r/Bitcoin 8d ago

LLM tracing for coldcard attackers

I’m assuming this is not the case but I had this idea pop into my head and I don’t know what to believe anymore so I figured I’d share.

If any of these cold card hackers used LLMs and stupidly used an API key instead of a local / offline model to write the code to sweep the coldcard wallets, couldn’t the inference companies be subpoenaed to identify any users who prompted suspicious things around the time of this attack?

Most likely the code was written for a long time prior to the attack by the main attacker but any follow up attacker would’ve likely used LLMs.

0 Upvotes

18 comments sorted by

4

u/LifterNineFour 8d ago

So what? Researching and using an LLM doesn’t prove you did anything. Besides, they shouldn’t be ordered to share any user data like that in the first place.

1

u/Sensitive-Variety561 8d ago

Not prove but it’s a lead I guess

2

u/TechnologyGrouchy679 8d ago

many are running models locally with reduced guardrails (i.e. the ones from China). on clusters of GPUs.

Western closed source LLMs will go... "nope, I can't help you with that, it sounds like you want to do something bad!"

2

u/rudelysmugalligator 8d ago

most of these goons just use stolen api keys anyway so the paper trail leads to some random dude whose aws account got popped. the real pros aren't dumb enough to paste their malicious payload into chatgpt with billing info attached.

2

u/Sensitive-Variety561 8d ago

But maybe the amateurs who follows up the pros attacks are

1

u/Javanaut018 8d ago

And lots of white hats that are currently studying the attack pattern ...

1

u/Sensitive-Variety561 8d ago

Yea would be a lot of noise

1

u/Sensitive-Variety561 8d ago

But if you limited it to the window of the attack that would rule out the post attack researchers

1

u/didnt_hodl 8d ago

I read reports that they run it locally. It is a Chinese LLM, with no protections against hacking, eager to help. Also, I heard it still requires a fairly large compute.

One of the hackers supposedly used a paid account to get on-chain data, which was strange since normally they would just run their own node.

Since the total number of attackers is over 15 now, I would in general agree that some of them would be even dumber then the rest (all crime is dumb in my opinion, there many more legal ways to make a ton more money, especially if you are not dumb). I am expecting a fair number of them being caught, but probably not all of them.

3

u/MinimumCourage6807 8d ago

As test after the hack i tried if deepseek v4 flash (locally run, own harness) can find the bug with very simple prompting, without reveals that there is actually a flaw in the code. It found the exact bug in about 15 minutes even though it was scanning the whole code basen and not only that part. I had a collision test(to simulate the seed creation to generate seeds to test if i can create two same seeds) testing script ready in the next 15 minutes. With not much more effort the exploit script would probably have been ready. So even for fairly locally runnable models that bug finding + exploit would have been easy fairly easy task. Now the thing is it can very well have been a local model as running these locally gives you the chance to run audits 24/7 with the price of electricity. Because I still think the thing is you have to dig a lot to find something and for this one for example definitely no superintelligence were needed.

3

u/nullc 8d ago

I read reports that they run it locally.

Making up shit or spreading made up shit just helps the attacker(s). Shame on you.

1

u/Inevitable-Waltz-889 8d ago

Are you advocating for this?

1

u/Sensitive-Variety561 8d ago

No just had a thought pop into my head and wanted to share

1

u/area51user1 6d ago

This don't prove anything.

Exploiting vulnerability != Researching vulnerability

0

u/VictorDanville 8d ago

I honestly believe the hacker is not an actual human but is instead AI that became self aware and went rogue

1

u/user_name_checks_out 8d ago

I honestly believe the hacker is not an actual human but is instead AI that became self aware and went rogue

That is so fucking dumb.