AI Exploit Drains $38M in Bitcoin From Coldcard Wallets
Coinkite suspects hackers used artificial intelligence to comb through old open-source firmware and uncover a critical vulnerability.
Advertising disclosure: we may earn a commission when you join an operator via links on this page, at no cost to you. This never dictates our ratings. How we make money
Key takeaways
- A hardware wallet flaw resulted in $38 million worth of Bitcoin being stolen.
- Coinkite revealed that the attacker likely used AI to inspect past versions of its open-source firmware.
- The breach highlights a growing security risk as AI tools make automated vulnerability scanning cheap and fast.
Hackers just walked off with $38 million in Bitcoin from Coldcard hardware wallets. The kicker? The wallet's maker thinks artificial intelligence handed them the key.
Scanning Legacy Code
Coinkite, the company behind Coldcard, says an attacker almost certainly used AI tools to digest old versions of its open-source firmware. Feed enough legacy releases into a model, and it'll spot the hidden crack you missed years ago.
That's the messy paradox of open source. Public code keeps devs honest because anyone can audit it. But "anyone" includes the bad guys, who get a free, detailed map of every change you've ever committed to the repository.
Why it matters
Cold storage rests on one assumption: your wallet's firmware won't betray you. This hack flips that balance. Finding obscure bugs used to take human researchers weeks of tedious reverse-engineering. Now? Automated systems crunch thousands of lines of code in seconds flat. Open-source transparency is still essential, sure. But right now, it's also giving rogue AI agents a front-row seat to hunt down your unpatched mistakes.
Source: Decrypt
Top Crypto Casinos Right Now
🇦🇺 Showing sites that accept players from Australia Change country
Advertising disclosure: we may earn a commission when you join an operator via links on this page, at no cost to you. This never dictates our ratings. How we make money
More info Less info
Why we chose it: A US-oriented casino that turns away only New Jersey. The cashier takes crypto, but the site publishes fewer specifics than any operator we list.
- KYC
- Required
Restricted countries: New Jersey (US).
More info Less info
Why we chose it: One of the widest crypto line-ups of any book we list - seven coins with fast payouts - aimed squarely at Asia and Latin America rather than the US or Western Europe.
- Licence
- Curacao
Restricted countries: Austria, Belgium, Bulgaria, Cyprus, Czechia, Germany, Denmark, Estonia and 21 more.
More info Less info
Why we chose it: Built for American bettors, priced accordingly. Biggest welcome bonus of the five, attached to the heaviest rollover of the five.
- Online since
- 1994
- Licence
- Curaçao
- Payout time
- 24–48 hours (crypto)
- Wagering
- 18x sportsbook / 30x casino
- KYC
- Required
Restricted countries: Belgium, Costa Rica, Croatia, Curaçao, Aruba, Sint Maarten, Caribbean Netherlands, France and 11 more.
Priya Nair
Priya covers the AI side of crypto — agent tokens, decentralised compute and where the two industries actually meet.