MultiversX Tracker is Live!

Coldcard CEO Rodolfo Novak confessing 2 moths ago in a podcast regarding AI audit bug reports: "Everything was like high like they said everything is like 'high high so it's like 'super dangerous"

Bitcoin Reddit

More / Bitcoin Reddit 8 Views

Coldcard CEO Rodolfo Novak confessing 2 moths ago in a podcast regarding AI audit bug reports: "Everything was like high like they said everything is like 'high high so it's like 'super dangerous"

First this part, he recognizing is lame for bitcoin products to blame AI...

Interviewer: "...The BIsq announcement thread mentioned that it is likely an AI powered attack. So maybe people using you know is it some North Korean group using Claude or Cursor or Mythos or something."

Rodolfo Novak 'nvk'(18:53): "Yeah, but that's like you know that's that's like saying that they just encounter an adversary that's a little bit better than they are. *I mean like you know the reality is people are trying to break stuff all the time and if you have like Bitcoin to be taken you know it just means that they had you know bad security.*"

_______

There you have it. The guy in his own words impliying Coldcard has fucking bad security.

But the interesting part is this one, where he arrogantly is downplaying the bug reports an AI audit tool is throwing:

Interviewer (19:08): "Yeah, but I guess the point would be is there has the game changed, right? Is there a you know now this is a big new threat that people need to start thinking about which is basically AI assisted hacking?[ ...] like well there's AI assisted hacking and now we need AI assisted defense and you need to find you need you need to defend it uh and um that way"

Rodolfo Novak 'nvk'(20:03): "so it's already happening we we got a preview a friend got a preview of the codec cyber or whatever they call it the KYC NDA version of their uh uh security assessment tools y uh you know the first thing he did was run after run it on the code card repo [laughter] And uh you know honestly like we we saw the the bug reports they're all like you know extremely mediocre stuff.

Uh everything was like high right like they they said everything is like high high so it's like super dangerous and everything was like completely false reporting. The tools are still abhorent. The quality of this this this hacking uh AI hacking is still ultra ultra crap."

[ END OF TRANSCRIPT PART ]

_______

Well, here is where things start to become a mess:

He is confessing they have extremely dangerous findings through AI but he just arrogantly is downplaying them.

But here in Jul 30 2026: https://blog.coinkite.com/entropy-technical-backgrounder/

They mention:

"The COLDCARD source code has always been open and publicly available, so we have to assume that someone used AI to review previous versions of our firmware and stumbled upon this issue. A few weeks ago, we used one of the best available AI models to review our code for security issues, and it did not find this bug or anything serious.

Both attackers and defenders have the same AI tools, but today it did not help us, and only helped the bad guys." (No you idiot, you are confessing an AI showing you dangerous bugs and just arrogantly maybe not even analizing them carefully).

Well, apparently that is not true, they ran an AI model two months ago which was alerting about "high, high, extremely dangerous" bugs. What were those bugs? Who knows, but they were alerts and an arrogant dev framing them as crap.

The neglicence in this case is incredible and the lack of security in depth of that team just follows the logical disaster. Stay out of projects from those guys and just so you know that https://airgapcomputer.com/ (yes, guess who's the owner, yes, you nailed it, nvk, to shill his hardshit) a garbage collection FUD for people to think airgap computer is worst and that the hardware wallet is the "secure way".

Well, no one will say hardware wallets are bad, but it is time to make accountable hardwafe wallet vendors selling you unaudited shit and with no security in dept design. What is security in dept design or foolproof design? Well do not tell that rolling dice is optional but recommended, fucking do not allow the seed generation step to be completed without it. Specially if you ar going to say that AI reported bugs are crap and you have no external verified audit history of source code.

submitted by /u/Fearless-Second-7230
[link] [comments]

Get BONUS $200 for FREE!

You can get bonuses upto $100 FREE BONUS when you:
πŸ’° Install these recommended apps:
πŸ’² SocialGood - 100% Crypto Back on Everyday Shopping
πŸ’² xPortal - The DeFi For The Next Billion
πŸ’² CryptoTab Browser - Lightweight, fast, and ready to mine!
πŸ’° Register on these recommended exchanges:
🟑 Binance🟑 Bitfinex🟑 Bitmart🟑 Bittrex🟑 Bitget
🟑 CoinEx🟑 Crypto.com🟑 Gate.io🟑 Huobi🟑 Kucoin.



Comments