Price:

AI audit exposes 85 critical Bitcoin bugs after Coldcard exploit

Aug 12, 2026Summary from 5 podcasts.
  • AI models scanned 390 Bitcoin codebases, finding 85 critical vulnerabilities after a $130M Coldcard exploit.
  • Strict US AI restrictions forced security researchers to rely on cheap, open-source Chinese models like Kimi K3.
  • Holders routed 5,600 Bitcoin through private relays to escape automated mempool bots draining compromised wallets.

A five-year-old firmware flaw in Coldcard hardware wallets allowed attackers to predict private key generation and drain over $110 million from single-signature vaults. The breach shattered trust in isolated hardware devices and triggered a scramble across open-source software. The real story, however, is how the attack happened: cheap artificial intelligence models scanned public source code to uncover the flaw before maintainers knew it existed.

On TFTC: A Bitcoin Podcast, Galaxy Research head Alex Thorn detailed how automated waves of drains targeted Coldcard devices running firmware introduced in March 2021. A compiler conditional bug bypassed the secure element's true random number generator, exposing passive holders who followed standard self-custody best practices. Galaxy Research tracked over 1,500 stolen Bitcoin, noting that attackers deployed unrestricted LLMs to parse public repositories and launch programmatic sweeps within seconds of funds touching compromised addresses.

The attack forced security researchers to deploy automated defense against automated code sweeps. On Bitcoin And, developer Cali and AnchorWatch CEO Rob Hamilton revealed that the OpenSats-funded Bitcoin Red Team deployed AI models to audit open-source Bitcoin infrastructure. Spending over $40,000 on API tokens, their custom harness scanned 171,000 lines of code across 390 repositories, uncovering 85 critical and 635 high-severity vulnerabilities.

That defensive campaign hit friction from American AI policy. On The Jack Mallers Show, Strike CEO Jack Mallers argued that corporate safety filters on domestic models throttled legitimate security research, forcing researchers like Hamilton to pivot to cheap, open-source Chinese LLMs like Kimi K3. While black-hat hackers operate without rate limits or administrative censorship, US researchers hit safety downgrades simply analyzing public blockchain code.

"The bugs were always there. AI simply made finding them virtually free."

- Jack Mallers, The Jack Mallers Show

On Stacker News Live, hosts Keon and Carr emphasized that rapid AI-driven static analysis upends long-held security assumptions. Open-source code visibility, long viewed as Bitcoin's strongest defense, becomes a direct liability unless an active commercial ecosystem has clear financial incentives to review every commit.

"Open-source transparency, historically viewed as Bitcoin’s greatest security asset, gives automated scanners a direct window into vulnerable logic."

- Keon, Stacker News Live

The fallout extended directly into the transaction layer during emergency migrations. On Ungovernable Misfits, Mempool.space researcher Orange Surf tracked panic fund movements following the exploit, noting how holders of 2-of-3 multisig setups faced immediate front-running risks when broadcasting spend transactions over public nodes. Distressed signers routed over 5,600 Bitcoin through Marathon’s Slipstream private transaction service, using direct miner relays to bypass predator bots watching the public mempool.

The loss of self-custodied capital is driving sovereign holders toward collaborative multisig vaults and institutional custodians like Unchained and spot ETFs. On Bitcoin And, host David Bennett noted that while regulated custodians require full identity verification, hardware vulnerabilities accomplished what regulatory crackdowns could not: driving sovereign, non-KYC Bitcoin directly into regulated vaults.