Coinkite2026-08-04 20:17:03Coinkite says COLDCARD flaw sat at module boundary and slipped past AI reviewCoinkite said the flaw exploited on COLDCARD last week was not found in its Bitcoin or cryptographic code, but at the boundary between two unrelated firmware submodules. According to a post cited by Bitcoin News on X, that placement helped the bug avoid both manual review and AI-assisted code review for years. After the incident, Coinkite said it tested several frontier AI models, including Kimi K3, Claude Fable, and Codex 5.6, and none of them identified the defect. The company is now urging security-critical projects to run dedicated audits on build systems and submodule boundaries. It also warned that AI-assisted development may leave similar blind spots across the Bitcoin ecosystem. The statement focuses on the limits of current review workflows when flaws appear outside the core Bitcoin or cryptography code path and instead emerge where separate software components meet.1840
Coinkite2026-08-04 20:17:49Coinkite says firmware boundary flaw slipped past human and AI review for yearsCoinkite said a flaw was located at the boundary between two unrelated firmware submodules, rather than in its Bitcoin or cryptographic code, which helped it evade both manual and AI-assisted code review for years. The statement was cited by Bitcoin News in a post on X. After the incident, Coinkite said it tested several frontier AI models, including Kimi K3, Claude Fable, and Codex 5.6. According to the company, none of those models detected the flaw. Coinkite is now urging security-critical projects to conduct dedicated audits of build systems and submodule boundaries. It also warned that AI-assisted development may leave similar blind spots in the Bitcoin ecosystem. The company’s comments focused on where the flaw appeared in the firmware structure and on the limits it observed in both human review and current AI model checks following the incident.1810