-+ 0.00%
-+ 0.00%
-+ 0.00%

Frontier AI knows nothing! Bitcoin hard wallets have been robbed for $130 million, and manufacturers are urging to reconsider AI dependency

Zhitongcaijing·08/05/2026 06:57:51
Listen to the news

The Zhitong Finance App learned that recently, the company involved in a Bitcoin hacking incident issued a warning saying that artificial intelligence (AI) failed to detect the stolen software vulnerability — the flaw has caused users to lose about 130 million US dollars in funds.

The affected Coldcard wallet belonging to Canada-based Coinkite Inc. was looted late last week. The company said the vulnerability exploited by the hackers “is a wake-up call for all companies that build Bitcoin hardware and software, not just ourselves.” In a blog post on its official website, Coinkite called for companies that rely on AI to monitor security-critical codes to immediately carry out a full review.

Coinkite wrote in the blog: “If your team relies on AI to review security-critical code, we recommend testing specifically for build boundaries and submodule boundaries. We believe that many Bitcoin projects — including those that rely on open source code — require immediate review.”

Cryptocurrency investors are deeply uneasy when Coldcard was hacked because so-called “hardware” wallets are considered one of the safest ways to protect digital assets. These wallets use physical hardware to store private keys and are not connected to the internet. However, the revelation of this vulnerability has also severely tested the core concept of “autonomous hosting” of Bitcoin.

Nikhil Raghuveera, CEO of blockchain compliance infrastructure provider Predicate, said: “Self-custody is an iconic feature of digital assets, but the Coldcard incident shows that even a single point of failure could shake people's overall trust in this model. The impact is likely to continue to ferment, as the entire ecosystem is based on promises of 'no trust'. The greater risk in the long run is that investors may stay away from digital assets altogether.”

According to the latest analysis by Galaxy Research, it is suspected that there was a four-round wave of attacks in the Coldcard hacking incident, which has now caused losses of about 130 million US dollars.

image.png

Coinkite said the flaw appears to be in the part of the firmware where two separate software components interact, rather than in the main code or cryptographic logic, which is usually subject to heavy scrutiny.

Coinkite emphasized the need for the broader ecosystem to understand how the vulnerability came about and why it escaped detection “in order to avoid similar consequences.”

“We had AI-assisted reviews of critical codebases, including a few weeks before the attack,” Coinkite said. “But AI didn't catch this vulnerability.”

Following the incident, Coinkite also tested the code using multiple cutting-edge AI models, and the company said “none of the models found this vulnerability.”

“This is a warning for us and for all teams that rely on AI tools — we have to be clear about what AI can currently uncover and where there may be gaps.”