The Coldcard case: when even AI misses the flaw — $100M in bitcoin stolen

In August 2026 the cryptocurrency world saw one of the most talked-about heists of the year: attackers stole 1,596 bitcoins —over $100 million— from about 7,300 Coldcard wallets, and a fourth, still unconfirmed wave would bring the total to 2,055 bitcoins, nearly $130 million, according to Galaxy Research. But the fact that should matter most to businesses is not the amount: it is that the manufacturer, Canadian company Coinkite, had analyzed its critical systems with artificial intelligence tools weeks before the attacks — and none of them detected the vulnerability.
A flaw invisible even to AI
Coinkite explained that the bug was not in the main code or in the cryptographic logic of its Coldcard wallets —physical devices, similar to a small calculator, that store bitcoin private keys offline. The vulnerability, present in firmware versions distributed since March 2021, lay in the interaction between two submodules that, in principle, had nothing to do with each other. Thanks to that flaw, cybercriminals could reconstruct private keys and access funds without physically tampering with the devices.
After the incident, the company reviewed the code again with several advanced AI models. None identified the error. CEO and co-founder Rodolfo Novak publicly apologized and took responsibility.
Lessons for your company
The case confirms three principles that apply to any organization, whether or not it holds cryptocurrencies:
- AI is a support, not a guarantee. AI code reviews are valuable for catching common problems, but they do not replace expert human review or integration testing. If an "AI-powered" audit is treated as a final certification, it builds a false sense of security.
- Problems live in the connections. As Coinkite recommended to other manufacturers, the hardest risks usually sit in the interaction between components, not inside them. In your company: review how your systems, vendors and services connect, not just each piece separately.
- Old software is debt that comes due. A flaw went undetected for five years. Keeping systems, firmware and dependencies updated is not optional.
In our region the context is urgent: Latin American organizations face on average more than 2,600 cyberattacks per week, above the global average, and ransomware grew nearly 78% in the past year.
How we approach it at SimCodec
At SimCodec we don't sell fear: we build capacity. As a strategic partner of EPIC, we embed cybersecurity into every service —networks and structured cabling, cloud, video surveillance, automation and custom software— starting with an honest risk diagnosis and prioritizing the controls with the highest return. If the Coldcard case left you wondering how your systems are reviewed and protected, let's talk: we assess your security posture, review your critical integrations and design the plan so the next flaw does not become a crisis.


