pull down to refresh

We review the ongoing Coldcard hack, the (lack of) preventative security for bitcoin OSS projects, and potential future mitigations.

So far $70M of bitcoin and counting has been drained from users' Coldcard hardware wallets setups in an apparently AI-assisted attack, targeting an entropy bug that's been available in source code for five years - missed by everyone.

We evaluate Project Loupe, an opt-in project for agentic AI hardening of bitcoin OSS projects from the Spiral team.

"Did Coldcard opt in to Loupe? I'm guessing not. Maybe they did. Seems that's the good-cop approach: hey let us help you with your security. And now you need someone else to play bad cop: aka 'I found some problems with your shit. Users are depending on you to not ship broken garbage that can get their life savings stolen. Here's the vulnerabilities that we found. And you responsibly disclose that to them using the standard practices of disclosure. But who's doing that? Apparently no one."

Shall we?

Watch on X: https://x.com/OpenAgents/status/2083291233112207718

110 sats \ 0 replies \ @anon 31 Jul

This attack certainly didn't require AI. It's just grossly neglegent enginering, plain and simple. Not even borderline.

The vulnerability looks like it was purposefully built-in. NVK will have known about it for a long time, and there's a fair bit of chatter about it on security blogs.

Also, I would use 'back door' instead of 'bug'.

reply