pull down to refresh

We run Spiral's vulnerability scanner Loupe on the Coldcard firmware codebase and get definitive answers to four questions:

  1. Could Loupe have found the Coldcard vulnerability in advance?

Yes, but ONLY if a non-default config was passed. Running Loupe with default config did NOT find the Coldcard vulnerability, but without the --bare config flag file it DID.

  1. What would have found the vulnerability in advance?

Anyone could have found the vulnerability by running Loupe pointed at the Coldcard firmware codebase (requiring a Codex account or ~$50 of compute via the OpenAI API), with config flag --bare removed so submodules were included.

  1. How would we run that on other projects now?

Anyone with a Codex account or API credits can point Loupe at any bitcoin OSS codebase for a similar analysis. (Before you do, we recommend coordinating with us so we can organize proper disclosure to affected projects. DMs open)

  1. What other vulnerabilities should we scan for?

See our preliminary analysis at https://t.co/FCWXPUe9ZX

Its recommendation for us:

"OpenAgents should build a security-invariant and evidence workbench, with Loupe as one input rather than the product boundary. Loupe already provides a good candidate lifecycle. The missing product is the machinery that binds a candidate to an exact build, proves or falsifies it, searches related projects, coordinates remediation, and keeps the fix alive. ... Finally, OpenAgents should build the operation around the evidence: private triage, encrypted maintainer contact, embargo state, cross-operator dedup by nonrevealing commitment, regression-pack delivery, release watch, budget accounting, and signed receipts."

We'll build that next.

Watch on X: https://x.com/OpenAgents/status/2083466735944970290