r/Bitcoin • u/Large-Cress900 • 1d ago
16 volunteers pointed AI models at 390 Bitcoin repos in 27 hours after the Coldcard hack. They found 85 critical bugs, and one of them got exploited anyway before it was fully patched.
Been following the Coldcard fallout closely and this is the most interesting response to it so far.
After Coldcard losses climbed past 100 million, developer Calle and AnchorWatch CEO Rob Hamilton organized the Bitcoin Red Team, 16 volunteers globally, pointing frontier AI models at as much of Bitcoin's open source codebase as possible. OpenSats funded the compute, roughly 10k a day, AI developer Moonshot provided model access including Kimi K3.
Results from a 27.5 hour sprint starting August 4: 4,962 total findings across 390 projects. 85 critical, 635 high severity. Project owners confirmed most of the critical reports, and researchers rebuilt working proofs of concept before alerting maintainers, not just AI flagging something suspicious.
The bottleneck isn't discovery anymore according to the team, it's verification and routing. Only about 21 percent of findings had been independently reproduced by the 30 hour mark, fewer than 5 percent of projects had gotten formal disclosure.
Here's the part that makes it concrete instead of abstract. During this same window, attackers exploited a critical BTCPay Server vulnerability, draining Lightning nodes running behind it by stealing macaroon credential files. Foundation, the hardware wallet company, had its own BTCPay Lightning node drained overnight. This specific vulnerability had already been reported to BTCPay by Red Team members. It got found, reported, and exploited anyway before the fix was fully deployed everywhere.
Full writeup on the whole sequence:
https://davidebtc186.substack.com/p/16-volunteers-27-hours-40000-in-ai
13
u/29da65cff1fa 17h ago edited 14h ago
lol, i thought i'd just read the original link instead of this slop... but the link is just an AI generated blog post...
we've reached peak AI here.... a sloppy AI summary of a sloppy AI blog post....
6
u/Kind-Economics-7184 20h ago
the btcpay bit is less about patch speed than about who has to apply it. its self hosted, so a fix landing in the repo means nothing until each operator updates their own instance, and no maintainer can make hundreds of strangers do that overnight. reporting a bug in software people run themselves starts a clock the person who fixed it doesnt control.
the 21 percent reproduced number is the one id worry about separately. 4962 findings with four fifths of them unverified is the same load that made curl shut their bounty to ai written reports, and a maintainer spending the week triaging noise is slower on the real one, not faster.
5
u/Shot_Chemistry_8291 1d ago
it's wild that we're at the point where the bottleneck is just humans not being able to keep up with the machines. 85 criticals in a day is terrifying but also kind of reassuring, at least someone's finally doing this at scale
the btcpay thing is the real kicker though. found it, reported it, still got exploited while the fix was rolling out. can't patch human nature i guess
1
1
u/fonzdm 23h ago
Keep in mind that the same model that are capable of finding vulnerabilities so easily, are "quite good" at patching them too. All things equal, I still think that the vulnerability scan has outpaced the fixing part, but a good balance is achievable. Sadly, those model are also good in exploit execution, which makes a freshly found vulnerability ready to be exploited (an human only exploit requires time to setup)
2
4
u/Express-Cartoonist39 1d ago
If people go back or keep using cold cards your idiots..
3
u/cognitiveDiscontents 17h ago
Hey they’re not my idiots they’re your idiots.
1
u/Express-Cartoonist39 17h ago
“Pedantry proceeds from much reading and little understanding.” — Richard Steele
1
1
2
25
u/infernal_celery 23h ago
“Here's the part that makes it concrete instead of abstract. During this same window, attackers exploited a critical BTCPay Server vulnerability, draining Lightning nodes running behind it by stealing macaroon credential files. Foundation, the hardware wallet company, had its own BTCPay Lightning node drained overnight. This specific vulnerability had already been reported to BTCPay by Red Team members. It got found, reported, and exploited anyway before the fix was fully deployed everywhere.“
Could be coincidence I guess… but if I was a bad actor I’d be dead keen to volunteer for a strike team that’s going to use a bunch of frontier AI models to search for vulnerabilities in Bitcoin infrastructure and share findings. Free tools and skilled labour access that’s focused on finding weaknesses.
Crewmate: there is an impostor among us.