Skip to Content News Archives Economy Energy Oil & Gas Renewables Electric Vehicles Mining Commodities Agriculture Real Estate Mortgages Mortgage Rates Finance Banking Insurance Fintech Cryptocurrency Work Wealth Smart Money Wealth Management Investor Personal Finance Family Finance Retirement Taxes High Net Worth FP Comment Executive Women Puzzmo Newsletters Financial Times Business Essentials More Innovation Information Technology FP500 Podcasts Small Business Lives Told Tails Told Shopping Financial Post Store Obituaries Place a Notice Advertising Advertising With Us Advertising Solutions Postmedia Ad Manager Sponsorship Requests Classifieds Place a Classifieds ad Working Profile Settings My Subscriptions Saved Articles My Offers Newsletters Customer Service FAQ News Economy Energy Mining Real Estate Finance Work Wealth Investor FP Comment Executive Women Puzzmo Newsletters Financial Times Business Essentials HomeFinanceCryptocurrencyHacked Canadian bitcoin wallet maker warns AI failed to detect bugFollowing the hack, roughly 728,000 Bitcoin wallets moved funds in a single dayAuthor of the article:Last updated 12 minutes ago You can save this article by registering for free here. Or sign-in if you have an account.Coinkite Inc., whose affected Coldcard wallets were drained late last week, said the vulnerability the hackers discovered “is a warning for every company building Bitcoin hardware and software, not only us.” Photo by Getty Images/iStockphotoThe company at the centre of a bitcoin hack has warned that artificial intelligence failed to detect the software flaw that was exploited to steal users’ funds, now estimated at US$130 million.Subscribe now to read the latest news in your city and across Canada.Exclusive articles from Barbara Shecter, Joe O'Connor, Gabriel Friedman, and others.Daily content from Financial Times, the world's leading global business publication.Unlimited online access to read articles from Financial Post, National Post and 15 news sites across Canada with one account.National Post ePaper, an electronic replica of the print edition to view on any device, share and comment on.Daily puzzles, including the New York Times Crossword.Subscribe now to read the latest news in your city and across Canada.Exclusive articles from Barbara Shecter, Joe O'Connor, Gabriel Friedman and others.Daily content from Financial Times, the world's leading global business publication.Unlimited online access to read articles from Financial Post, National Post and 15 news sites across Canada with one account.National Post ePaper, an electronic replica of the print edition to view on any device, share and comment on.Daily puzzles, including the New York Times Crossword.Create an account or sign in to continue with your reading experience.Access articles from across Canada with one account.Share your thoughts and join the conversation in the comments.Enjoy additional articles per month.Get email updates from your favourite authors.Create an account or sign in to continue with your reading experience.Access articles from across Canada with one accountShare your thoughts and join the conversation in the commentsEnjoy additional articles per monthGet email updates from your favourite authorsSign In or Create an AccountorCanada-based Coinkite Inc., whose affected Coldcard wallets were drained late last week, said the vulnerability the hackers discovered “is a warning for every company building Bitcoin hardware and software, not only us.” Firms using AI to monitor security-critical code should undertake immediate reviews, Coinkite said in a blog post on its website.“If your team relies on AI review of security-critical code, we recommend you test it specifically against build and sub-module boundaries,” Coinkite said. “We believe many Bitcoin projects, including those that rely on open-source code, require immediate review.”Breaking business news, incisive views, must-reads and market signals. Weekdays by 9 a.m.By signing up you consent to receive the above newsletter from Postmedia Network Inc.A welcome email is on its way. If you don't see it, please check your junk folder.The next issue of Posthaste will soon be in your inbox.We encountered an issue signing you up. Please try againThe Coldcard hack has unnerved crypto investors because so-called “hard” wallets, which use physical hardware to store private keys and are not connected to the internet, are considered one of the safest ways to secure digital tokens. The breach has put scrutiny on self-custody, one of crypto’s founding principles.“Self-custody is a hallmark of digital assets, but Coldcard shows how one point of failure can shake trust in the whole model,” said Nikhil Raghuveera, chief executive of Predicate, a blockchain compliance infrastructure provider. “The repercussions could be long-lasting because the ecosystem is built on the promise of being trustless. Over time the bigger risk is that investors move away from digital assets entirely.”Following the hack, roughly 728,000 Bitcoin wallets moved funds in a single day, according Ki Young Ju, founder of CryptoQuant. The rush to move the tokens was significant enough to push down the “mean coin age,” a measure of the average number of days tokens have remained dormant, for the first time this year, he wrote in a post on X.“The excess likely reflects a move to safer storage,” he wrote."Not your keys, not your coins" doesn't work for most people.Even in the Wild West, when banks got robbed weekly, people still kept gold there. Because a home safe without expertise isn't security. It's just a treasure chest with a sign on it.And even if everyone learned…— Ki Young Ju (@ki_young_ju) August 5, 2026Galaxy Research estimates that four suspected attack waves in the Coldcard hack have resulted in losses of about US$130 million, according to its latest analysis.Coinkite said the bug appears to have lived in the part of the firmware where two separate software components interact, not in the parent code or cryptographic logic that are subject to most reviews.It’s important for the broader ecosystem to understand how the bug arose and why it evaded detection, “so they can avoid similar consequences,” it said.“We’ve run AI-assisted review against our critical codebases, including in the weeks before the exploit,” Coinkite said. “It did not catch this vulnerability.”Since the incident, Coinkite has tested its code against several frontier AI models, and “none of them caught it,” the company said.“It’s a reason for us, and anyone else relying on AI tools, to be specific about what they currently catch and what they might not.” Join the Conversation This website uses cookies to personalize your content (including ads), and allows us to analyze our traffic. Read more about cookies here. By continuing to use our site, you agree to our Terms of Use and Privacy Policy.