safety-critical code, we recommend specifically testing for the construction of boundaries and submodule boundaries. We believe that many Bitcoin projectsincluding those relying on open-source codeneed to undergo immediate reviews." The hacking incident involving Coldcard has left cryptocurrency investors deeply unsettled, as so-called "hardware" wallets are considered one of the safest ways to protect digital assets. These wallets store private keys through physical hardware and do not connect to the internet. The exposure of this vulnerability has also severely tested the core principle of Bitcoin "self-custody." Nikhil Raghuveera, CEO of blockchain compliance infrastructure provider Predicate, stated: "Self-custody is a hallmark of digital assets, but the Coldcard incident shows that even a single point of failure can undermine overall trust in this model. Its impact may continue to ripple through the community, as the foundation of the entire ecosystem is built on the promise of 'trustless' transactions. In the long term, the greater risk is that investors may completely turn away from digital assets." According to the latest analysis from Galaxy Research, the Coldcard hacking incident appears to involve four waves of attacks, resulting in approximately $130 million in losses. Coinkite stated that the vulnerability seems to exist in the interaction of two separate software components within the firmware, rather than in the main code or cryptographic logic that usually receives close scrutiny. Coinkite emphasized the broader ecosystem needs to understand how the vulnerability arose and why it evaded detection, "in order to prevent similar consequences." "We conducted AI-assisted reviews of critical codebases, including reviews just weeks before the attack," Coinkite stated, "but AI did not catch this vulnerability." After the incident, Coinkite also tested the code using multiple cutting-edge AI models, and the company claimed, "not a single model identified the vulnerability." "This serves as a warning for us and for all teams relying on AI toolswe must be clear about what AI can currently detect and where potential blind spots may exist."