Hacked Bitcoin wallet maker Coinkite warns of AI failure to detect bug

Sign up now: Get ST's newsletters delivered to your inbox

Firms using AI to monitor security-critical code should undertake immediate reviews, Coinkite said in a blog post on its website.

Firms using AI to monitor security-critical code should undertake immediate reviews, Coinkite said in a blog post on its website.

PHOTO: REUTERS

TORONTO – The company at the centre of a Bitcoin hack has warned that artificial intelligence failed to detect the software flaw that was exploited to steal users’ funds, now estimated at US$130 million (S$166.5 million).

Canada-based Coinkite, whose affected Coldcard wallets were drained late last week, said the vulnerability the hackers discovered “is a warning for every company building Bitcoin hardware and software, not only us”.

Firms using AI to monitor security-critical code should undertake immediate reviews, Coinkite said in a blog post on its website.

“If your team relies on AI review of security-critical code, we recommend you test it specifically against build and sub-module boundaries,” Coinkite said.

“We believe many Bitcoin projects, including those that rely on open-source code, require immediate review.”

The Coldcard hack has unnerved crypto investors because so-called “hard” wallets, which use physical hardware to store private keys and are not connected to the internet, are considered one of the safest ways to secure digital tokens. The breach has put scrutiny on self-custody, one of crypto’s founding principles.

“Self-custody is a hallmark of digital assets, but Coldcard shows how one point of failure can shake trust in the whole model,” said Nikhil Raghuveera, chief executive of Predicate, a blockchain compliance infrastructure provider.

“The repercussions could be long-lasting because the ecosystem is built on the promise of being trustless. Over time, the bigger risk is that investors move away from digital assets entirely.”

Galaxy Research estimates that four suspected attack waves in the Coldcard hack have resulted in losses of about US$130 million, according to its latest analysis.

Coinkite said the bug appears to have lived in the part of the firmware where two separate software components interact, not in the parent code or cryptographic logic that are subject to most reviews.

It is important for the broader ecosystem to understand how the bug arose and why it evaded detection, “so they can avoid similar consequences”, it said. 

“We’ve run AI-assisted review against our critical codebases, including in the weeks before the exploit,” Coinkite said. “It did not catch this vulnerability.” 

Since the incident, Coinkite has tested its code against several frontier AI models, and “none of them caught it”, the company said.

“It’s a reason for us, and anyone else relying on AI tools, to be specific about what they currently catch and what they might not.” Bloomberg

See more on