When more than $100 million disappeared from wallets generated by Coldcard hardware, the cryptocurrency security community focused on the exploit. The vulnerability in the firmware. The timeline of the attack. The funds moving on-chain.

The WarmBadge Intelligence Fabric was looking at something else.

What The Score Showed

60.3
coinkite.com — WarmBadge Score at Time of Incident Documentation
Grade: C  ·  Risk Level: Medium  ·  Domain State: Active
One unconfirmed community intelligence flag  ·  Email authentication incomplete  ·  Network graph coverage sparse

60.3 is a medium-risk score. Below the 70 threshold we describe as the floor for effective AEO. For a technology company building hardware security products for Bitcoin custody — products where people entrust the protection of significant financial assets — a medium-risk domain trust profile is a signal worth examining.

The engine was not predicting the exploit. Trust scores don't predict events. What the engine was measuring was the infrastructure layer underneath the product: the domain's age and stability, its email authentication configuration, its position in the broader web of trust relationships, its reputation profile across independent intelligence feeds.

On most of those dimensions, coinkite.com was sound. The domain has been registered since 2013 — a thirteen-year-old domain with consistent infrastructure and clean hosting. Zero malicious flags across 91 independent security vendors. Zero phishing flags. A clean reputation profile by any conventional security measurement.

But email authentication was incomplete. And the domain's network graph position — how densely it was cited and linked by other credible sources in the security and cryptocurrency space — was sparse for a company of its profile.

What Incomplete Infrastructure Signals

A hardware wallet manufacturer operates in a trust-critical environment. Its customers are making security decisions based on the company's credibility. They are trusting the product with custody of Bitcoin. In that context, the infrastructure layer underneath the domain is not a technical detail — it is a statement about how seriously the organization takes the mechanics of trust.

Missing email authentication on a security product company's primary domain is not a catastrophic failure. But it is a gap. It signals that the organization has not completed the basic technical hygiene that trust infrastructure requires. It is the kind of signal that a deterministic scoring engine notices and weights, because it is measurable, reproducible, and factual.

The score was not wrong about Coldcard. It was right about something the market was not measuring.

The Score After

By August 10, 2026 — after the exploit had been publicly documented, the incident extensively reported, and the cryptocurrency security community fully engaged — coinkite.com rescored at 71.72.

The infrastructure gap that drove the earlier score — the sparse network graph position — had partially closed. More credible sources were citing and linking to coinkite.com in the context of the security incident. The graph had filled in. The score moved.

That trajectory is itself instructive. A domain's trust score is not fixed. It reflects the current state of its infrastructure and its position in the web of trust relationships. When events force an organization into the public conversation — when credible sources start citing it, investigating it, reporting on it — the graph changes. The score changes with it.

The 60.3 that the engine returned during incident documentation was an accurate measurement of where coinkite.com stood in the trust graph at that moment. The 71.72 it returns today reflects a different moment — one where the network has processed the incident and adjusted its relationships accordingly.

What This Means For AEO

AI systems evaluate domain trust before they decide what to cite. A company building security products with a medium-risk domain trust profile is competing at a disadvantage in the AI citation landscape against companies that have completed their trust infrastructure.

The lesson from the Coldcard score is not that 60.3 caused the exploit. It is that 60.3 was a measurable, accurate reflection of a trust infrastructure that had gaps — gaps that existed independently of the security incident, that were visible to any deterministic scoring engine, and that mattered for how AI systems would evaluate the domain as a credible source.

Trust is not built in response to incidents. It is built before them. The infrastructure signals are there before the events confirm them. That is what the score was telling you.

Check your domain’s trust infrastructure

The WarmBadge Intelligence Fabric evaluates the signals that matter for AI citability. Free. No account required.

Check Your Domain →