Thirty-eight million dollars in Bitcoin gone in twenty-five minutes, and the tool that may have cracked it open is the same one half the tech world is using to write their emails.

This isn't a story about some shadowy zero-day exploit that required nation-state resources to find. According to Coinkite, the company behind the Coldcard hardware wallet, the most likely explanation is that an attacker ran AI over their own publicly available, open source firmware history — and found something Coinkite's own team had missed. That should make anyone holding serious Bitcoin on hardware they trusted sit down for a minute.

What Actually Happened

The Coldcard Mk3, a hardware wallet that built its reputation on being one of the most security-conscious devices in the space, had a key generation vulnerability. Someone found it, exploited it, and drained wallets to the tune of $38 million. The whole thing reportedly took under half an hour.

Coinkite has since issued a warning specifically about the Mk3, and the working theory from the manufacturer themselves is that an attacker used AI to comb through previous versions of their open source firmware — versions that were publicly accessible to anyone with an internet connection and a subscription to whatever model they fancied. Because the code was open source, there was no barrier to that kind of analysis. That's a double-edged sword that the open source community has always known about, but the speed and thoroughness with which AI can now tear through a codebase has changed the calculation entirely.

The uncomfortable truth here is that open source transparency, which is supposed to be a feature, became the attack surface. Every version, every patch, every incremental change sitting in a public repository — all of it readable, comparable, and now apparently exploitable with tools that are getting sharper by the month.

The AI Angle Is the Bit That Matters

We've written before about [how AI is being used to bankroll infrastructure projects](/getohedz/crypto/hyperscale-data-sells-100-btc-to-bankroll-michigan-ai-centre), but this is a different use of that technology entirely — and a more dangerous one. Using AI to surface security flaws in legacy code is not a new concept in theory. What's new is how accessible and capable these tools have become. An attacker no longer needs a team of specialist security researchers. They need patience and a prompt.

Coinkite being honest about this is worth acknowledging. They're not burying the lead or blaming abstract "sophisticated actors." They've put their own hypothesis on the table. But that honesty doesn't recover anyone's funds, and it doesn't change the fact that the Mk3 warning is arriving after the money is already gone.

For anyone still thinking about the broader picture — [Bitcoin's structural pressures aren't only external](/getohedz/crypto/rising-real-yields-are-a-problem-bitcoin-cannot-ignore). The self-custody argument, the whole point of a hardware wallet, rests on the assumption that the device and its firmware are airtight. When that assumption cracks, it doesn't just hurt the people who lost funds. It rattles confidence in the entire proposition.

Our Take

Hardware wallets have always carried the implicit promise that your keys are your keys. That promise just got stress-tested in the worst possible way. If AI can be used to audit open source firmware faster and more thoroughly than the teams who wrote it, then every wallet manufacturer needs to be running those same tools against their own code — right now, before someone else does. Thirty-eight million reasons why.