pull down to refresh

AI just changed the economics of security.

A vulnerability can sit unnoticed in public code for five years, then an AI-assisted audit can tear through the assumptions in hours. That is exactly what the Zcash and Coldcard incidents illustrate.

Well, I think the lesson isn't “AI is dangerous.”

The lesson is: trusting that nobody will look closely enough is no longer a security model.

And the Coldcard incident makes this painfully concrete. The community has already documented the Coldcard Mk2–Mk5 and Q firmware vulnerability, here: #1536739, the technical autopsy of the entropy failure, here: #1546011, and the investigative history of the entropy bug, here: #1540008.

There is even a post documenting an AI-assisted audit that reportedly found thousands of vulnerabilities across Bitcoin-related projects, here: #1542869.

Open-source Bitcoin software needs more adversarial eyes, more reproducible builds, more independent audits, stronger entropy verification, and continuous testing.

Trust less. Verify more.

If attackers can use AI to find the bug, the community should be using AI to find it first.

The machine isn't the enemy.

The dangerous part is letting the machine find your assumptions before you do.

82 sats \ 0 replies \ @anon 21 Sep

Monero, liquid network, zcash had or have inflation bugs relating to confidential transactions. This all shows that bitcoins layer one design of transparency and security in lieu of confidential transactions was a feature not a flaw. As for zcash, it was rumored that it was being exploited via an inflation bug for years, but unconfirmed.

reply