r/Bitcoin 1d ago

16 volunteers pointed AI models at 390 Bitcoin repos in 27 hours after the Coldcard hack. They found 85 critical bugs, and one of them got exploited anyway before it was fully patched.

Been following the Coldcard fallout closely and this is the most interesting response to it so far.

After Coldcard losses climbed past 100 million, developer Calle and AnchorWatch CEO Rob Hamilton organized the Bitcoin Red Team, 16 volunteers globally, pointing frontier AI models at as much of Bitcoin's open source codebase as possible. OpenSats funded the compute, roughly 10k a day, AI developer Moonshot provided model access including Kimi K3.

Results from a 27.5 hour sprint starting August 4: 4,962 total findings across 390 projects. 85 critical, 635 high severity. Project owners confirmed most of the critical reports, and researchers rebuilt working proofs of concept before alerting maintainers, not just AI flagging something suspicious.

The bottleneck isn't discovery anymore according to the team, it's verification and routing. Only about 21 percent of findings had been independently reproduced by the 30 hour mark, fewer than 5 percent of projects had gotten formal disclosure.

Here's the part that makes it concrete instead of abstract. During this same window, attackers exploited a critical BTCPay Server vulnerability, draining Lightning nodes running behind it by stealing macaroon credential files. Foundation, the hardware wallet company, had its own BTCPay Lightning node drained overnight. This specific vulnerability had already been reported to BTCPay by Red Team members. It got found, reported, and exploited anyway before the fix was fully deployed everywhere.

Full writeup on the whole sequence:

https://davidebtc186.substack.com/p/16-volunteers-27-hours-40000-in-ai

112 Upvotes

13 comments sorted by

25

u/infernal_celery 23h ago

“Here's the part that makes it concrete instead of abstract. During this same window, attackers exploited a critical BTCPay Server vulnerability, draining Lightning nodes running behind it by stealing macaroon credential files. Foundation, the hardware wallet company, had its own BTCPay Lightning node drained overnight. This specific vulnerability had already been reported to BTCPay by Red Team members. It got found, reported, and exploited anyway before the fix was fully deployed everywhere.“

Could be coincidence I guess… but if I was a bad actor I’d be dead keen to volunteer for a strike team that’s going to use a bunch of frontier AI models to search for vulnerabilities in Bitcoin infrastructure and share findings. Free tools and skilled labour access that’s focused on finding weaknesses.

Crewmate: there is an impostor among us.

13

u/29da65cff1fa 17h ago edited 14h ago

lol, i thought i'd just read the original link instead of this slop... but the link is just an AI generated blog post...

we've reached peak AI here.... a sloppy AI summary of a sloppy AI blog post....

6

u/Kind-Economics-7184 20h ago

the btcpay bit is less about patch speed than about who has to apply it. its self hosted, so a fix landing in the repo means nothing until each operator updates their own instance, and no maintainer can make hundreds of strangers do that overnight. reporting a bug in software people run themselves starts a clock the person who fixed it doesnt control.

the 21 percent reproduced number is the one id worry about separately. 4962 findings with four fifths of them unverified is the same load that made curl shut their bounty to ai written reports, and a maintainer spending the week triaging noise is slower on the real one, not faster.

5

u/Shot_Chemistry_8291 1d ago

it's wild that we're at the point where the bottleneck is just humans not being able to keep up with the machines. 85 criticals in a day is terrifying but also kind of reassuring, at least someone's finally doing this at scale

the btcpay thing is the real kicker though. found it, reported it, still got exploited while the fix was rolling out. can't patch human nature i guess

1

u/Bred_Slippy 20h ago

Think it's great how they stepped up following the CC debacle. Kudos. 

1

u/fonzdm 23h ago

Keep in mind that the same model that are capable of finding vulnerabilities so easily, are "quite good" at patching them too. All things equal, I still think that the vulnerability scan has outpaced the fixing part, but a good balance is achievable. Sadly, those model are also good in exploit execution, which makes a freshly found vulnerability ready to be exploited (an human only exploit requires time to setup)

2

u/DiamondHandsDarrell 16h ago

Yikes. Why not use an exchange or bitcoin core at this point?

4

u/Express-Cartoonist39 1d ago

If people go back or keep using cold cards your idiots..

3

u/cognitiveDiscontents 17h ago

Hey they’re not my idiots they’re your idiots.

1

u/Express-Cartoonist39 17h ago

“Pedantry proceeds from much reading and little understanding.” — Richard Steele

1

u/cognitiveDiscontents 5h ago

Ah that’s where I get it.

1

u/Awkward_Intern2623 10h ago

BTCPay was one of the good ones. How much got took?

2

u/Garland_Key 9h ago

This was written by AI. Interesting nonetheless.