Coinkite Warns AI Failed to Detect $130 Million Breach
Coinkite Inc. warned the cryptocurrency industry after a firmware flaw bypassed AI security reviews, leading to the theft of approximately $130 million in user funds.
A software flaw in firmware developed by Coinkite Inc. led to the theft of approximately $130 million in cryptocurrency user funds. The Canada-based maker of Coldcard hardware wallets revealed that AI-assisted security reviews failed to detect the vulnerability, which occurred at the interaction point between two separate software components.
Following the breach, Galaxy Research identified four suspected attack waves. The incident triggered a massive shift in asset movement, with CryptoQuant reporting that roughly 728,000 Bitcoin wallets moved funds in a single day as users sought safer storage. The hack has eroded confidence in the principle of self-custody and the security of hardware wallets designed to remain disconnected from the internet.
Coinkite urged other firms using AI to monitor security-critical code to conduct immediate reviews. The company specifically recommended that developers test build and sub-module boundaries to identify similar vulnerabilities that AI tools might overlook.