
The company at the center of a Bitcoin hack has warned that artificial intelligence (AI) failed to detect a software vulnerability that was used to steal user funds.
Canadian Coinkite Inc., whose Coldcard wallets were emptied late last week, stated that the vulnerability discovered by hackers "is a warning to every company creating Bitcoin hardware and software, not just us." Companies using AI to monitor security-critical code should conduct reviews immediately, Coinkite noted in a blog post on its website.
"If your team relies on AI-powered code review for security-critical code, we recommend testing it separately at build and submodule boundaries," Coinkite stated. "We believe many Bitcoin projects, including those based on open-source code, require immediate scrutiny."
The Coldcard hack has alarmed crypto investors, as so-called "cold" wallets, which store private keys on a physical device and are not connected to the internet, are considered one of the most secure ways to store digital tokens. The incident has called into question the principle of self-custody, one of the fundamental principles of cryptocurrency.
"Self-custody is a hallmark of digital assets, but the Coldcard incident shows how a single point of failure can undermine trust in the entire model," said Nikhil Raghuveera, CEO of Predicate, a blockchain compliance infrastructure provider. "The consequences could be long-term, as the ecosystem is built on the promise of trustlessness. Over time, the main risk is that investors will turn away from digital assets altogether." Bitcoin is trading above $64,000 on Wednesday after recently falling to $62,300, which held as support.