MEMPOL!TICS
← BACK TO THE BOARD
MaximalistTUE AUG 11 · 12:34 PM ET · Forbes + Protos investigative

NVK'S DEFENSE: 'AI DID IT.' SECURITY EXPERTS: 'A BUILD FLAG DISABLED THE RNG FOR FIVE YEARS AND A HUMAN SHOULD HAVE CAUGHT IT.'

"To every other developer: we believe this is a sober reality of the new AI paradigm. AI-assisted code review can now find latent bugs at a speed that is outpacing even the industry's most seasoned experts." — NVK, follow-up defense statement.
Rodolfo Novak (NVK), Coldcard co-founder at Coinkite, escalated his defense of the entropy-vulnerability exploit that has drained $130M+ from Coldcard MK3 self-custody wallets. His new framing: this is not a Coldcard failure. This is an AI-paradigm failure that any developer could face. AI-assisted code review, per his statement, now outpaces the industry’s most seasoned experts at surfacing latent bugs. The implication: humans could not have caught this. Bad-actor AI did.
WHAT THE SECURITY COMMUNITY IS SAYINGSecurity specialists have pushed back on the record. Wizard Sardine’s post-mortem: one character in a build flag stood between the safeguard and the drain. That is human engineering failure — a wrong constant, wrongly compiled, deployed to production for five years. Any conventional code review should have caught it. Any static-analysis tool should have flagged it. AI-assisted review would have found it faster, yes — but the AI framing shifts the responsibility off the vendor and onto a shared industry ‘paradigm.’ Security specialists on record: that framing does not match the technical facts.
The Protos investigation from Aug 7 documented NVK deleting specific X posts as the losses climbed. Peter Todd caught the November 2024 Blockclock ‘back door’ post going dark. Zach Herbert of Foundation on record: ‘NVK is currently deleting old posts from 2020 to try to clean up the history.’ Matt Kratter, Hodlonaut, Erin Malone, Greg Tonoski all documented specific deletions. That is not AI-paradigm failure. That is corporate-PR-tier reputation management. The distinction matters because the sovereignty tier is watching.
WHY THE FRAMING FAILSThe AI-defense framing has three problems on its face:

1. The bug predates the AI-review era. The vulnerable code was compiled and shipped starting 2019-2020, when AI code review was not a viable defender. Blaming a post-hoc AI advantage for a five-year human failure is chronologically incoherent.
2. Peter Todd, Casa, Foundation, Wizard Sardine did catch it — without AI. Human security researchers found and reported the vulnerability. AI wasn’t needed as the discoverer. AI was needed as the exploiter, at scale. That’s a different failure mode.
3. The response, not the bug, is the operator-class question. Delete-the-record-and-blame-the-paradigm is not sovereignty-tier behavior.
The Maximalist tier read: Coldcard could have preserved its brand equity by taking responsibility, publishing the timeline, funding a class-action-safe restitution mechanism, and open-sourcing the audit trail. It chose instead to delete posts, blame AI, and issue an apology-plus-pivot statement. That is corporate-PR playbook, not sovereignty-tier response. Foundation, Bitkey, SeedSigner — Coldcard’s three main hardware-wallet competitors — are watching this response and taking notes on what NOT to do. The sovereignty tier can tell the difference.
The build flag was human.
The exploit was mechanical.
The AI defense is corporate PR.
Sovereignty is the response, not the bug.
READ THE FORBES COLDCARD INVESTIGATION →
Forbes + Protos · corroborated by @peterktodd, @zherbert, @mattkratter, @hodlonaut, Wizard Sardine