● EN VIVO

EL DIARIODICE

Independent digital journalism, economy and analysis

← Back to homepage
Technology⏱️ 2 min read

US$100 million bitcoin theft: the Coldcard case

US$100 million bitcoin theft: the Coldcard caseFoto: EFE

Artificial intelligence did not see it. And it cost more than US$100 million in bitcoin. Canadian company Coinkite, maker of Coldcard cold wallets — one of the most respected among cryptocurrency users — acknowledged that its AI-assisted code reviews failed to detect the vulnerability that allowed the theft.

The Toronto-based company explained that it analyzed its critical systems with artificial intelligence even weeks before the attacks, and that after the incident it re-tested the code with several advanced models: none identified the flaw.

Where the error was

The most unsettling part of the case is the nature of the bug. According to Coinkite, the error was in the interaction between two unrelated submodules, not in the main code or the cryptographic logic — exactly the areas reviews usually focus on.

In other words: auditors, human and machine, looked where bugs “normally live.” This one lived in the space between two pieces.

The lesson for the crypto world

The case hits confidence in the security of cold wallets, considered for years the gold standard of custody. If the AI reviewing the code does not see the problem, and humans do not either, what is left?

The industry’s answer is uncomfortable: more audit layers, more independent testing and less blind faith in any tool — including the artificial intelligence that promised to eliminate human error.

The key figure

US$100 million stolen, zero prior detections by AI. The Coldcard case is the most expensive warning so far: AI can speed up auditing, but it still cannot replace skepticism.

Sources

  1. bitcoinmagazine.com
  2. forbes.com
  3. coindesk.com
  4. coindesk.com