Unchained · Tuesday, August 4, 2026
The software development failure leading to the Coldcard hack, which remained unfound for approximately five years, is attributed to insufficient eyes on the codebase and a lack of proper review. The codebase was not fully open source, and commits lacked comments. It's suggested that AI may have assisted in uncovering this vulnerability, though it wasn't necessary for its initial discovery.
“Um, but this is a software development failure that somehow went unfound for five years. It probably was found with the help of AI. Um, people have proven now that now that it's known that AI can find it. Um, but it didn't need AI to find.”
“This is simply not enough eyes on this codebase. Um, there were obviously issues as well with the codebase, it was not fully open source. Um, and when you look at the codebase, there's, you know, hundreds of commits with no comments, right? Like it doesn't seem like it was properly reviewed either.”