Hardware wallet maker Coldcard says several leading AI coding assistants failed to spot the firmware vulnerability that was later exploited in a major Bitcoin theft, as the scale of the attack continues to grow.
According to the company, AI code review tools including Kimi K3, Claude Fable, and Codex 5.6 did not identify the flaw when asked to analyze the affected firmware, raising questions about how much developers can rely on artificial intelligence for security reviews.
The disclosure comes after a fresh cyberattack targeting Coldcard users.
Coldcard hack: what happened?
Since Thursday, hackers have carried out four waves of attacks, compromising more than 5,200 Bitcoin wallet addresses, according to blockchain intelligence firm Galaxy Research.
The firm said on-chain data shows attackers have already moved around 1,816 Bitcoin, worth nearly $116 million, out of the affected wallets.
Coldcard hardware wallets are designed to keep users’ private keys offline and are widely regarded as one of the safest ways to store cryptocurrency. However, the latest incident shows that even offline storage devices remain vulnerable if flaws exist in the underlying firmware.
After tracing the attack back to the vulnerable code, Coldcard said it wanted to understand why the issue had gone unnoticed for so long.
The company tested several AI-powered code review models using the affected firmware to see whether they would identify the security flaw.
According to Coldcard, none of the tools flagged the vulnerability.
The company did not provide details about the prompts or testing methods it used but said the results demonstrate that AI should be treated as an aid for developers rather than a replacement for experienced security researchers.
AI coding assistants have become increasingly popular across the software industry, helping engineers write code, explain complex functions and review large codebases. Many companies now rely on these tools to improve productivity and speed up development.
But security experts have long cautioned that AI systems can miss subtle vulnerabilities, particularly those involving cryptography, authentication or interactions between different parts of a program.
Hack renews focus on hardware wallet security
Coldcard said the latest incident reinforces the need for traditional security practices such as manual code reviews, independent audits and rigorous testing, especially when software is responsible for protecting valuable financial assets.
The attack has also reignited discussion about the security of cryptocurrency storage.
While hardware wallets remain one of the most secure options available for safeguarding digital assets, the incident illustrates how a flaw in firmware can undermine the protections users expect from offline storage.
As investigators continue tracking the stolen Bitcoin, the breach is likely to add momentum to broader conversations about both firmware security and the role AI should play in software development.
For developers, the message is increasingly clear: AI can help write and review code, but when millions of dollars are at stake, human expertise remains an essential part of the security process.



