COLDCARD RNG incident the public record, collected and explained
Informational only, and this site never asks for your seed words. details

Informational only. This is an open source collection of what others have published about the incident, together with an explanation of it. It is not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite. Material is attributed and quoted as published; where sources disagree their scenarios are kept separate with their assumptions rather than reconciled into one answer. Everything is meant to be checked against the linked evidence rather than taken on trust. Act on your own judgement about a particular situation. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it, and contributions containing recovery words or private keys are not accepted.

r/Bitcoin thread on the Claude Code vulnerability-audit reproduction

reddit-ai-discovery-thread

https://www.reddit.com/r/Bitcoin/comments/1vddeuy/

Latest reviewed change

source content difference between and

The thread gained a new comment blaming speculators and defending open-source code, while an earlier open-versus-closed-source comment was replaced and the live comment count expanded.

seen +10 -12 full history below
 edited: 1785671653
 body:
 ... that is exactly how it works
-
-comment: p18gaim
-parent: t1_p18e31w
-author: Aggravating_Stage996
-created_utc: 1785668951

First lines only. The complete diff is in the timeline below.

Organisation
r/Bitcoin
Evidence role
Community discussion
Published
2026-08-02
Source changes
16
Detected differences
16
Unreviewed
0
Copies held
17

A discussion thread claiming an LLM prompted only to "check for vulnerabilities" surfaced the defect after eight minutes, and asserting the theft exceeded $100m. Both figures are the thread's own; the post-publication discovery reproductions this archive holds are attributed on /response/ai/. Captured for how the AI-discovery framing spread in community venues.

Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .

  1. source content difference between and Current source content +10 -12

    The thread gained a new comment blaming speculators and defending open-source code, while an earlier open-versus-closed-source comment was replaced and the live comment count expanded.

    seen · Captured here 155,340 chars
    What changed from the previous capture 22 lines
     edited: 1785671653
     body:
     ... that is exactly how it works
    -
    -comment: p18gaim
    -parent: t1_p18e31w
    -author: Aggravating_Stage996
    -created_utc: 1785668951
    -edited: false
    -body:
    -If the code is open source anyone can run any AI models over it countless of times if they wish. If people are actually using some software they will have a vested interest in doing this.
    -
    -If the code is closed source the dev team may run whatever AI's over their own code substantially less times than above.  
    -  
    -Of course this argument is also assuming AI is the be all end all of penetration tests which it is not.
     
     comment: p18gc0p
     parent: t1_p18b7vt
     body:
     Could someone run Claude prompts to review Trezor and Ledger codebases and share the results?
     
    +comment: p2j46mn
    +parent: t3_1vddeuy
    +author: KindBench2700
    +created_utc: 1786223348
    +edited: false
    +body:
    +Lol code was open source.  Users should have read it.  Take some personal responsibility.  Speculators got speculated.
    +
     more-stub: parent t1_p19a2fb count <live-count>
     
     more-stub: parent t1_p1922vv count <live-count>
     
     more-stub: parent t1_p18c95s count <live-count>
     
    +more-stub: parent t1_p18e31w count <live-count>
    +
     more-stub: parent t1_p188hon count <live-count>
     
     more-stub: parent t1_p185uzk count <live-count>
    
    Extracted text as captured
    post: 1vddeuy
    author: Impressive-Gene-421
    created_utc: 1785662370
    title: Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes
    body:
    It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code.
    
    [Also on GLM 5.2 (trained 16th June, no internet access).](https://www.reddit.com/r/Bitcoin/s/5x8CBk8Csk)
    
    comment: p1848pg
    parent: t3_1vddeuy
    author: TeaSipper007
    created_utc: 1785663020
    edited: false
    body:
    Can you do the same for Seedsigner?
    
    comment: p184hcb
    parent: t3_1vddeuy
    author: Dry_Mortgage_4646
    created_utc: 1785663142
    edited: false
    body:
    😢
    
    comment: p184nnw
    parent: t3_1vddeuy
    author: Powerful_Quarter691
    created_utc: 1785663232
    edited: false
    body:
    This was def preplanned and in the works for quite some time, since attackers knew that draining the wallets will alert everyone and once they start they will be in the race against time. But I agree with the part that someone with little to none knowledge could have also performed this attack, probably even attempted once the news was out. 
    
    comment: p184yqj
    parent: t3_1vddeuy
    author: fanfanye
    created_utc: 1785663393
    edited: false
    body:
    "thinking", 

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  2. source content difference between and source content +9 -9

    The thread gained a new comment asking someone to run Claude prompts against Trezor and Ledger codebases and share the results, and the visible more-stub parent pointer shifted from p18crfw to p18c95s.

    seen · Captured here 155,609 chars
    What changed from the previous capture 18 lines
     We spent an entire section in probability and stats of how difficult it is to produce true randomness. 
     
     You can’t get through a reputable CS degree without having at least a good grasp on how difficult it is to achieve true randomness with a computer 
    -
    -comment: p18crfw
    -parent: t1_p18c95s
    -author: Aggravating_Stage996
    -created_utc: 1785667320
    -edited: false
    -body:
    -I can't tell if you're dumb or trolling
     
     comment: p18cs64
     parent: t1_p18agg4
     body:
     From my reading on this whole incident is that the team was well aware of the vulnerability, as the "bug" was there for testing purposes and was basically just left there, with no code check, even a cursory glance with AI prior to release. But like I said, just what I've read, so don't take it as the gospel until we get hard proof (if that day comes).
     
    +comment: p2gdegb
    +parent: t3_1vddeuy
    +author: aaj094
    +created_utc: 1786194287
    +edited: false
    +body:
    +Could someone run Claude prompts to review Trezor and Ledger codebases and share the results?
    +
     more-stub: parent t1_p19a2fb count <live-count>
     
     more-stub: parent t1_p1922vv count <live-count>
     
     more-stub: parent t1_p18l6la count <live-count>
     
    -more-stub: parent t1_p18crfw count <live-count>
    +more-stub: parent t1_p18c95s count <live-count>
     
     more-stub: parent t1_p188hon count <live-count>
     
    
    Extracted text as captured
    post: 1vddeuy
    author: Impressive-Gene-421
    created_utc: 1785662370
    title: Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes
    body:
    It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code.
    
    [Also on GLM 5.2 (trained 16th June, no internet access).](https://www.reddit.com/r/Bitcoin/s/5x8CBk8Csk)
    
    comment: p1848pg
    parent: t3_1vddeuy
    author: TeaSipper007
    created_utc: 1785663020
    edited: false
    body:
    Can you do the same for Seedsigner?
    
    comment: p184hcb
    parent: t3_1vddeuy
    author: Dry_Mortgage_4646
    created_utc: 1785663142
    edited: false
    body:
    😢
    
    comment: p184nnw
    parent: t3_1vddeuy
    author: Powerful_Quarter691
    created_utc: 1785663232
    edited: false
    body:
    This was def preplanned and in the works for quite some time, since attackers knew that draining the wallets will alert everyone and once they start they will be in the race against time. But I agree with the part that someone with little to none knowledge could have also performed this attack, probably even attempted once the news was out. 
    
    comment: p184yqj
    parent: t3_1vddeuy
    author: fanfanye
    created_utc: 1785663393
    edited: false
    body:
    "thinking", 

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  3. source content difference between and source content +69 -59

    A large reshuffle: roughly ten previously collapsed comments are now expanded (a subthread on whether dev teams should pay for AI code review) and several low-quality comments (insults, "prove it", court-payout speculation) disappeared.

    seen · Captured here 155,569 chars
    What changed from the previous capture 128 lines
     body:
     Funny thing is with this IC they even give you premade functions packaged with a pretty nooby GUI to configure the hardware. It's awful but it's enough to demonstrate the isolated capabilities of the chip. It seems even just copying that tool generated code and gluing it to theirs was too much hard work for them!
     
    +comment: p18a7ot
    +parent: t1_p188w2f
    +author: Level-Set5770
    +created_utc: 1785666071
    +edited: false
    +body:
    +The close source devs could easily do those security passes with AI themselves.
    +
     comment: p18aei5
     parent: t1_p185x67
     author: Rino-Sensei
     edited: false
     body:
     If OP didn't use the online search mode, there is no way for Claude to know the current situation.
    +
    +comment: p18aez1
    +parent: t1_p18a7ot
    +author: Cryptizard
    +created_utc: 1785666172
    +edited: false
    +body:
    +Sure so there is no security difference between open and closed source then, but open source is better for the community.  
     
     comment: p18agg4
     parent: t1_p185uzk
     
     Maybe you're just using LLMs as chat bots but they're more advanced than that now.
     
    +comment: p18bbec
    +parent: t1_p18a7ot
    +author: Aggravating_Stage996
    +created_utc: 1785666618
    +edited: false
    +body:
    +So every dev team no matter how small should require access to multiple top tier AI models? You realize these aren't free right?
    +
     comment: p18bfts
     parent: t1_p185wl3
     author: aleqqqs
     body:
     No point arguing with the clueless mofos 😂
     
    +comment: p18c95s
    +parent: t1_p18bbec
    +author: Level-Set5770
    +created_utc: 1785667074
    +edited: false
    +body:
    +Yes, moving forward I do expect every dev team to have access to top tier models. If you aren't even willing to pay $25 fucking dollar for a codex sub, you should not be in this business.
    +
     comment: p18clb4
     parent: t1_p189cs8
     author: mlhender
     
     You can’t get through a reputable CS degree without having at least a good grasp on how difficult it is to achieve true randomness with a computer 
     
    +comment: p18crfw
    +parent: t1_p18c95s
    +author: Aggravating_Stage996
    +created_utc: 1785667320
    +edited: false
    +body:
    +I can't tell if you're dumb or trolling
    +
     comment: p18cs64
     parent: t1_p18agg4
     author: Level-Set5770
     edited: false
     body:
     Except it is not like everyone has a different model. Everyone is running the same set of models. 
    +
    +comment: p18e31w
    +parent: t1_p18bbec
    +author: dondondorito
    +created_utc: 1785667943
    +edited: false
    +body:
    +With $100 per month you have practically unlimited Claude usage of their best model. It‘s absolutely negligible, especially because it can be booked on a month-by-month basis.
     
     comment: p18e9ef
     parent: t1_p18clb4
     body:
     I don’t know what to say about that chief. I am working at a cybersecurity company developing very custom auth solutions, sandboxed infra and a lot of other kinds of security critical software, and we use both Claude and Codex to do preliminary security reviews to our changes before any human reviews and I lost count how many times the models raised legit and not obvious issues
     
    -comment: p18ew51
    -parent: t1_p184yqj
    -author: NoInterraction
    -created_utc: 1785668316
    -edited: false
    -body:
    -How do you explain the first time it (or another AI) found it? I hear it was an AI that found it
    -
     comment: p18fige
     parent: t1_p185i6q
     author: SpareEconomy1849
     Lmao you're being downvoted for being right. 
     
     Literally a commit that changes MICROPY_HW_ENABLE_RNG to 0. Modern agents reliably find vulnerabilities much more complex than this
    -
    -comment: p18g7bl
    -parent: t1_p184yqj
    -author: Next-Inevitable-Fag
    -created_utc: 1785668910
    -edited: false
    -body:
    -prove it
     
     comment: p18g8zi
     parent: t1_p185i6q
     body:
     ... that is exactly how it works
     
    +comment: p18gaim
    +parent: t1_p18e31w
    +author: Aggravating_Stage996
    +created_utc: 1785668951
    +edited: false
    +body:
    +If the code is open source anyone can run any AI models over it countless of times if they wish. If people are actually using some software they will have a vested interest in doing this.
    +
    +If the code is closed source the dev team may run whatever AI's over their own code substantially less times than above.  
    +  
    +Of course this argument is also assuming AI is the be all end all of penetration tests which it is not.
    +
     comment: p18gc0p
     parent: t1_p18b7vt
     author: ImpressiveRelief37
     body:
     Absolutely. You can even clone a random GitHub repo, and then with no internet access let Claude review the code and chances are it’ll find bugs. 
     
    -comment: p18lsjs
    -parent: t3_1vddeuy
    -author: MyFrontTeethAreFake
    -created_utc: 1785671371
    -edited: false
    -body:
    -COLDCARD must have hundreds of millions of dollars in Bitcoin, eh?
    -
    -they better, because payouts are going to wild after court.
    -
     comment: p18lv4f
     parent: t1_p188qas
     author: nestaa13
     edited: false
     body:
     Exactly, patching overload right now!
    +
    +comment: p18o6x1
    +parent: t1_p18a7ot
    +author: snek-jazz
    +created_utc: 1785672345
    +edited: false
    +body:
    +And they can easily include any vulnerability they like, or are coerced to do, since it's closed source.
     
     comment: p18o9p0
     parent: t3_1vddeuy
     Not saying you’re entirely wrong, but you’d be shocked at the lack of internal controls at some of these large companies. And indeed I agree that is the real problem
     
     ETA: also vibe coding is not limited to small Indy games or apps. Plenty of engineers do exactly as I described above and don’t test edge cases properly and they get past weak testing pipelines
    -
    -comment: p194ma0
    -parent: t3_1vddeuy
    -author: ForsakenBet2647
    -created_utc: 1785678138
    -edited: false
    -body:
    -It makes me so hard bro
     
     comment: p194muo
     parent: t1_p18i6h2
     body:
     A FUKING LOT TRUST ME BRAH!  HIS ASS IS HUGE!
     
    -comment: p19e0xu
    -parent: t1_p18lsjs
    -author: insbordnat
    -created_utc: 1785681047
    -edited: false
    -body:
    -You realize the company is like a super small shop.  I'd be shocked if they had more than 20mm of insurance.
    -
     comment: p19ein6
     parent: t1_p18rp2b
     author: Mallmagician
     body:
     Y2K flashbacks
     
    -comment: p1akfuq
    -parent: t1_p19e0xu
    -author: MyFrontTeethAreFake
    -created_utc: 1785692793
    -edited: false
    -body:
    -so what happens now? they say "Sorry. we'll be better!" then everyone just moves on?
    -
     comment: p1aljse
     parent: t1_p1aa4m6
     author: Opposite-Friend7275
     body:
     security by obscurity isn't a strictly defined term - this is almost as objective of an example as you can get because there are very obviously different forms of obscurity. Relying on the fact that other people "probably" audited the code and just trusting $50k+ to that is absolutely a form of obscurity. Nobody with the time + knowledge actually audited the code, everybody trusted that they did, and everybody got bit.
     
    -comment: p1dghl4
    -parent: t1_p1akfuq
    -author: insbordnat
    -created_utc: 1785724626
    -edited: false
    -body:
    -Unfortunately, that's what typically happens.  Doubtful there are any other assets to go after.  
    -
     comment: p1dmdno
     parent: t1_p18svdv
     author: EDWARD_SN0WDEN
     
     more-stub: parent t1_p18l6la count <live-count>
     
    -more-stub: parent t1_p188w2f count <live-count>
    +more-stub: parent t1_p18crfw count <live-count>
     
     more-stub: parent t1_p188hon count <live-count>
     
    
    Extracted text as captured
    post: 1vddeuy
    author: Impressive-Gene-421
    created_utc: 1785662370
    title: Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes
    body:
    It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code.
    
    [Also on GLM 5.2 (trained 16th June, no internet access).](https://www.reddit.com/r/Bitcoin/s/5x8CBk8Csk)
    
    comment: p1848pg
    parent: t3_1vddeuy
    author: TeaSipper007
    created_utc: 1785663020
    edited: false
    body:
    Can you do the same for Seedsigner?
    
    comment: p184hcb
    parent: t3_1vddeuy
    author: Dry_Mortgage_4646
    created_utc: 1785663142
    edited: false
    body:
    😢
    
    comment: p184nnw
    parent: t3_1vddeuy
    author: Powerful_Quarter691
    created_utc: 1785663232
    edited: false
    body:
    This was def preplanned and in the works for quite some time, since attackers knew that draining the wallets will alert everyone and once they start they will be in the race against time. But I agree with the part that someone with little to none knowledge could have also performed this attack, probably even attempted once the news was out. 
    
    comment: p184yqj
    parent: t3_1vddeuy
    author: fanfanye
    created_utc: 1785663393
    edited: false
    body:
    "thinking", 

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  4. source content difference between and source content +18 -28

    Two duplicated RollingMeteors comments disappeared and two new comments were added: one asserting the developer did it on purpose, one recounting that the team was allegedly aware of the test-only bug.

    seen · Captured here 154,758 chars
    What changed from the previous capture 46 lines
     body:
     [deleted]
     
    -comment: p1aqpgq
    -parent: t1_p18ekrz
    -author: RollingMeteors
    -created_utc: 1785694462
    -edited: false
    -body:
    -> how fucking stupid ColdCard is and how they clearly did not test their RNG device sufficiently
    -
    -
    -
    -
    -
    -<priceIsRightSadTrombone.wav>
    -
    -comment: p1aqsh5
    -parent: t1_p18ekrz
    -author: RollingMeteors
    -created_utc: 1785694485
    -edited: false
    -body:
    -> how fucking stupid ColdCard is and how they clearly did not test their RNG device sufficiently
    -
    -
    -
    -
    -
    -<priceIsRightSadTrombone.wav>
    -
     comment: p1aqvkv
     parent: t3_1vddeuy
     author: YLCZ
     body:
     It’s crazy that this is wasn’t caught sooner
     
    +comment: p23xay4
    +parent: t1_p19xhzr
    +author: zinornia
    +created_utc: 1786040023
    +edited: false
    +body:
    +he did it on purpose 
    +
    +comment: p265lbf
    +parent: t1_p18e9m0
    +author: Coleyx123
    +created_utc: 1786062428
    +edited: false
    +body:
    +From my reading on this whole incident is that the team was well aware of the vulnerability, as the "bug" was there for testing purposes and was basically just left there, with no code check, even a cursory glance with AI prior to release. But like I said, just what I've read, so don't take it as the gospel until we get hard proof (if that day comes).
    +
     more-stub: parent t1_p19a2fb count <live-count>
     
     more-stub: parent t1_p1922vv count <live-count>
     
     more-stub: parent t1_p18n109 count <live-count>
     
    +more-stub: parent t1_p18ekrz count <live-count>
    +
     more-stub: parent t1_p1ufsx6 count <live-count>
     
     more-stub: parent t1_p19jcia count <live-count>
    
    Extracted text as captured
    post: 1vddeuy
    author: Impressive-Gene-421
    created_utc: 1785662370
    title: Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes
    body:
    It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code.
    
    [Also on GLM 5.2 (trained 16th June, no internet access).](https://www.reddit.com/r/Bitcoin/s/5x8CBk8Csk)
    
    comment: p1848pg
    parent: t3_1vddeuy
    author: TeaSipper007
    created_utc: 1785663020
    edited: false
    body:
    Can you do the same for Seedsigner?
    
    comment: p184hcb
    parent: t3_1vddeuy
    author: Dry_Mortgage_4646
    created_utc: 1785663142
    edited: false
    body:
    😢
    
    comment: p184nnw
    parent: t3_1vddeuy
    author: Powerful_Quarter691
    created_utc: 1785663232
    edited: false
    body:
    This was def preplanned and in the works for quite some time, since attackers knew that draining the wallets will alert everyone and once they start they will be in the race against time. But I agree with the part that someone with little to none knowledge could have also performed this attack, probably even attempted once the news was out. 
    
    comment: p184yqj
    parent: t3_1vddeuy
    author: fanfanye
    created_utc: 1785663393
    edited: false
    body:
    "thinking", 

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  5. source content difference between and source content +9 -9

    A comment by THE_RETARD_AGITATOR ("honestly, good") was deleted, and one new comment by Valnaya says it is crazy this was not caught sooner.

    seen · Captured here 154,619 chars
    What changed from the previous capture 18 lines
     edited: false
     body:
     Rumor is that they set it to 0 to test it without using the hardware and forgot to re-enable the trng on the shipping firmware. 
    -
    -comment: p1937zz
    -parent: t1_p18i6h2
    -author: THE_RETARD_AGITATOR
    -created_utc: 1785677686
    -edited: false
    -body:
    -honestly, good. how can we keep apologizing past all of these critical flaws 
     
     comment: p193c1q
     parent: t1_p18wm9r
     Estoy seguro al 100% que hay codigo metido en la mayoría de software actual de "día 0" que permiten estas cosas. Aunque la mayoría de la gente piense que una seed generada por el mismo sea mas insegura, os digo yo que eliminarias ese factor. De hecho creo que los que generaron su propia entropía no están afectados. 
     Con esto quiero aclarar que yo tengo una cantidad insignificante de criptos, yo prefiero tener el respaldo del banco que me asegura 100k por cuenta bancaria. Además debido a las grandes fluctuaciones que tiene me parece un producto de altisimo riesgo, soy de un perfil conservador. Para luchar contra la inflaccion lo mejor es invertir en propiedades, alquiler, airbnb. Igual no haces un x100 o x1000 pero vives tranquilo, con la certeza de que tu propiedad no va a desaparecer como "humo"
     
    +comment: p226r1v
    +parent: t3_1vddeuy
    +author: Valnaya
    +created_utc: 1786024210
    +edited: false
    +body:
    +It’s crazy that this is wasn’t caught sooner
    +
     more-stub: parent t1_p19a2fb count <live-count>
     
     more-stub: parent t1_p1922vv count <live-count>
     
     more-stub: parent t1_p184yqj count <live-count>
     
    -more-stub: parent t1_p1937zz count <live-count>
    +more-stub: parent t1_p18i6h2 count <live-count>
     
     more-stub: parent t1_p18jy2w count <live-count>
     
    
    Extracted text as captured
    post: 1vddeuy
    author: Impressive-Gene-421
    created_utc: 1785662370
    title: Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes
    body:
    It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code.
    
    [Also on GLM 5.2 (trained 16th June, no internet access).](https://www.reddit.com/r/Bitcoin/s/5x8CBk8Csk)
    
    comment: p1848pg
    parent: t3_1vddeuy
    author: TeaSipper007
    created_utc: 1785663020
    edited: false
    body:
    Can you do the same for Seedsigner?
    
    comment: p184hcb
    parent: t3_1vddeuy
    author: Dry_Mortgage_4646
    created_utc: 1785663142
    edited: false
    body:
    😢
    
    comment: p184nnw
    parent: t3_1vddeuy
    author: Powerful_Quarter691
    created_utc: 1785663232
    edited: false
    body:
    This was def preplanned and in the works for quite some time, since attackers knew that draining the wallets will alert everyone and once they start they will be in the race against time. But I agree with the part that someone with little to none knowledge could have also performed this attack, probably even attempted once the news was out. 
    
    comment: p184yqj
    parent: t3_1vddeuy
    author: fanfanye
    created_utc: 1785663393
    edited: false
    body:
    "thinking", 

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  6. source content difference between and source content +12 -18

    Two earlier comments disappeared (a "wtf are you talking about?" reply and a comment claiming GPG signatures prove switck is doc-hex), and one new Spanish-language comment argues self-generated entropy avoids the bug.

    seen · Captured here 154,664 chars
    What changed from the previous capture 30 lines
     
     CC was well and truly screwed once this firmware shipped on devices.
     
    -comment: p1a7tod
    -parent: t1_p1937zz
    -author: jannies_doit_4_free
    -created_utc: 1785689413
    -edited: false
    -body:
    -wtf are you talking about?
    -
     comment: p1a82q0
     parent: t1_p18j0mj
     author: jannies_doit_4_free
     body:
     The guy stealing the btc himself and the guy accidentally allowing an exploit are two different things
     
    -comment: p1v54ic
    -parent: t1_p198qu8
    -author: Napoleanna
    -created_utc: 1785940869
    -edited: false
    -body:
    -it turns out that switck is doc-hex, [proven by GPG commit signatures](https://gist.github.com/jamesob/ca9b4ca384969b4cfd62813419854d69)
    -
    -
    -
     comment: p1vn1us
     parent: t1_p18dalk
     author: ScreenAppropriate679
     body:
     I trust you pay close attention to small details r/PmMeUrTinyAsianTits 
     
    +comment: p20y251
    +parent: t3_1vddeuy
    +author: SingerLate3349
    +created_utc: 1786008097
    +edited: false
    +body:
    +No sé si es por mi profesión "Pero soy muy desconfiado" el hecho de que un dispositivo me genere su propia seed con las palabras que el quiere no me acaba de convencer. Como dice aquel "Poderoso caballero es don dinero".
    +Estoy seguro al 100% que hay codigo metido en la mayoría de software actual de "día 0" que permiten estas cosas. Aunque la mayoría de la gente piense que una seed generada por el mismo sea mas insegura, os digo yo que eliminarias ese factor. De hecho creo que los que generaron su propia entropía no están afectados. 
    +Con esto quiero aclarar que yo tengo una cantidad insignificante de criptos, yo prefiero tener el respaldo del banco que me asegura 100k por cuenta bancaria. Además debido a las grandes fluctuaciones que tiene me parece un producto de altisimo riesgo, soy de un perfil conservador. Para luchar contra la inflaccion lo mejor es invertir en propiedades, alquiler, airbnb. Igual no haces un x100 o x1000 pero vives tranquilo, con la certeza de que tu propiedad no va a desaparecer como "humo"
    +
     more-stub: parent t1_p19a2fb count <live-count>
     
     more-stub: parent t1_p1922vv count <live-count>
     
     more-stub: parent t1_p184yqj count <live-count>
     
    +more-stub: parent t1_p1937zz count <live-count>
    +
     more-stub: parent t1_p18jy2w count <live-count>
     
     more-stub: parent t1_p18l6la count <live-count>
    
    Extracted text as captured
    post: 1vddeuy
    author: Impressive-Gene-421
    created_utc: 1785662370
    title: Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes
    body:
    It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code.
    
    [Also on GLM 5.2 (trained 16th June, no internet access).](https://www.reddit.com/r/Bitcoin/s/5x8CBk8Csk)
    
    comment: p1848pg
    parent: t3_1vddeuy
    author: TeaSipper007
    created_utc: 1785663020
    edited: false
    body:
    Can you do the same for Seedsigner?
    
    comment: p184hcb
    parent: t3_1vddeuy
    author: Dry_Mortgage_4646
    created_utc: 1785663142
    edited: false
    body:
    😢
    
    comment: p184nnw
    parent: t3_1vddeuy
    author: Powerful_Quarter691
    created_utc: 1785663232
    edited: false
    body:
    This was def preplanned and in the works for quite some time, since attackers knew that draining the wallets will alert everyone and once they start they will be in the race against time. But I agree with the part that someone with little to none knowledge could have also performed this attack, probably even attempted once the news was out. 
    
    comment: p184yqj
    parent: t3_1vddeuy
    author: fanfanye
    created_utc: 1785663393
    edited: false
    body:
    "thinking", 

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  7. source content difference between and source content +14 -24

    Reddit now marks the original author and one comment as deleted or removed, removes linked examples from that comment, and adds a later reply.

    seen · Captured here 153,868 chars
    What changed from the previous capture 38 lines
     
     comment: p19gy7p
     parent: t1_p18rp2b
    -author: FastRelief3222
    +author: [deleted]
     created_utc: 1785681912
     edited: false
     body:
    -[https://www.reddit.com/r/coldcard/comments/17fy8cz/17\_btc\_drained\_instantly\_using\_sparrow\_to\_cold/](https://www.reddit.com/r/coldcard/comments/17fy8cz/17_btc_drained_instantly_using_sparrow_to_cold/)
    -
    -[https://www.reddit.com/r/Electrum/comments/id7bpj/the\_loss\_of\_bitcoin/](https://www.reddit.com/r/Electrum/comments/id7bpj/the_loss_of_bitcoin/)
    -
    -[https://www.reddit.com/r/coldcard/comments/17epqk8/040\_bitcoin\_taken\_instantly\_from\_my\_coldcard/](https://www.reddit.com/r/coldcard/comments/17epqk8/040_bitcoin_taken_instantly_from_my_coldcard/)
    -
    -Just imagine if they knew 6 years ago
    +[deleted]
     
     comment: p19h7ev
     parent: t1_p18khog
     body:
     Its opensource anyone can verify!
     
    -comment: p1a9jwi
    -parent: t1_p18rp2b
    -author: Forsaken-Stink
    -created_utc: 1785689879
    -edited: false
    -body:
    -Stupid take but OK
    -
     comment: p1a9om4
     parent: t1_p19yqn7
     author: Aazimoxx
     edited: false
     body:
     Sauce?
    -
    -comment: p1ae4c2
    -parent: t1_p18l6la
    -author: Objective_Digit
    -created_utc: 1785691113
    -edited: false
    -body:
    -It wasn't open source.
     
     comment: p1aed92
     parent: t1_p18v2ky
     body:
     increasing smelling like an inside job
     
    +comment: p1zgnr8
    +parent: t1_p1d4sah
    +author: No-Good-One-Shoe
    +created_utc: 1785984353
    +edited: false
    +body:
    +I trust you pay close attention to small details r/PmMeUrTinyAsianTits 
    +
     more-stub: parent t1_p19a2fb count <live-count>
     
     more-stub: parent t1_p1922vv count <live-count>
     
     more-stub: parent t1_p19ein6 count <live-count>
     
    +more-stub: parent t1_p18rp2b count <live-count>
    +
     more-stub: parent t1_p194b74 count <live-count>
     
     more-stub: parent t1_p185wl3 count <live-count>
     
     more-stub: parent t1_p18jy2w count <live-count>
     
    +more-stub: parent t1_p18l6la count <live-count>
    +
     more-stub: parent t1_p188w2f count <live-count>
     
     more-stub: parent t1_p188hon count <live-count>
    
    Extracted text as captured
    post: 1vddeuy
    author: Impressive-Gene-421
    created_utc: 1785662370
    title: Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes
    body:
    It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code.
    
    [Also on GLM 5.2 (trained 16th June, no internet access).](https://www.reddit.com/r/Bitcoin/s/5x8CBk8Csk)
    
    comment: p1848pg
    parent: t3_1vddeuy
    author: TeaSipper007
    created_utc: 1785663020
    edited: false
    body:
    Can you do the same for Seedsigner?
    
    comment: p184hcb
    parent: t3_1vddeuy
    author: Dry_Mortgage_4646
    created_utc: 1785663142
    edited: false
    body:
    😢
    
    comment: p184nnw
    parent: t3_1vddeuy
    author: Powerful_Quarter691
    created_utc: 1785663232
    edited: false
    body:
    This was def preplanned and in the works for quite some time, since attackers knew that draining the wallets will alert everyone and once they start they will be in the race against time. But I agree with the part that someone with little to none knowledge could have also performed this attack, probably even attempted once the news was out. 
    
    comment: p184yqj
    parent: t3_1vddeuy
    author: fanfanye
    created_utc: 1785663393
    edited: false
    body:
    "thinking", 

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  8. source content difference between and source content +52 -32

    Reddit served five additional comments about the audit framing, source availability and inside-job speculation, while four previously held comments were omitted from this response.

    seen · Captured here 154,460 chars
    What changed from the previous capture 84 lines
     edited: false
     body:
     Mythos found a bug used throughout the internet that had existed since 1998 and no security research team or individual ever spotted it. It was so significant that they had to stop the release, give it to 50 of the biggest American companies to patch their systems and then re-released it later. 
    -
    -comment: p18qkhi
    -parent: t1_p1877qg
    -author: Chucklum
    -created_utc: 1785673267
    -edited: false
    -body:
    -So many other comments pointed out why. If you had tried this 1 month ago you wouldn't have gotten the same results.
     
     comment: p18r5nc
     parent: t1_p18iyzy
     
     Check how much power you need to derive such seephrase .
     
    -comment: p19cu1k
    -parent: t1_p18n109
    -author: Unable_Review3665
    -created_utc: 1785680692
    -edited: false
    -body:
    -Ai works on both sides so seems the attackers are more active than security employees. Id even say attackers have fewer resources… so pure lazyness
    -
     comment: p19cvp4
     parent: t1_p19bc1a
     author: habbadee
     body:
     You're exactly right, and honestly it all exists in such a legal grey area I wouldn't be surprised if CC and their personnel just fade into non existence and face 0 real consequences for their actions. That's the unfortunate reality of BTC and recovering funds can sometimes be an impossible feat. I truly feel for all the people who have lost funds due to the complete negligence that CC has exhibited. 
     
    -comment: p19kbuj
    -parent: t1_p19ein6
    -author: ElMasAltoDeLosEnanos
    -created_utc: 1785682891
    -edited: false
    -body:
    -That makes too much sense.
    -
     comment: p19kean
     parent: t1_p18zn1x
     author: Th4ab
     body:
     The guy stealing the btc himself and the guy accidentally allowing an exploit are two different things
     
    -comment: p1ul5oi
    -parent: t1_p1ufsx6
    -author: slvbtc
    -created_utc: 1785935392
    -edited: false
    -body:
    -What if they are not. Havent you seen the posts showcasing why the CTO of coinkite may have planted the bug on purpose in order to steal user funds himself.
    +comment: p1v54ic
    +parent: t1_p198qu8
    +author: Napoleanna
    +created_utc: 1785940869
    +edited: false
    +body:
    +it turns out that switck is doc-hex, [proven by GPG commit signatures](https://gist.github.com/jamesob/ca9b4ca384969b4cfd62813419854d69)
    +
    +
    +
    +comment: p1vn1us
    +parent: t1_p18dalk
    +author: ScreenAppropriate679
    +created_utc: 1785945417
    +edited: false
    +body:
    +Fable would have been prevented by safeguards to audit the codebase
    +
    +comment: p1w11om
    +parent: t1_p1vn1us
    +author: dondondorito
    +created_utc: 1785948875
    +edited: false
    +body:
    +Why? The codebase was out there for everyone to read. Fable would have read it just fine when prompted to.
    +
    +comment: p1w3j2y
    +parent: t1_p1w11om
    +author: ScreenAppropriate679
    +created_utc: 1785949482
    +edited: false
    +body:
    +Because Anthropic doesn't want Fable to be used by everyone to identify vulnerabilities in open source software. 
    +
    +Fable doesn't even allow me to audit my own softwares in depth.
    +
    +comment: p1x9o6p
    +parent: t3_1vddeuy
    +author: TechnologyGrouchy679
    +created_utc: 1785960065
    +edited: false
    +body:
    +increasing smelling like an inside job
     
     more-stub: parent t1_p19a2fb count <live-count>
     
     more-stub: parent t1_p1922vv count <live-count>
     
    -more-stub: parent t1_p1ul5oi count <live-count>
    +more-stub: parent t1_p18n109 count <live-count>
    +
    +more-stub: parent t1_p1ufsx6 count <live-count>
     
     more-stub: parent t1_p19jcia count <live-count>
     
    +more-stub: parent t1_p19ein6 count <live-count>
    +
    +more-stub: parent t1_p194b74 count <live-count>
    +
     more-stub: parent t1_p185wl3 count <live-count>
     
     more-stub: parent t1_p18d317 count <live-count>
     
     more-stub: parent t1_p188nay count <live-count>
     
    +more-stub: parent t1_p1877qg count <live-count>
    +
     more-stub: parent t3_1vddeuy count <live-count>
    
    Extracted text as captured
    post: 1vddeuy
    author: Impressive-Gene-421
    created_utc: 1785662370
    title: Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes
    body:
    It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code.
    
    [Also on GLM 5.2 (trained 16th June, no internet access).](https://www.reddit.com/r/Bitcoin/s/5x8CBk8Csk)
    
    comment: p1848pg
    parent: t3_1vddeuy
    author: TeaSipper007
    created_utc: 1785663020
    edited: false
    body:
    Can you do the same for Seedsigner?
    
    comment: p184hcb
    parent: t3_1vddeuy
    author: Dry_Mortgage_4646
    created_utc: 1785663142
    edited: false
    body:
    😢
    
    comment: p184nnw
    parent: t3_1vddeuy
    author: Powerful_Quarter691
    created_utc: 1785663232
    edited: false
    body:
    This was def preplanned and in the works for quite some time, since attackers knew that draining the wallets will alert everyone and once they start they will be in the race against time. But I agree with the part that someone with little to none knowledge could have also performed this attack, probably even attempted once the news was out. 
    
    comment: p184yqj
    parent: t3_1vddeuy
    author: fanfanye
    created_utc: 1785663393
    edited: false
    body:
    "thinking", 

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  9. source content difference between and source content +47 -45

    Reddit served new comments discussing the distinction between an exploit and deliberate theft, including speculation about a vendor employee, while several earlier comments were omitted from the captured thread surface.

    seen · Captured here 154,104 chars
    What changed from the previous capture 92 lines
     body:
     which is hilarious since crypto is mostly tech heads…
     
    -comment: p18kd9p
    -parent: t1_p185i6q
    -author: Wizzard_2025
    -created_utc: 1785670765
    -edited: false
    -body:
    -Yes, that's how they work. 
    -
     comment: p18kf7v
     parent: t1_p18frua
     author: mastermilian
     edited: false
     body:
     I work in IT and vulnerability remediation is part of my role. The last three months have seen record amounts of CVEs month after month. AI is giving so many threat actors tools to quickly identify vulnerabilities. We’re getting hammered 
    -
    -comment: p18n25j
    -parent: t1_p18kvn1
    -author: harvested
    -created_utc: 1785671889
    -edited: false
    -body:
    -Advanced models have only been out a couple of months. Timing is obvious, no?
    -
    -Doesn't change the fact the OP comment with 200 votes doesn't understand how AI works and thinks they're just search engines.
     
     comment: p18n8vb
     parent: t1_p18jzsa
     body:
     Yes, that person verified, then took all the coins for themselves and got the reward....
     
    -comment: p1bknub
    -parent: t1_p19jcia
    -author: Tomsonx232
    -created_utc: 1785702764
    -edited: false
    -body:
    -You could have them send a transaction with a specific message on chain from that address
    -
     comment: p1bnjee
     parent: t1_p1anhge
     author: PleaseDoTapTheGlass
     body:
     Doing nothing just means an attacker has time to prepare a plan before acting on it
     
    -comment: p1bufad
    -parent: t1_p1bknub
    -author: Rannasha
    -created_utc: 1785705577
    -edited: false
    -body:
    -But the attacker would also control that address, which is exactly the problem.
    -
     comment: p1bvq4x
     parent: t1_p1ahgub
     author: Bascilian
     body:
     Oh wow that was quite the read. Thanks for sharing. Shit could get dark. 
     
    -comment: p1hoi4s
    -parent: t1_p1bufad
    -author: Tomsonx232
    -created_utc: 1785779511
    -edited: false
    -body:
    -Yes but only the user would be given the message to send from Cold Card.... I.e. whatever email/shipping address you gave Cold Card during purchase they would email (or based on user preference, mail) you a specialized code. So sending that code on the blockchain confirms you control the original email address and the wallet.
    -
    -Part 1 of the message would be the unique code Cold Card would give you and part 2 of the message would be the public address of the new and wallet or CEX deposit address
    -
     comment: p1j13k9
     parent: t3_1vddeuy
     author: flooberdoodler
     body:
     Next time I hear people talk shit about vibe coders and security vulnerabilities I’m going to point to this. Thanks!
     
    +comment: p1tzfe3
    +parent: t1_p1bcmqz
    +author: Jogol
    +created_utc: 1785928051
    +edited: false
    +body:
    +Someone did :) 
    +
    +comment: p1uchyj
    +parent: t1_p1ap3h0
    +author: MatixMint
    +created_utc: 1785932737
    +edited: false
    +body:
    +Still no. It makes me realize a lot of yall dont understand how this works. 
    +
    +comment: p1uegt8
    +parent: t1_p1uchyj
    +author: slvbtc
    +created_utc: 1785933363
    +edited: false
    +body:
    +What if theres strong evidence the safe maker also used this 1 digit pin code flaw to steal the contents of the safe.
    +
    +comment: p1ufsx6
    +parent: t1_p1uegt8
    +author: MatixMint
    +created_utc: 1785933778
    +edited: false
    +body:
    +The guy stealing the btc himself and the guy accidentally allowing an exploit are two different things
    +
    +comment: p1ul5oi
    +parent: t1_p1ufsx6
    +author: slvbtc
    +created_utc: 1785935392
    +edited: false
    +body:
    +What if they are not. Havent you seen the posts showcasing why the CTO of coinkite may have planted the bug on purpose in order to steal user funds himself.
    +
     more-stub: parent t1_p19a2fb count <live-count>
     
     more-stub: parent t1_p1922vv count <live-count>
     
    +more-stub: parent t1_p1ul5oi count <live-count>
    +
    +more-stub: parent t1_p19jcia count <live-count>
    +
     more-stub: parent t1_p185wl3 count <live-count>
     
     more-stub: parent t1_p18d317 count <live-count>
     
    -more-stub: parent t1_p18n25j count <live-count>
    +more-stub: parent t1_p18kvn1 count <live-count>
    +
    +more-stub: parent t1_p185i6q count <live-count>
     
     more-stub: parent t1_p193er6 count <live-count>
     
    
    Extracted text as captured
    post: 1vddeuy
    author: Impressive-Gene-421
    created_utc: 1785662370
    title: Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes
    body:
    It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code.
    
    [Also on GLM 5.2 (trained 16th June, no internet access).](https://www.reddit.com/r/Bitcoin/s/5x8CBk8Csk)
    
    comment: p1848pg
    parent: t3_1vddeuy
    author: TeaSipper007
    created_utc: 1785663020
    edited: false
    body:
    Can you do the same for Seedsigner?
    
    comment: p184hcb
    parent: t3_1vddeuy
    author: Dry_Mortgage_4646
    created_utc: 1785663142
    edited: false
    body:
    😢
    
    comment: p184nnw
    parent: t3_1vddeuy
    author: Powerful_Quarter691
    created_utc: 1785663232
    edited: false
    body:
    This was def preplanned and in the works for quite some time, since attackers knew that draining the wallets will alert everyone and once they start they will be in the race against time. But I agree with the part that someone with little to none knowledge could have also performed this attack, probably even attempted once the news was out. 
    
    comment: p184yqj
    parent: t3_1vddeuy
    author: fanfanye
    created_utc: 1785663393
    edited: false
    body:
    "thinking", 

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  10. source content difference between and source content +19 -19

    Two earlier discussion comments disappeared, including a sceptical reply about the AI framing, and the thread gained two new replies advocating physical entropy and praising the vulnerability-audit example.

    seen · Captured here 154,436 chars
    What changed from the previous capture 38 lines
     body:
     Dude don't even stress on it. Anyone with half a brain and a basic understanding of programming realizes you're 100% correct in this post. The people disagreeing are just technologically illiterate which is insane considering they're on a Bitcoin subreddit lmao
     
    -comment: p18b62v
    -parent: t1_p188nay
    -author: LeftMorning6141
    -created_utc: 1785666544
    -edited: false
    -body:
    -lmao????
    -
     comment: p18b7vt
     parent: t1_p188nay
     author: LeftMorning6141
     edited: false
     body:
     you don't need Fable. Any LLM with coding abilities can find this. "Security by obscurity" is gone for good.
    -
    -comment: p18p9gu
    -parent: t1_p18n25j
    -author: retro_grave
    -created_utc: 1785672766
    -edited: 1785673130
    -body:
    -It's not obvious to me as a software engineer/IT specialist. There are major data breaches and CVEs published weekly, long before AI were added to the process. Yes, AI is increasing the pace, but this could have been identified 6 months ago by the attacker and them quietly scanned/indexed wallets they could drain until they were confident to pull the trigger. Most vulnerabilities are in the wild for years before identified, so the timing isn't really suspect IMO. I would be curious about anything the attacker could say, but I doubt they want to be known which is why I asked. Once they trigger the drains they would want to move quickly to unload the BTC as well, and would likely want some plan in place. Curious about that as well.
    -
    -I would also say, the exploits I've seen reported are fairly trivial and similar PRNG "attacks" have a long history in crypto. Coldcard reaping their day doesn't make the attack any more likely to be AI. Maybe it is, but I just haven't seen evidence of it.
     
     comment: p18plhp
     parent: t1_p18d317
     body:
     The remedy would be a civil suit for damages 
     
    +comment: p1rs1nx
    +parent: t1_p1n9jvx
    +author: shedgehog-orchard
    +created_utc: 1785894333
    +edited: false
    +body:
    +Yes 100% you should use either physical entropy entirely with a corresponding table (lots of options or can come up with your own) or some combination of software and hardware entropy but the core randomness generation shouldn’t be in software
    +
    +comment: p1rv3wn
    +parent: t3_1vddeuy
    +author: Braddles14
    +created_utc: 1785895338
    +edited: false
    +body:
    +Next time I hear people talk shit about vibe coders and security vulnerabilities I’m going to point to this. Thanks!
    +
     more-stub: parent t1_p19a2fb count <live-count>
     
     more-stub: parent t1_p1922vv count <live-count>
     
     more-stub: parent t1_p18d317 count <live-count>
     
    -more-stub: parent t1_p18p9gu count <live-count>
    +more-stub: parent t1_p18n25j count <live-count>
     
     more-stub: parent t1_p193er6 count <live-count>
     
     
     more-stub: parent t1_p187kfo count <live-count>
     
    +more-stub: parent t1_p188nay count <live-count>
    +
     more-stub: parent t3_1vddeuy count <live-count>
    
    Extracted text as captured
    post: 1vddeuy
    author: Impressive-Gene-421
    created_utc: 1785662370
    title: Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes
    body:
    It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code.
    
    [Also on GLM 5.2 (trained 16th June, no internet access).](https://www.reddit.com/r/Bitcoin/s/5x8CBk8Csk)
    
    comment: p1848pg
    parent: t3_1vddeuy
    author: TeaSipper007
    created_utc: 1785663020
    edited: false
    body:
    Can you do the same for Seedsigner?
    
    comment: p184hcb
    parent: t3_1vddeuy
    author: Dry_Mortgage_4646
    created_utc: 1785663142
    edited: false
    body:
    😢
    
    comment: p184nnw
    parent: t3_1vddeuy
    author: Powerful_Quarter691
    created_utc: 1785663232
    edited: false
    body:
    This was def preplanned and in the works for quite some time, since attackers knew that draining the wallets will alert everyone and once they start they will be in the race against time. But I agree with the part that someone with little to none knowledge could have also performed this attack, probably even attempted once the news was out. 
    
    comment: p184yqj
    parent: t3_1vddeuy
    author: fanfanye
    created_utc: 1785663393
    edited: false
    body:
    "thinking", 

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  11. source content difference between and source content +2 -10

    An existing Reddit comment no longer appeared in the captured thread.

    seen · Captured here 155,048 chars
    What changed from the previous capture 12 lines
     
     comment: p1ap6cu
     parent: t1_p18ho21
    -author: b1mm3rl1f3
    +author: [deleted]
     created_utc: 1785694050
     edited: false
     body:
    -Also, can someone explain why the bluetooth on the Trezor safe 7 isn't considered a vulnerability?
    +[deleted]
     
     comment: p1aqpgq
     parent: t1_p18ekrz
     body:
     Then don’t use a styrofoam safe genius.  
     
    -comment: p1d8gvr
    -parent: t1_p1cqp7r
    -author: b1mm3rl1f3
    -created_utc: 1785721750
    -edited: false
    -body:
    -I ordered the 7 yesterday, cancelled it, and ordered the 5 today. It isn't fully air gapped and I don't want the option there at all. I'm surprised Trezor went with that 
    -
     comment: p1daxn2
     parent: t1_p1brx6e
     author: IInsulince
    
    Extracted text as captured
    post: 1vddeuy
    author: Impressive-Gene-421
    created_utc: 1785662370
    title: Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes
    body:
    It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code.
    
    [Also on GLM 5.2 (trained 16th June, no internet access).](https://www.reddit.com/r/Bitcoin/s/5x8CBk8Csk)
    
    comment: p1848pg
    parent: t3_1vddeuy
    author: TeaSipper007
    created_utc: 1785663020
    edited: false
    body:
    Can you do the same for Seedsigner?
    
    comment: p184hcb
    parent: t3_1vddeuy
    author: Dry_Mortgage_4646
    created_utc: 1785663142
    edited: false
    body:
    😢
    
    comment: p184nnw
    parent: t3_1vddeuy
    author: Powerful_Quarter691
    created_utc: 1785663232
    edited: false
    body:
    This was def preplanned and in the works for quite some time, since attackers knew that draining the wallets will alert everyone and once they start they will be in the race against time. But I agree with the part that someone with little to none knowledge could have also performed this attack, probably even attempted once the news was out. 
    
    comment: p184yqj
    parent: t3_1vddeuy
    author: fanfanye
    created_utc: 1785663393
    edited: false
    body:
    "thinking", 

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  12. source content difference between and source content +1 -17

    The captured reply tree gained a collapsed more-stub indicating two additional replies under an existing comment.

    seen · Captured here 155,409 chars
    What changed from the previous capture 18 lines
     edited: false
     body:
     It’s almost certain that the developer was confident in python but forced to use C.
    -
    -comment: p18pzuj
    -parent: t1_p18p9gu
    -author: harvested
    -created_utc: 1785673048
    -edited: false
    -body:
    -Okay, general consensus is around AI, in particular Kimi K3.
    -
    -https://x.com/w_s_bitcoin/status/2083539953892364400
    -
    -This went unnoticed for 5 years then was found when the models advanced.
    -
    -But yeah you are welcome to disagree.
    -
    -I believe they have a lead on the original sweep attacker.
     
     comment: p18q1ij
     parent: t1_p18b4dc
     
     more-stub: parent t1_p18d317 count 4
     
    -more-stub: parent t1_p18pzuj count 1
    +more-stub: parent t1_p18p9gu count 2
     
     more-stub: parent t1_p193er6 count 0
     
    
    Extracted text as captured
    post: 1vddeuy
    author: Impressive-Gene-421
    created_utc: 1785662370
    title: Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes
    body:
    It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code.
    
    [Also on GLM 5.2 (trained 16th June, no internet access).](https://www.reddit.com/r/Bitcoin/s/5x8CBk8Csk)
    
    comment: p1848pg
    parent: t3_1vddeuy
    author: TeaSipper007
    created_utc: 1785663020
    edited: false
    body:
    Can you do the same for Seedsigner?
    
    comment: p184hcb
    parent: t3_1vddeuy
    author: Dry_Mortgage_4646
    created_utc: 1785663142
    edited: false
    body:
    😢
    
    comment: p184nnw
    parent: t3_1vddeuy
    author: Powerful_Quarter691
    created_utc: 1785663232
    edited: false
    body:
    This was def preplanned and in the works for quite some time, since attackers knew that draining the wallets will alert everyone and once they start they will be in the race against time. But I agree with the part that someone with little to none knowledge could have also performed this attack, probably even attempted once the news was out. 
    
    comment: p184yqj
    parent: t3_1vddeuy
    author: fanfanye
    created_utc: 1785663393
    edited: false
    body:
    "thinking", 

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  13. source content difference between and source content +4 -6

    An existing comment was deleted: its author and body now appear as “[deleted]”.

    seen · Captured here 155,796 chars
    What changed from the previous capture 10 lines
     
     comment: p18z27c
     parent: t1_p18e9m0
    -author: ContemptMarzipan
    +author: [deleted]
     created_utc: 1785676306
    -edited: false
    -body:
    -Peter D. Gray made the commit to the code - https://x.com/grok/status/2083899371330916755 
    -
    -https://www.linkedin.com/in/doc-hex-04063811/
    +edited: 1785852936
    +body:
    +[deleted]
     
     comment: p18zjr8
     parent: t1_p18l6la
    
    Extracted text as captured
    post: 1vddeuy
    author: Impressive-Gene-421
    created_utc: 1785662370
    title: Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes
    body:
    It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code.
    
    [Also on GLM 5.2 (trained 16th June, no internet access).](https://www.reddit.com/r/Bitcoin/s/5x8CBk8Csk)
    
    comment: p1848pg
    parent: t3_1vddeuy
    author: TeaSipper007
    created_utc: 1785663020
    edited: false
    body:
    Can you do the same for Seedsigner?
    
    comment: p184hcb
    parent: t3_1vddeuy
    author: Dry_Mortgage_4646
    created_utc: 1785663142
    edited: false
    body:
    😢
    
    comment: p184nnw
    parent: t3_1vddeuy
    author: Powerful_Quarter691
    created_utc: 1785663232
    edited: false
    body:
    This was def preplanned and in the works for quite some time, since attackers knew that draining the wallets will alert everyone and once they start they will be in the race against time. But I agree with the part that someone with little to none knowledge could have also performed this attack, probably even attempted once the news was out. 
    
    comment: p184yqj
    parent: t3_1vddeuy
    author: fanfanye
    created_utc: 1785663393
    edited: false
    body:
    "thinking", 

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  14. source content difference between and source content +10 -20

    1 new Reddit comment was posted, including Peking_Meerschaum.

    seen · Captured here 155,926 chars
    What changed from the previous capture 30 lines
     body:
     That's no different than a public announcement that there's a security flaw.  Which brings everyone, thieves included, to seeking out that flaw to exploit.  So now, not only did they introduce a fatal flaw, but they announced it's existence to the world as ready and available to be exploited.  Imagine their liability after wallets are compromised after the announcement.
     
    -comment: p19d1hm
    -parent: t1_p18pzuj
    -author: Aazimoxx
    -created_utc: 1785680754
    -edited: 1785681050
    -body:
    -[xcancel link](https://xcancel.com/w_s_bitcoin/status/2083539952395067509) for the non-twittards 👍
    -
    -And [Bitkey response](https://xcancel.com/clay_garrett/status/2083585966481068398) shortly after:
    -
    ->Sharing our initial findings on a reported vulnerability. Our recommendation is to continue to use your Bitkey normally.
    ->  
    ->The reported vulnerability would require exceptional circumstances to exploit, and can only occur at a specific narrow time during inheritance setup. Even if an attacker was able to exploit this vulnerability (including exploiting TLS internet security), they would not have enough cryptographic material to access funds. This is Bitkey’s defense-in-depth in action. 
    ->   
    ->Our assessment is this presents no risk of remote drains or immediate funds loss. We appreciate @1440000bytes who reported this issue to us directly. 
    ->  
    ->We will share a more thorough technical report imminently, and follow that with a hosted space on X where the team will talk through the details with the community and answer any questions. We'll submit a patch to the mobile app to both stores today.
    -
    -This isn't a comment on the existing conversation here btw.  The guy you're responding to makes one or two okay points but gets some of the fundamentals wrong.  There's nothing to suggest the attackers in this case waited 6-18mths versus just planning it out over say a week, and there's zero need to rush to launder the BTC once it's been first moved.
    -
     comment: p19dcnp
     parent: t1_p192rll
     author: 99999999999999999989
     body:
     So you mean, instead of using Trezor or Ledger's seed phrase generation, we should make our own? Like by rolling dice or something and picking words out of a corresponding book?
     
    +comment: p1ngeg4
    +parent: t1_p1ap3h0
    +author: Peking_Meerschaum
    +created_utc: 1785851668
    +edited: false
    +body:
    +The remedy would be a civil suit for damages 
    +
     more-stub: parent t1_p19a2fb count 2
     
     more-stub: parent t1_p1922vv count 1
     
     more-stub: parent t1_p18d317 count 4
     
    +more-stub: parent t1_p18pzuj count 1
    +
     more-stub: parent t1_p193er6 count 0
     
     more-stub: parent t1_p184yqj count 2
    
    Extracted text as captured
    post: 1vddeuy
    author: Impressive-Gene-421
    created_utc: 1785662370
    title: Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes
    body:
    It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code.
    
    [Also on GLM 5.2 (trained 16th June, no internet access).](https://www.reddit.com/r/Bitcoin/s/5x8CBk8Csk)
    
    comment: p1848pg
    parent: t3_1vddeuy
    author: TeaSipper007
    created_utc: 1785663020
    edited: false
    body:
    Can you do the same for Seedsigner?
    
    comment: p184hcb
    parent: t3_1vddeuy
    author: Dry_Mortgage_4646
    created_utc: 1785663142
    edited: false
    body:
    😢
    
    comment: p184nnw
    parent: t3_1vddeuy
    author: Powerful_Quarter691
    created_utc: 1785663232
    edited: false
    body:
    This was def preplanned and in the works for quite some time, since attackers knew that draining the wallets will alert everyone and once they start they will be in the race against time. But I agree with the part that someone with little to none knowledge could have also performed this attack, probably even attempted once the news was out. 
    
    comment: p184yqj
    parent: t3_1vddeuy
    author: fanfanye
    created_utc: 1785663393
    edited: false
    body:
    "thinking", 

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  15. source content difference between and source content +34 -35

    3 new Reddit comments were posted, including Crazy__Donkey,No-Newspaper8600,hrad95.

    seen · Captured here 157,300 chars
    What changed from the previous capture 69 lines
     "Oh this is easy! \*Does 0 research.\* Grabs a popular chip and installs some libraries off git. Call this function and call that function and bam. There it is, the final product and it only took me a few days to make!"
     
     What do you mean TRNG? What's that? I don't need it! See it works fine! Entropy? What's that? I called Random(), so the result must be!
    -
    -comment: p189g94
    -parent: t1_p188hon
    -author: Level-Set5770
    -created_utc: 1785665690
    -edited: false
    -body:
    -You just don't get it, do you?
    -
    -With closed source, you have:
    -
    -* A few dumb monkeys + A couple of god-tier AI programmers
    -
    -With open source, you have:
    -
    -* More dumb monkeys + The same couple of god-tier programmers
    -
    -The additional eyeballs the monkeys provide are a rounding error in the age of AI models. They no longer justify the risk of having your source code out in the open.
     
     comment: p189klg
     parent: t1_p189cs8
     So this is a case where the code being open source made it less secure?  
     Everyone was thinking that “everyone else” was auditing the code for vulnerabilities. Meanwhile the only ones checking the code were bad actors.
     
    -comment: p18on0b
    -parent: t1_p189g94
    -author: snek-jazz
    -created_utc: 1785672521
    -edited: false
    -body:
    -With closed source you can't audit what you're running. It could have intentional  backdoors. It's a dealbreaker.
    -
     comment: p18oqrm
     parent: t1_p18ecvu
     author: dempsey1200
     edited: false
     body:
     OP mentioned that his LLM was trained on june 16th and unconnected to the internet
    -
    -comment: p194ihp
    -parent: t1_p1922vv
    -author: Aazimoxx
    -created_utc: 1785678104
    -edited: false
    -body:
    -Sounds like your company has made a decision to accept inferior review processes then?  A decision that can have legal implications, depending on what your software is responsible for...
     
     comment: p194j8j
     parent: t1_p1945t4
     body:
     In a way it's a good heads-up. We can no leverage AI to audit our own buggy code. No wonder every token is being run past Claude to check for vulnerabilities.
     
    +comment: p1m4xk8
    +parent: t1_p18rp2b
    +author: Crazy__Donkey
    +created_utc: 1785834146
    +edited: false
    +body:
    +may i ask, and i have ZERO vlue in the area, crypto, seed generating etc (had a crypto ride a few years back, gor burned hard, and stepped away for good). 
    +
    +assuming they issue a firmware update, the user's current key is still compromised, isnt it? 
    +
    +if they say "you need to generate a new address", than  they admit the exact flaw.... so why I, as a user, create a new seed with their updated firmware and not with a new company's uncompromised  hardware?
    +
    +  
    +and on a more serious note, why those cold wallets are safer than a seed generated by online wallet like meta mask etc? 
    +
    +comment: p1mvnve
    +parent: t1_p18e9m0
    +author: No-Newspaper8600
    +created_utc: 1785845401
    +edited: false
    +body:
    +Outsource to Pakistan 
    +
    +comment: p1n9jvx
    +parent: t1_p18ekrz
    +author: hrad95
    +created_utc: 1785849732
    +edited: false
    +body:
    +So you mean, instead of using Trezor or Ledger's seed phrase generation, we should make our own? Like by rolling dice or something and picking words out of a corresponding book?
    +
     more-stub: parent t1_p19a2fb count 2
     
    +more-stub: parent t1_p1922vv count 1
    +
     more-stub: parent t1_p185wl3 count 5
     
     more-stub: parent t1_p18d317 count 4
     
     more-stub: parent t1_p188w2f count 11
     
    -more-stub: parent t1_p189g94 count 12
    +more-stub: parent t1_p188hon count 14
     
     more-stub: parent t1_p185uzk count 14
     
    
    Extracted text as captured
    post: 1vddeuy
    author: Impressive-Gene-421
    created_utc: 1785662370
    title: Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes
    body:
    It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code.
    
    [Also on GLM 5.2 (trained 16th June, no internet access).](https://www.reddit.com/r/Bitcoin/s/5x8CBk8Csk)
    
    comment: p1848pg
    parent: t3_1vddeuy
    author: TeaSipper007
    created_utc: 1785663020
    edited: false
    body:
    Can you do the same for Seedsigner?
    
    comment: p184hcb
    parent: t3_1vddeuy
    author: Dry_Mortgage_4646
    created_utc: 1785663142
    edited: false
    body:
    😢
    
    comment: p184nnw
    parent: t3_1vddeuy
    author: Powerful_Quarter691
    created_utc: 1785663232
    edited: false
    body:
    This was def preplanned and in the works for quite some time, since attackers knew that draining the wallets will alert everyone and once they start they will be in the race against time. But I agree with the part that someone with little to none knowledge could have also performed this attack, probably even attempted once the news was out. 
    
    comment: p184yqj
    parent: t3_1vddeuy
    author: fanfanye
    created_utc: 1785663393
    edited: false
    body:
    "thinking", 

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  16. source content difference between and source content +27 -29

    Three comments and their subthread (frankster p18ac4g, Level-Set5770 p18bgi4, frankster p18g2ma) disappeared from the thread, three new comments were posted (Either_Display_6624 p1kg6wz, Shepinion p1lcxyy, djscoox p1lmvzg), and the more-stub reply count under t1_p189g94 rose from 4 to 12.

    seen · Captured here 157,154 chars
    What changed from the previous capture 56 lines
     edited: false
     body:
     Funny thing is with this IC they even give you premade functions packaged with a pretty nooby GUI to configure the hardware. It's awful but it's enough to demonstrate the isolated capabilities of the chip. It seems even just copying that tool generated code and gluing it to theirs was too much hard work for them!
    -
    -comment: p18ac4g
    -parent: t1_p189g94
    -author: frankster
    -created_utc: 1785666132
    -edited: false
    -body:
    -If closed source meant this bug took another 10 years to uncover, think how much more would have been stolen from the wallets when they were hacked
     
     comment: p18aei5
     parent: t1_p185x67
     body:
     It does find a lot of faulty code and backdoors anywhere, that's for sure. It doesn't do it unprompted so you still have to point it at a codebase.
     
    -comment: p18bgi4
    -parent: t1_p18ac4g
    -author: Level-Set5770
    -created_utc: 1785666688
    -edited: false
    -body:
    -If Coldcard had been closed source, the bozos at Coinkite could've at least had a chance to run the AI models themselves before anyone else even knew the bug existed.
    -
    -What's changed is that AI has become incredibly good over just the last few months, and not everyone has realized this. Coldcard's shitty code was just sitting in the open, so some random person fed it into Claude before Coinkite ever had a chance.
    -
     comment: p18bkyp
     parent: t1_p1877qg
     author: harvested
     edited: false
     body:
     No, AI is actually very good in finding such things. (In fact any dev worth their salt should have found it during testing. Which is why I’m torn between “worst dev in history” and “deliberate backdoor”) The wallet dev just never bothered to run audits with frontier models.
    -
    -comment: p18g2ma
    -parent: t1_p18bgi4
    -author: frankster
    -created_utc: 1785668852
    -edited: false
    -body:
    -Why haven't coldcard run scanning tools already and detected the bug? This would have been possible for them 
     
     comment: p18g3r3
     parent: t1_p18fsoh
     body:
     I went on their website today just to see what was up. They are still claiming it is super duper fucking secure and cutting edge. But at the top is a link about the issues. And they say to update blah, blah, blah... As if anyone is trusting them with their BTC again. GTFOH 😂
     
    +comment: p1kg6wz
    +parent: t3_1vddeuy
    +author: Either_Display_6624
    +created_utc: 1785808154
    +edited: false
    +body:
    + claude code was trained on this vulnerability and learned it from the web 😭
    +
     comment: p1krpr6
     parent: t1_p1a5nj3
     author: quasides
     body:
     Less of an AI story than it looks. The model didn’t do anything clever, the randomness was just predictable enough that anyone actually looking would have found it. That’s the part worth being angry about. 
     
    +comment: p1lcxyy
    +parent: t1_p18rp2b
    +author: Shepinion
    +created_utc: 1785820551
    +edited: false
    +body:
    +That’s such a good point. Haven’t seen that discussed much. And yes to the people saying it would still be a better situation than what happened. But now I’m generally curious what the best way to handle would be. I would be worried it WAS a scam if I received a message from my cold wallet company that I needed to immediately create a new wallet with a new seed and move all my funds bc the current wallet is compromised…. That’s how every scam email and text and PM sounds….
    +
    +Fascinating 
    +
    +comment: p1lmvzg
    +parent: t3_1vddeuy
    +author: djscoox
    +created_utc: 1785825206
    +edited: false
    +body:
    +In a way it's a good heads-up. We can no leverage AI to audit our own buggy code. No wonder every token is being run past Claude to check for vulnerabilities.
    +
     more-stub: parent t1_p19a2fb count 2
     
     more-stub: parent t1_p185wl3 count 5
     
     more-stub: parent t1_p188w2f count 11
     
    -more-stub: parent t1_p18bgi4 count 5
    -
    -more-stub: parent t1_p189g94 count 4
    +more-stub: parent t1_p189g94 count 12
     
     more-stub: parent t1_p185uzk count 14
     
    
    Extracted text as captured
    post: 1vddeuy
    author: Impressive-Gene-421
    created_utc: 1785662370
    title: Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes
    body:
    It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code.
    
    [Also on GLM 5.2 (trained 16th June, no internet access).](https://www.reddit.com/r/Bitcoin/s/5x8CBk8Csk)
    
    comment: p1848pg
    parent: t3_1vddeuy
    author: TeaSipper007
    created_utc: 1785663020
    edited: false
    body:
    Can you do the same for Seedsigner?
    
    comment: p184hcb
    parent: t3_1vddeuy
    author: Dry_Mortgage_4646
    created_utc: 1785663142
    edited: false
    body:
    😢
    
    comment: p184nnw
    parent: t3_1vddeuy
    author: Powerful_Quarter691
    created_utc: 1785663232
    edited: false
    body:
    This was def preplanned and in the works for quite some time, since attackers knew that draining the wallets will alert everyone and once they start they will be in the race against time. But I agree with the part that someone with little to none knowledge could have also performed this attack, probably even attempted once the news was out. 
    
    comment: p184yqj
    parent: t3_1vddeuy
    author: fanfanye
    created_utc: 1785663393
    edited: false
    body:
    "thinking", 

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

  17. Earliest copy held
    seen · Captured here 157,133 chars
    Extracted text as captured
    post: 1vddeuy
    author: Impressive-Gene-421
    created_utc: 1785662370
    title: Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes
    body:
    It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code.
    
    [Also on GLM 5.2 (trained 16th June, no internet access).](https://www.reddit.com/r/Bitcoin/s/5x8CBk8Csk)
    
    comment: p1848pg
    parent: t3_1vddeuy
    author: TeaSipper007
    created_utc: 1785663020
    edited: false
    body:
    Can you do the same for Seedsigner?
    
    comment: p184hcb
    parent: t3_1vddeuy
    author: Dry_Mortgage_4646
    created_utc: 1785663142
    edited: false
    body:
    😢
    
    comment: p184nnw
    parent: t3_1vddeuy
    author: Powerful_Quarter691
    created_utc: 1785663232
    edited: false
    body:
    This was def preplanned and in the works for quite some time, since attackers knew that draining the wallets will alert everyone and once they start they will be in the race against time. But I agree with the part that someone with little to none knowledge could have also performed this attack, probably even attempted once the news was out. 
    
    comment: p184yqj
    parent: t3_1vddeuy
    author: fanfanye
    created_utc: 1785663393
    edited: false
    body:
    "thinking", 

    Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.

How to check this yourself

The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.

Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.