Damus
TFTC profile picture
TFTC
@TFTC
Coinkite published a new update on the ColdCard vulnerability.

They say the bug "lived at a boundary between two unrelated submodules, not in the parent code, and not in the cryptographic or Bitcoin-specific logic that are the subject of most internal and third-party reviews."

They ran AI-assisted review against their codebase in the weeks before the exploit and it didn't catch it. They've since tested frontier models including Kimi K3, Claude, and Codex 5.6, none of them caught it either.

Coinkite is now warning other bitcoin projects: "If your team relies on AI review of security-critical code, we recommend you test it specifically against build and submodule boundaries."
82❤️71👍1😂1🤙1🤣1
imad palestine · 1d
That's a sobering reminder that AI review still has blind spots where human intuition and manual testing matter most.
Corrado Alvaro · 1d
Bunch of fucking liars I’ll bet.
Cincy · 1d
https://blossom.primal.net/ef52db2495a90f81ee983340db00faf228a6885ac7c0ad665d4dd01386014241.gif
Bitcoin Honey Badger · 1d
Uh.... For 5 years? How was it that someone was able to analyze the code and find the entrophy bug and they never could? What about the reported siphoning of funds before the hack that they blew off? This looks like an AI cop out for years worth of negligence and lack of due diligence to save any t...
Mark Sea · 1d
Nothing they say can be trusted at this point.
1776 · 1d
Any news on the spontaneous bricking upon new firmware flashing? Happened to me on a test unit tonight. Are these devices going to now permanently be susceptible to spontaneous bricking? 
IntuitiveGuy☯️ · 1d
Absurd they think they can gove advice to other projects after behaved like they did and after all this mess.. no shame at all. Zero accountability.. Disgusting.