We run Spiral's vulnerability scanner Loupe on the Coldcard firmware codebase and get definitive answers to four questions:
- Could Loupe have found the Coldcard vulnerability in advance?
Yes, but ONLY if a non-default config was passed. Running Loupe with default config did NOT find the Coldcard vulnerability, but without the --bare config flag file it DID.
- What would have found the vulnerability in advance?
Anyone could have found the vulnerability by running Loupe pointed at the Coldcard firmware codebase (requiring a Codex account or ~$50 of compute via the OpenAI API), with config flag --bare removed so submodules were included.
- How would we run that on other projects now?
Anyone with a Codex account or API credits can point Loupe at any bitcoin OSS codebase for a similar analysis. (Before you do, we recommend coordinating with us so we can organize proper disclosure to affected projects. DMs open)
- What other vulnerabilities should we scan for?
See our preliminary analysis at https://t.co/FCWXPUe9ZX
Its recommendation for us:
"OpenAgents should build a security-invariant and evidence workbench, with Loupe as one input rather than the product boundary. Loupe already provides a good candidate lifecycle. The missing product is the machinery that binds a candidate to an exact build, proves or falsifies it, searches related projects, coordinates remediation, and keeps the fix alive. ... Finally, OpenAgents should build the operation around the evidence: private triage, encrypted maintainer contact, embargo state, cross-operator dedup by nonrevealing commitment, regression-pack delivery, release watch, budget accounting, and signed receipts."
We'll build that next.
Watch on X: https://x.com/OpenAgents/status/2083466735944970290
https://twiiit.com/OpenAgents/status/2083466735944970290