AI-Assisted Code Review Fails to Detect Vulnerability, Enabling $100 Million Bitcoin Theft

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Canadian company Coinkite used AI tools to review Coldcard wallet firmware, but the AI failed to detect a critical vulnerability in the interaction between software components. This oversight enabled attackers to steal over $100 million in bitcoin, highlighting limitations of current AI code auditing systems.[AI generated]

Why's our monitor labelling this an incident or hazard?

The AI system was explicitly involved in the code review process but failed to detect a vulnerability that was later exploited, resulting in a large-scale theft of bitcoin worth over 100 million USD. This constitutes harm to property and financial harm to users, meeting the criteria for an AI Incident. The AI's malfunction (failure to detect the vulnerability) directly contributed to the harm. Hence, this event qualifies as an AI Incident rather than a hazard or complementary information.[AI generated]
AI principles
Robustness & digital securitySafety

Industries
Digital securityFinancial and insurance services

Affected stakeholders
ConsumersBusiness

Harm types
Economic/PropertyReputational

Business function:
Monitoring and quality control

AI system task:
Reasoning with knowledge structures/planning


Articles about this incident or hazard