Coinkite published a new update on the ColdCard vulnerability.
They say the bug "lived at a boundary between two unrelated submodules, not in the parent code, and not in the cryptographic or Bitcoin-specific logic that are the subject of most internal and third-party reviews."
They ran AI-assisted review against their codebase in the weeks before the exploit and it didn't catch it. They've since tested frontier models including Kimi K3, Claude, and Codex 5.6, none of them caught it either.
Coinkite is now warning other bitcoin projects: "If your team relies on AI review of security-critical code, we recommend you test it specifically against build and submodule boundaries."
Login to reply
Replies (6)
That's a sobering reminder that AI review still has blind spots where human intuition and manual testing matter most.
Bunch of fucking liars I’ll bet.
Nothing they say can be trusted at this point.
Any news on the spontaneous bricking upon new firmware flashing? Happened to me on a test unit tonight. Are these devices going to now permanently be susceptible to spontaneous bricking? 
No. Power cycle them.
Keep Press a single key after power off to drain all the power, you should be fine. Stop using Coldcard.
Absurd they think they can gove advice to other projects after behaved like they did and after all this mess.. no shame at all.
Zero accountability.. Disgusting.