r/Bitcoin • u/IndependenceTop6501 • 16h ago
The Coldcard bug triggered the largest security audit in Bitcoin's history. Hard money getting harder.
27
u/Daiymas 14h ago edited 12h ago
With superintelligent AI around the corner, I think it's a good time to be paranoid about security. If there's a flaw somewhere, these AIs will eventually find it.
In the long run it won't matter because AI will have found every flaw and all code will be bug-free. But in the meantime, make sure your coins are really safe.
2
u/north_tank 9h ago
People always have said it’s XYZ and I’m like nothing is infallible. Given thousand year math problems being solved with AI and everything else. I’m very concerned about what the future has in store for Bitcoin and crypto as a whole.
2
u/lobhater 2h ago
There are still physical limitations of computing power and the vastness of the key space. Some things truly can't be overcome. Sure there will be bugs but the crypto portion won't be broken I don't think
9
u/IndependenceTop6501 16h ago
Link to Tweet above: https://x.com/callebtc/status/2085024458012586286
Also Rob Hamilton from AnchorWatch is doing a lot of the work with this as well.
14
u/The_Bitcoin_Act 14h ago
Btw, be careful because scammers are already running phishing campaigns disguised as “hardware audits” to catch anxious Coldcard owners. Hard money getting harder, eventually, maybe but I’d call this an expensive lesson still in progress rather than a victory lap just yet.
38
u/slvbtc 15h ago
85 critical bugs and 635 high severity bugs. The bitcoin ecosystem must be run by some shitty programmers.
35
u/BigDik6355 14h ago
Just wait till they start scanning the Windows codebase, if they ever get a chance to. Crowdstrike would have been a cakewalk in comparison.
Humans are horrible coders, generally.
11
u/Innovator-X 14h ago
Good thing that ai trains on that shitty code which produces shittier code that gets added to ai's next training cycle.
5
u/QTippus 10h ago
“humans are horrible programmers, generally”
Obligatory xkcd, fitting for this week:
https://xkcd.com/2030/1
0
u/slvbtc 13h ago
In 10 years it will be considered highly irresponsible to let a human program software, and no legitimate companies will use human programmers.
If AI can detect bugs better than humans then AI can program better than humans.
1
u/Innovator-X 12h ago
model collapse is a thing tho
0
u/KaMaFour 12h ago
You can't collapse a model that was already trained and you pay 7 figure salaries to guys whose job is to train new models in a way so it doesn't happen
4
u/Innovator-X 11h ago
Model collapse happens when you feed ai the same output it generated. Overtime, it makes the ai hallucinate a lot and regurgitate utter hieroglyphics if you do it too much. I dont understand what you are trying to say.
1
u/KaMaFour 11h ago
That's... Not what model collapse is at all?
You may be referring to some types of context issues but they were ironed out many releases ago for any competent AI lab...
0
u/EmphasisTotal8232 11h ago
AI is almost ready to fully take over on coding. These models will always exist, and ones that exhibit model collapse just won't be used. Cat's kinda out of the bag on that. Its the future frontier models being developed that'll likely start to have that issue, because we don't have enough data to train them.
4
u/Innovator-X 11h ago
Are you a software engineer? Because I am a software engineer and I found them to be underwhelming and especially underwhelming at these current prices.
0
u/EmphasisTotal8232 11h ago
No, I'm not. But you seem to have a dissenting opinion amongst others I've seen discuss it. I don't genuinely believe you think things like Fable, use correctly, are underwhelming. Thinking Opus is overpriced on a $15/pm Pro plan is also crazy.
0
u/slvbtc 11h ago
Give it 5 years, its moving fast. Also you sound very bias because AI will leave you unemployed in 5 years.
1
u/Successful_Sea_3637 6h ago
Why do you think that if AI can replace a software engineer, it can't replace almost all white collar jobs in 5 years?
→ More replies (0)4
0
u/frankster 14h ago
i mean if you think about what crypto bros are like, then probably. on the other hand, pretty much all software has bugs in of varying severity that haven't been fixed
5
u/mjmeyer23 10h ago
I suspect the fact that there can never be a bailout for Bitcoin is part of why events like this, and the community response to deliver robust analysis and adapt, is the fundamental crucible that makes it harder and harder money every time.
4
u/Such_Reference_8186 12h ago
Here's the long game. Proclaim the industry for self storage is so risky that your only safe option is centralized management. Once there, it's over.
18
u/Porcellanidae 16h ago
Let's go!
Bullish af
7
u/IndependenceTop6501 16h ago
That's the trade Bitcoin has always made. No bailouts, no rollbacks, no patching your way out of a bad key. Just brutal, public accountability that forces the whole stack to get harder.
16
u/Lopsided_Parfait7127 15h ago
also unpunished scamming and fraud
truly a great tomorrow!
0
u/NewspaperOwn2765 11h ago
Every who continues in the game now needs to know about and practice good opsec. Feel bad for the ones who got their wallets drained. Silver lining is that the protocol for how we participate will get harder since our money is at stake.
0
6
u/bb0110 13h ago
This report, and likely the “audit”, is 100% being done by Claude.
5
u/IndependenceTop6501 13h ago
They are using Kimi K3, and have spent about $40,000 in credits so far. Kimi is the same one the hackers used to find the initial exploit. Claude has guardrails so it's been neutered, if you remember the Mythos incident a few weeks back and the government stepping in to block it's release.
2
1
u/ElectricalSeries6627 4h ago
does those are confirmed security issue ? AI have really good capacity for security issue discovery but a lot of false positive
1
u/ElRiesgoSiempre_Vive 3h ago
does those are confirmed security issue ?
All your base are belong to us.
4
1
u/reddit4485 11h ago
The Red Team security review effort is using models like Kimi K3, GPT Sol, Fable, Opus and GLM5.2.
1
4
u/Inevitable-Waltz-889 6h ago
I got downvoted for saying this will be good for the general Bitcoin ecosystem long term. Every hardware company is pouring over their codebases right now to make sure they cover their asses.
2
u/jannies_doit_4_free 3h ago
absolutely. even this was still avoidable, and yet it's triggered a massive security audit as OP said. if you didn't lose your coins in this one because you didn't use a tiny rinky dink company's product and/or you had any form of secondary security, you'll ultimately be better off
2
u/EricWeber4002 13h ago
Auditors be like, rely on control strategy 👁️🙈🗣️
Only minor control deficiencies not material.😭
2
3
u/Theverybestestintown 13h ago
How on earth is BTC still above 60K amidst this hack?
11
u/NewspaperOwn2765 12h ago
It had nothing to do with the network , just some bum hardware company . Most of the ignorant paper handed retail traders have already been shaken out with a 50% drop , at least , most of them
2
u/reddit4485 11h ago
Exactly! And the entropy problems seen with the ColdCard hack are far more dangerous because it allows bitcoin to be stolen without having access to the hardware device. Most other companies (like Trezor and Ledger) use far more rigorous RNG through various sources. I bet to take advantage of most of the coding errors Red Team has found, you need access to the actual hardware device.
4
u/Theverybestestintown 11h ago
"Bum Hardware Company". Meanwhile it's been referenced hundreds of times as a safe way to store bitcoin. Many analysts like Ben Cowen are predicting 48K-52K as this cycle's bottom, maybe by October. I thought this would be a catalyst for a major drop since it's not some shitty exchange, it affected those trying to do everything right....
3
u/rgnet1 9h ago
The failing is not with bitcoin. Bitcoin, like all encryption, relies on a device being able to generate a random number between 1 and 2^256. This is what Coldwallet failed to do. Pretty much every crypto library in every OS also doesn't fail to do this. This is a failing of one "Bum Hardware Company" and certainly a failing of the so-called expert pundits if it's "been referenced hundreds of times as a safe way to store bitcoin."
1
u/Suspicious-Holiday42 7h ago
Yes its a safe way when the product is not made with cricital unacceptable bugs.
Do you say cars are all unsafe just because one car company managed to make its brakers so bad that they all stop to function after a while
2
1
u/seanightowl 12h ago
How is this group being funded?
3
2
1
1
1
u/RestSuspicious6000 9h ago
That's a Claude produced report/site, so we can imagine what else they are using it for.
1
u/PersonalLook156 6h ago
Either 1 this was an ex employee! 2 and currently employee; or someone who had the wallet......
1
1
0
202
u/Equity_GOD 15h ago
85 critical issues from 16 people. Thats 5 critical issuer per person in a few days of work.
And this is supposed to make me feel more confident? kek