ChainCatcher reports that Bitcoin News posted on X that Coinkite stated the vulnerability existed at the boundary between two unrelated firmware submodules, not within its Bitcoin or cryptographic code, allowing it to evade both manual and AI-assisted code reviews for years. Coinkite said that after the incident, the company tested leading AI models, including Kimi K3, Claude Fable, and Codex 5.6, none of which detected the flaw. Coinkite is now urging security-critical projects to specifically audit build systems and submodule boundaries, warning that AI-assisted development may leave similar blind spots in the Bitcoin ecosystem.
AI code review misses critical vulnerability, exploited in COLDCARD last week
ChaincatcherShare
Last week, a vulnerability incident emerged after a critical flaw in COLDCARD’s firmware was exploited, bypassing both manual and AI-powered code review systems. The issue resided at the interface between two unrelated submodules, not within Bitcoin or cryptocurrency code itself. AI and crypto news platforms reported that Coinkite tested leading AI models—including Kimi K3, Claude Fable, and Codex 5.6—but none detected the flaw. The company now advises projects to audit submodule boundaries, warning that AI-assisted development may introduce similar blind spots in the Bitcoin ecosystem.
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.