Updated September 13, 2026 ProductsCulture

Coldcard's AI code review missed a bug behind $100 million in thefts

Illustration for the Coldcard AI audit story

A bitcoin wallet company ran AI over its own firmware weeks before the hack. The AI found nothing.

The audit that missed

Coinkite, maker of the Coldcard hardware wallet, says it ran one of the best available models across its code a few weeks before attackers began draining funds, and the model “did not find this bug or anything serious.”

The sharper twist is who Coinkite thinks did find it. The company now assumes the attacker used AI to review older firmware versions and discovered what its own review missed.

The bug itself

The flaw dates to a March 2021 firmware migration that, through a build error, routed seed generation to a software random number generator instead of the device’s hardware one. Coinkite’s preliminary estimate puts the effective search space at about 40 bits on Mk2 and Mk3 devices, and about 72 bits on Mk4, Q and Mk5, which mixed in extra secure-element entropy, against an intended 128 bits.

That downgrade changes the nature of the problem entirely. At 128 bits, guessing a key is a cryptographic impossibility. At roughly 40 bits, it becomes an arithmetic exercise: weak keys can be regenerated offline, with no need to touch the device or its owner.

The thefts began on July 29, 2026, according to CoinDesk, which later cited Galaxy Research’s estimate of about 1,596 BTC, worth over $100 million, stolen from about 7,300 addresses by at least 15 attackers. Coinkite shipped fixed firmware and told users with affected seeds to move their funds to new ones, since updating firmware alone does not repair an existing affected seed.

The lesson for everyone shipping code

The uncomfortable part reaches well beyond hardware wallets: the same tool that reviews your work also reviews it for whoever comes looking. AI code review is symmetric. Defenders run models over their code to find bugs first; attackers run models over the same public code with the same question and more patience.

Coinkite’s experience suggests the symmetry is not even guaranteed to favor the defender. Its model pass found nothing; the presumed attacker’s pass, aimed at older firmware versions, apparently found a five-year-old flaw worth over $100 million.

An AI review is a useful layer. Treating it as a security audit, the thing that lets you sleep, is the mistake this story prices at about 1,596 BTC.

Sources

ANOTHER News is published by ANOTHER, an AI-native content agency. Daily coverage also runs on Instagram.