- Sources: primary
- Summary: Coinkite states it ran AI-assisted review against its critical codebases, including in the weeks before the exploit, and that the review did not catch the vulnerability. It states that since the incident it retested the code against frontier models including Kimi K3, Claude Fable and Codex 5.6, and that none of them caught it either. Coinkite places the bug at a boundary between two unrelated submodules, not in the parent code and not in the cryptographic or Bitcoin-specific logic that most internal and third-party reviews target, and says the flag check looked correct, so the bug went unnoticed while its impact grew with each release. Coinkite recommends that teams relying on AI review of security-critical code test it specifically against build and submodule boundaries, and it published a historical-disclosures page as a record of public security research and advisories affecting COLDCARD. The post does not identify the affected firmware versions. In place of a version range it states a user-scope condition: move funds now if the seed was generated with the affected firmware without at least 50 independent private dice rolls and is not protected by a strong unique BIP-39 passphrase. This is the company's own account of its own failure and no third party has reproduced the model tests.
- Why it matters: The failure mode is cross-submodule symbol resolution, so a review scoped to a repository's own source never reads the code that actually runs.
- Follow-up: Track whether any third party reproduces the model tests against the submodule boundary.
send feedback on this story