A partially open electronic device revealing its
AI

Coinkite says AI missed bug behind $130M Coldcard wallet drain

The hardware-wallet maker urged immediate reviews of AI monitoring on security-critical code after wallets were drained late last week.

By Elliot Marsh8 min read

Coinkite said a software vulnerability that drained affected Coldcard Bitcoin wallets late last week slipped past an AI-based security workflow, with losses now estimated at $130 million. The company framed the miss as a broader warning about relying on AI to monitor security-critical code paths where a single flaw can translate directly into theft.

Key Takeaways

  • A software flaw exploited in affected Coldcard Bitcoin wallets led to an estimated $130 million in stolen funds.
  • Coinkite tied the miss to artificial intelligence failing to detect the vulnerability before it was exploited.
  • The draining occurred late last week, positioning the event as a self-custody incident rather than an exchange or pooled-custody breach.
  • Coinkite called for immediate reviews by any firm using AI to monitor security-critical code and framed the vulnerability as an industry-wide warning.

Coldcard Wallets Drained, Losses Estimated at $130M

Coinkite, the Canada-based maker of Coldcard hardware wallets, said hackers exploited a software vulnerability to steal users’ funds from “affected Coldcard wallets,” with losses now estimated at $130 million. The company’s description matters because it points to a self-custody failure mode, not an exchange solvency event where a single balance sheet absorbs the hit.

The timeline in the company’s account is tight and still imprecise. Coinkite said the wallets were drained “late last week,” and it published its warning on Aug. 5. The excerpt does not specify the number of impacted devices or users, which Coldcard models were affected, or whether the drain was concentrated in a small set of high-balance wallets versus a broad distribution.

Mechanically, a hardware wallet is supposed to keep private keys offline, but it still depends on firmware and companion software behaving exactly as intended. When a bug sits in a signing path, update path, or any code that touches key material, “self-custody” stops being a binary promise and becomes an operational discipline with sharp edges.

Coinkite’s AI-Missed-Bug Claim and the Industry-Wide Warning

Coinkite’s core claim is not just that a vulnerability existed, but that an AI-based security workflow failed to catch it before attackers did. The company said artificial intelligence failed to detect the software flaw that was exploited to steal users’ funds, and it used the incident to push a process warning outward to the rest of the industry.

Coinkite’s verbatim framing is explicit: the vulnerability hackers discovered “is a warning for every company building Bitcoin hardware and software, not only us.” That is a deliberate attempt to make the takeaway about development and monitoring practices across custody products, not a one-off vendor mistake.

The phrase “security-critical code” is doing real work here. In custody-grade products, it means the parts of the stack where a defect can directly enable theft or loss, including code that governs key generation, transaction signing, address display, firmware updates, and any logic that can be coerced into signing something the user did not intend. If AI is being used to scan diffs, flag suspicious changes, or triage vulnerability reports in those areas, a false negative is not a nuisance. It is an incident.

Coinkite urged firms using AI to monitor security-critical code to undertake immediate reviews. The call reads less like a marketing swipe at “AI hype” and more like a control-gap admission: some teams may have treated AI monitoring as a substitute for the slower, more expensive controls that tend to catch edge-case failures, like adversarial code review, formal verification on narrow components, or independent audits focused on signing and update flows.

What Traders Can and Can’t Infer From the AI Angle Right Now

For traders, the cleanest inference is category-level, not token-level. This is a self-custody trust event: the kind that can change user behavior around hardware wallets, firmware updates, and how much operational risk people are willing to hold personally versus outsourcing to custodians.

What stands out is how the AI angle changes the narrative of “how this slipped.” If the market reads this as a tooling failure, the spillover is not limited to one vendor. Any custody product that has publicly leaned on AI-assisted code review, automated monitoring, or AI triage for vulnerability management can get dragged into the same question: which controls are actually gating releases and which are advisory.

There is also a more practical trader takeaway: incident headlines about hardware wallets tend to compress time horizons. Users who were comfortable sitting in cold storage can move funds quickly when the perceived safety of the device class is questioned, and that can show up as short-term on-chain movement, exchange inflows, and a burst of demand for alternative custody setups.

The excerpt still leaves major gaps that limit what can be concluded. It does not identify which AI system failed, whether it was used for pre-merge code review, post-merge monitoring, anomaly detection, or something else entirely. It also does not establish the exploit path, whether the vulnerability required user interaction, whether it was tied to a specific firmware version, or whether the compromise depended on supply-chain tampering versus pure software.

The $130 million figure is directionally important but still provisional in the form presented here. It is described as an estimate without a methodology, on-chain attribution, or a breakdown that would let the market separate confirmed theft from suspected exposure.

Confirmations to Watch: Tooling Details, Patch Status, and Loss Accounting

The next confirmations that matter are the ones that turn this from a cautionary headline into an actionable risk model.

First is tooling specificity. Coinkite has said AI failed to detect the flaw, but it has not, in the excerpt provided, named the AI system or described how it was integrated into the security workflow. A concrete description of whether the AI was acting as a reviewer, a monitor, or a triage layer would clarify whether the miss was model-specific, process-specific, or simply a case of AI being asked to cover a class of bugs it is structurally bad at catching.

Second is remediation. The excerpt does not include patch status, firmware or software version guidance, or user instructions beyond the call for immediate reviews. Traders should look for a clear statement on whether a fix is available, what users must do to be protected, and whether Coinkite has identified additional affected vectors beyond the phrase “affected Coldcard wallets.”

Third is loss accounting. If the $130 million estimate is updated with on-chain attribution, wallet clustering, or a breakdown of confirmed versus suspected theft, that will determine whether this stays a contained incident or becomes a longer-running overhang. Movement patterns also matter: confirmed flows into exchanges or mixers would change how quickly the market expects the stolen funds to be liquidated.

Finally, watch for second-order industry response. Coinkite framed this as a warning for “every company building Bitcoin hardware and software,” and the real-world test of that claim is whether other vendors issue advisories, announce audits, or disclose changes to AI-assisted security workflows in response.

My Read: AI Security Workflows Are a Control, Not a Guarantee, in Custody-Grade Code

The part that decides how big this gets is not the headline number, it is the control boundary. Coinkite is telling the market that an AI-based workflow sat somewhere in the path that was supposed to prevent a security-critical bug from shipping or persisting, and it missed. That is not surprising in the abstract, because AI tools are probabilistic and custody code is adversarial, but it is still a meaningful admission because it forces the question every security team hates answering in public: what was the last deterministic gate before users’ keys were at risk.

There are two plausible scenarios from here, and they trade on different confirmations. If Coinkite can specify the AI tooling and show it was a non-blocking layer, the incident reads as a conventional vulnerability that happened to evade one detection method, with the real fix being tighter review and patch distribution. If, instead, the follow-up reveals that AI monitoring was treated as a primary control for security-critical code, then the warning is not rhetorical. It is a map of a common failure mode across the industry, where teams replace expensive human review and narrow formal methods with broad AI scanning and call it “coverage.”

The threshold that matters for market impact is whether remediation is crisp and bounded. A clear patch, clear affected versions, and a stable loss accounting path would keep this in the lane of a self-custody incident that bruises trust but does not rewrite the category. If the scope stays vague, the tooling remains unnamed, and the $130 million estimate floats without on-chain confirmation, the story becomes about uncertainty itself, and uncertainty is what drives users to move funds.

What would confirm the core thesis is a concrete disclosure of the AI workflow’s role alongside a patch and verifiable loss accounting, because that would show whether AI was a thin safety net or a misplaced substitute for custody-grade controls.

Sources