Hacked Canadian bitcoin company warns others relying ‘on open-source code’ that AI security failed

1 hour ago 7
An AI software failure led to an estimated US$130 million stolen from users of a Canada-based Bitcoin wallet maker, according to the company.An AI software failure led to an estimated US$130 million stolen from users of a Canada-based Bitcoin wallet maker, according to the company. Photo by Jean Chung /Bloomberg

Article content

The company at the center of a Bitcoin hack has warned that artificial intelligence failed to detect the software flaw that was exploited to steal users’ funds, now estimated at US$130 million.

National Post

THIS CONTENT IS RESERVED FOR SUBSCRIBERS

Enjoy the latest local, national and international news.

  • Exclusive articles by Conrad Black, Barbara Kay and others. Plus, special edition NP Platformed and First Reading newsletters and virtual events.
  • Unlimited online access to National Post.
  • National Post ePaper, an electronic replica of the print edition to view on any device, share and comment on.
  • Daily puzzles including the New York Times Crossword.
  • Support local journalism.

SUBSCRIBE FOR MORE ARTICLES

Enjoy the latest local, national and international news.

  • Exclusive articles by Conrad Black, Barbara Kay and others. Plus, special edition NP Platformed and First Reading newsletters and virtual events.
  • Unlimited online access to National Post.
  • National Post ePaper, an electronic replica of the print edition to view on any device, share and comment on.
  • Daily puzzles including the New York Times Crossword.
  • Support local journalism.

REGISTER / SIGN IN TO UNLOCK MORE ARTICLES

Create an account or sign in to continue with your reading experience.

  • Access articles from across Canada with one account.
  • Share your thoughts and join the conversation in the comments.
  • Enjoy additional articles per month.
  • Get email updates from your favourite authors.

THIS ARTICLE IS FREE TO READ REGISTER TO UNLOCK.

Create an account or sign in to continue with your reading experience.

  • Access articles from across Canada with one account
  • Share your thoughts and join the conversation in the comments
  • Enjoy additional articles per month
  • Get email updates from your favourite authors

Sign In or Create an Account

or

Article content

Canada-based Coinkite Inc., whose affected Coldcard wallets were drained late last week, said the vulnerability the hackers discovered “is a warning for every company building Bitcoin hardware and software, not only us.” Firms using AI to monitor security-critical code should undertake immediate reviews, Coinkite said in a blog post on its website.

Article content

Article content

Article content

“If your team relies on AI review of security-critical code, we recommend you test it specifically against build and sub-module boundaries,” Coinkite said. “We believe many Bitcoin projects, including those that rely on open-source code, require immediate review.”

Article content

By signing up you consent to receive the above newsletter from Postmedia Network Inc.

Article content

The Coldcard hack has unnerved crypto investors because so-called “hard” wallets, which use physical hardware to store private keys and are not connected to the internet, are considered one of the safest ways to secure digital tokens. The breach has put scrutiny on self-custody, one of crypto’s founding principles.

Article content

“Self-custody is a hallmark of digital assets, but Coldcard shows how one point of failure can shake trust in the whole model,” said Nikhil Raghuveera, chief executive officer of Predicate, a blockchain compliance infrastructure provider. “The repercussions could be long-lasting because the ecosystem is built on the promise of being trustless. Over time, the bigger risk is that investors move away from digital assets entirely.”

Article content

Following the hack, roughly 728,000 Bitcoin wallets moved funds in a single day, according to Ki Young Ju, founder of CryptoQuant. The rush to move the tokens was significant enough to push down the “mean coin age,” a measure of the average number of days tokens have remained dormant, for the first time this year, he wrote in a post on X.

Article content

Article content

“The excess likely reflects a move to safer storage,” he wrote.

Article content

Article content

Galaxy Research estimates that four suspected attack waves in the Coldcard hack have resulted in losses of about $130 million, according to its latest analysis.

Article content

map

Article content

Coinkite said the bug appears to have lived in the part of the firmware where two separate software components interact, not in the parent code or cryptographic logic that are subject to most reviews.

Article content

It’s important for the broader ecosystem to understand how the bug arose and why it evaded detection, “so they can avoid similar consequences,” it said.

Article content

“We’ve run AI-assisted review against our critical codebases, including in the weeks before the exploit,” Coinkite said. “It did not catch this vulnerability.”

Article content

Since the incident, Coinkite has tested its code against several frontier AI models, and “none of them caught it,” the company said.

Article content

“It’s a reason for us, and anyone else relying on AI tools, to be specific about what they currently catch and what they might not.”

Article content

Our website is the place for the latest breaking news, exclusive scoops, longreads and provocative commentary. Please bookmark nationalpost.com and sign up for our daily newsletter, Posted, here.

Article content

*** Disclaimer: This Article is auto-aggregated by a Rss Api Program and has not been created or edited by Bdtype.

(Note: This is an unedited and auto-generated story from Syndicated News Rss Api. News.bdtype.com Staff may not have modified or edited the content body.

Please visit the Source Website that deserves the credit and responsibility for creating this content.)

Watch Live | Source Article