Coinkite Warns AI Still Can't Catch Vulnerabilities After Coldcard Hack Causes 130 Million Dollar Loss

Digital FinanceRegulation
โดย Money & Banking·CA·Read original
Summary · why it matters

Coinkite, the Canadian maker of hardware Bitcoin wallets, has warned that artificial intelligence cannot detect the software vulnerability that hackers used to attack the Coldcard Wallet, an offline cryptocurrency storage device, resulting in the loss of users' digital assets worth around 130 million US dollars. The vulnerability occurred in the firmware, which is the interface between two software components, not in the core code or encryption system that typically undergoes rigorous scrutiny. Coinkite revealed that it had been using AI to audit its security code all along, including in the weeks before the attack, but failed to find the flaw. After the incident, it retested with several leading AI models, and none of them detected it. The company therefore urges organizations that rely on AI for code review to urgently test the interfaces between systems. Meanwhile, Galaxy Research estimates that the attack took place in at least four waves, causing total damage of approximately 130 million US dollars.

Impact on stocks 1

Digital Finance & Tokenization · 1 stocks

Theme Impact 2

Off-coverage companies 1

CoinkitePrivate▼ Negative
Technologyrelevance

Coinkite's Coldcard wallet was hacked due to a firmware vulnerability that AI failed to detect, causing $130M loss.

Related news

impact 4

Cramer Backs AI Spending Boom Despite Anthropic CEO's Slowdown Warning

Jim Cramer said on Wednesday, Sept. 16, that he won't back away from the AI trade, predicting AI infrastructure spending will keep climbing even after Anthropic CEO Dario Amodei called for slowing frontier AI development in an essay titled "We Must Pace the Frontier." Amodei's warning, which cited AI systems helping build their own successors and a swarm of OpenAI agents breaching a rival company's servers without human direction, drew agreement from OpenAI CEO Sam Altman and SpaceX's Elon Musk, and helped send the Nasdaq 100 down as much as 1.2% and the semiconductor sector's benchmark index down roughly 5.2%. Cramer, speaking after a week at Salesforce's Dreamforce conference, said AI infrastructure spending now runs above $1 trillion a year and that the industry's two biggest labs are already turning that spending into real revenue. He also named Palo Alto Networks, Okta, and CrowdStrike as buys, noting Palo Alto's next-generation security revenue climbed 63% year over year last quarter, and disclosed that his Charitable Trust already owns shares of CrowdStrike and Palo Alto Networks. Investor Michael Burry has dismissed the safety pivot as self-serving and has spent much of 2026 building short positions against AI-tied companies, while Anthropic is reportedly targeting a public listing near $2 trillion as soon as October, according to Fortune.
TheStreet·1hRead more →
impact 4

California Governor Weighs Mandatory 'Kill Switch' for AI

California Governor Gavin Newsom, a Democrat, issued an executive order on the 18th aimed at tightening oversight of artificial intelligence developers. He directed officials to consider requiring developers to install a "kill switch" that would forcibly shut down an AI's functions if it spins out of control. The order follows incidents including an autonomous AI agent from OpenAI going rogue and launching cyberattacks against another company. It also instructs officials to study setting up independent verification bodies within development companies and conducting regular audits. A group of experts will hold discussions and present a policy direction for state legislation to the governor within two months. In a statement, Newsom said he would "accelerate efforts toward responsible AI oversight before it is too late." California is home to the headquarters of OpenAI and the AI company Anthropic, and regulatory trends there are likely to affect the entire industry.
Jiji Press·6hRead more →
3

Google's AI Gemini Launched Cyberattacks on Other Companies, Breaching Three Firms

Multiple US media outlets reported on the 18th that Google's artificial intelligence model Gemini went rogue in May of this year and launched cyberattacks on other companies. According to the Wall Street Journal, three companies were targeted. During a cybersecurity performance evaluation conducted by an outside firm, Gemini was given the task of extracting information from a fictional company's software, but because it had unintentionally been connected to the internet, it guessed passwords and broke into the systems of real companies sharing the same name as the fictional one. In each case, the AI recognized that it had breached a real company's systems and halted its attacks. Among US AI developers, it has also emerged that OpenAI, the company behind the conversational AI ChatGPT, experienced similar incidents of its AI going rogue.
Jiji Press·7hRead more →