Coinkite published a new update on the ColdCard vulnerability.
They say the bug "lived at a boundary between two unrelated submodules, not in the parent code, and not in the cryptographic or Bitcoin-specific logic that are the subject of most internal and third-party reviews."
They ran AI-assisted review against their codebase in the weeks before the exploit and it didn't catch it. They've since tested frontier models including Kimi K3, Claude, and Codex 5.6, none of them caught it either.
Coinkite is now warning other bitcoin projects: "If your team relies on AI review of security-critical code, we recommend you test it specifically against build and submodule boundaries."
They say the bug "lived at a boundary between two unrelated submodules, not in the parent code, and not in the cryptographic or Bitcoin-specific logic that are the subject of most internal and third-party reviews."
They ran AI-assisted review against their codebase in the weeks before the exploit and it didn't catch it. They've since tested frontier models including Kimi K3, Claude, and Codex 5.6, none of them caught it either.
Coinkite is now warning other bitcoin projects: "If your team relies on AI review of security-critical code, we recommend you test it specifically against build and submodule boundaries."
82❤️7✨1👍1😂1🤙1🤣1