← Front page

Unchained · Tuesday, August 4, 2026

Coldcard Exploit Uncovered Due to Insufficient Code Review, Potentially Found by AI

The software development failure leading to the Coldcard hack, which remained unfound for approximately five years, is attributed to insufficient eyes on the codebase and a lack of proper review. The codebase was not fully open source, and commits lacked comments. It's suggested that AI may have assisted in uncovering this vulnerability, though it wasn't necessary for its initial discovery.

companyColdcard

The tape

2 quotes
Um, but this is a software development failure that somehow went unfound for five years. It probably was found with the help of AI. Um, people have proven now that now that it's known that AI can find it. Um, but it didn't need AI to find.
This is simply not enough eyes on this codebase. Um, there were obviously issues as well with the codebase, it was not fully open source. Um, and when you look at the codebase, there's, you know, hundreds of commits with no comments, right? Like it doesn't seem like it was properly reviewed either.
Heard on Unchained — “Is Any Cold Wallet Safe? Inside the Coldcard Hack's Wave Three, published Tuesday, August 4, 2026. Heardvine summarizes and quotes with attribution and timestamps, and links to the original everywhere.
Transcribed via Gemini audio transcription · $0.01
Coldcard Exploit Uncovered Due to Insufficient Code Review, Potentially Found by AI — Heardvine