{"slug": "coldcard-says-ai-code-review-tools-missed-firmware-flaw-behind-wallet", "title": "Coldcard says AI Code review tools missed firmware flaw behind wallet vulnerability", "summary": "Hardware wallet maker Coldcard reported that AI code review tools including Kimi K3, Claude Fable, and Codex 5.6 failed to detect the firmware vulnerability exploited in a Bitcoin theft that has compromised more than 5,200 wallet addresses, with attackers moving nearly 1,816 Bitcoin worth about $116 million, according to blockchain intelligence firm Galaxy Research. Coldcard said the results show AI should be an aid for developers, not a replacement for experienced security researchers.", "body_md": "Hardware wallet maker Coldcard says several leading AI coding assistants failed to spot the firmware vulnerability that was later exploited in a major Bitcoin theft, as the scale of the attack continues to grow.\n\nAccording to the company, AI code review tools including Kimi K3, Claude Fable, and Codex 5.6 did not identify the flaw when asked to analyze the affected firmware, raising questions about how much developers can rely on artificial intelligence for security reviews.\n\nThe disclosure comes after a fresh[ cyberattack targeting Coldcard users](https://thecoinheadlines.com/crypto/coldcard-security-flaw-leads-to-38m-bitcoin-theft-across-500-wallets/article-28018/).\n\n## Coldcard hack: what happened?\n\nSince Thursday, hackers have carried out four waves of attacks, compromising more than 5,200 Bitcoin wallet addresses, according to blockchain intelligence firm Galaxy Research.\n\nThe firm said on-chain data shows attackers have already moved around 1,816 Bitcoin, worth nearly $116 million, out of the affected wallets.\n\nColdcard hardware wallets are designed to keep users’ private keys offline and are widely regarded as one of the safest ways to store cryptocurrency. However, the latest incident shows that even offline storage devices remain vulnerable if flaws exist in the underlying firmware.\n\nAfter tracing the attack back to the vulnerable code, Coldcard said it wanted to understand why the issue had gone unnoticed for so long.\n\nThe company tested several AI-powered code review models using the affected firmware to see whether they would identify the security flaw.\n\nAccording to Coldcard, none of the tools flagged the vulnerability.\n\nThe company did not provide details about the prompts or testing methods it used but said the results demonstrate that AI should be treated as an aid for developers rather than a replacement for experienced security researchers.\n\nAI coding assistants have become increasingly popular across the software industry, helping engineers write code, explain complex functions and review large codebases. Many companies now rely on these tools to improve productivity and speed up development.\n\nBut security experts have long cautioned that AI systems can miss subtle vulnerabilities, particularly those involving cryptography, authentication or interactions between different parts of a program.\n\n## Hack renews focus on hardware wallet security\n\nColdcard said the latest incident reinforces the need for traditional security practices such as manual code reviews, independent audits and rigorous testing, especially when software is responsible for protecting valuable financial assets.\n\nThe attack has also reignited discussion about the [security of cryptocurrency storage](https://thecoinheadlines.com/tech-and-ai/cloudflare-to-fuel-autonomous-agentic-transactions-debuts-ai-wallet-service/article-28354/).\n\nWhile hardware wallets remain one of the most secure options available for safeguarding digital assets, the incident illustrates how a flaw in firmware can undermine the protections users expect from offline storage.\n\nAs investigators continue tracking the stolen Bitcoin, the breach is likely to add momentum to broader conversations about both firmware security and the role AI should play in software development.\n\nFor developers, the message is increasingly clear: AI can help write and review code, but when millions of dollars are at stake, human expertise remains an essential part of the security process.", "url": "https://wpnews.pro/news/coldcard-says-ai-code-review-tools-missed-firmware-flaw-behind-wallet", "canonical_source": "https://thecoinheadlines.com/crypto/coldcard-says-ai-code-review-tools-missed-firmware-flaw-behind-wallet-vulnerability/article-28409/", "published_at": "2026-08-05 04:04:51+00:00", "updated_at": "2026-08-05 04:08:02.529417+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-tools", "ai-safety"], "entities": ["Coldcard", "Kimi K3", "Claude Fable", "Codex 5.6", "Galaxy Research"], "alternates": {"html": "https://wpnews.pro/news/coldcard-says-ai-code-review-tools-missed-firmware-flaw-behind-wallet", "markdown": "https://wpnews.pro/news/coldcard-says-ai-code-review-tools-missed-firmware-flaw-behind-wallet.md", "text": "https://wpnews.pro/news/coldcard-says-ai-code-review-tools-missed-firmware-flaw-behind-wallet.txt", "jsonld": "https://wpnews.pro/news/coldcard-says-ai-code-review-tools-missed-firmware-flaw-behind-wallet.jsonld"}}