r/Bitcoin thread on the Claude Code vulnerability-audit reproduction
reddit-ai-discovery-thread
Latest reviewed change
source content difference between and
The thread gained a new comment blaming speculators and defending open-source code, while an earlier open-versus-closed-source comment was replaced and the live comment count expanded.
edited: 1785671653
body:
... that is exactly how it works
-
-comment: p18gaim
-parent: t1_p18e31w
-author: Aggravating_Stage996
-created_utc: 1785668951
First lines only. The complete diff is in the timeline below.
- Organisation
- r/Bitcoin
- Evidence role
- Community discussion
- Published
- 2026-08-02
- Source changes
- 16
- Detected differences
- 16
- Unreviewed
- 0
- Copies held
- 17
A discussion thread claiming an LLM prompted only to "check for vulnerabilities" surfaced the defect after eight minutes, and asserting the theft exceeded $100m. Both figures are the thread's own; the post-publication discovery reproductions this archive holds are attributed on /response/ai/. Captured for how the AI-discovery framing spread in community venues.
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
The thread gained a new comment blaming speculators and defending open-source code, while an earlier open-versus-closed-source comment was replaced and the live comment count expanded.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 22 lines
edited: 1785671653 body: ... that is exactly how it works - -comment: p18gaim -parent: t1_p18e31w -author: Aggravating_Stage996 -created_utc: 1785668951 -edited: false -body: -If the code is open source anyone can run any AI models over it countless of times if they wish. If people are actually using some software they will have a vested interest in doing this. - -If the code is closed source the dev team may run whatever AI's over their own code substantially less times than above. - -Of course this argument is also assuming AI is the be all end all of penetration tests which it is not. comment: p18gc0p parent: t1_p18b7vt body: Could someone run Claude prompts to review Trezor and Ledger codebases and share the results? +comment: p2j46mn +parent: t3_1vddeuy +author: KindBench2700 +created_utc: 1786223348 +edited: false +body: +Lol code was open source. Users should have read it. Take some personal responsibility. Speculators got speculated. + more-stub: parent t1_p19a2fb count <live-count> more-stub: parent t1_p1922vv count <live-count> more-stub: parent t1_p18c95s count <live-count> +more-stub: parent t1_p18e31w count <live-count> + more-stub: parent t1_p188hon count <live-count> more-stub: parent t1_p185uzk count <live-count>Extracted text as captured
post: 1vddeuy author: Impressive-Gene-421 created_utc: 1785662370 title: Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes body: It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code. [Also on GLM 5.2 (trained 16th June, no internet access).](https://www.reddit.com/r/Bitcoin/s/5x8CBk8Csk) comment: p1848pg parent: t3_1vddeuy author: TeaSipper007 created_utc: 1785663020 edited: false body: Can you do the same for Seedsigner? comment: p184hcb parent: t3_1vddeuy author: Dry_Mortgage_4646 created_utc: 1785663142 edited: false body: 😢 comment: p184nnw parent: t3_1vddeuy author: Powerful_Quarter691 created_utc: 1785663232 edited: false body: This was def preplanned and in the works for quite some time, since attackers knew that draining the wallets will alert everyone and once they start they will be in the race against time. But I agree with the part that someone with little to none knowledge could have also performed this attack, probably even attempted once the news was out. comment: p184yqj parent: t3_1vddeuy author: fanfanye created_utc: 1785663393 edited: false body: "thinking",Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The thread gained a new comment asking someone to run Claude prompts against Trezor and Ledger codebases and share the results, and the visible more-stub parent pointer shifted from p18crfw to p18c95s.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 18 lines
We spent an entire section in probability and stats of how difficult it is to produce true randomness. You can’t get through a reputable CS degree without having at least a good grasp on how difficult it is to achieve true randomness with a computer - -comment: p18crfw -parent: t1_p18c95s -author: Aggravating_Stage996 -created_utc: 1785667320 -edited: false -body: -I can't tell if you're dumb or trolling comment: p18cs64 parent: t1_p18agg4 body: From my reading on this whole incident is that the team was well aware of the vulnerability, as the "bug" was there for testing purposes and was basically just left there, with no code check, even a cursory glance with AI prior to release. But like I said, just what I've read, so don't take it as the gospel until we get hard proof (if that day comes). +comment: p2gdegb +parent: t3_1vddeuy +author: aaj094 +created_utc: 1786194287 +edited: false +body: +Could someone run Claude prompts to review Trezor and Ledger codebases and share the results? + more-stub: parent t1_p19a2fb count <live-count> more-stub: parent t1_p1922vv count <live-count> more-stub: parent t1_p18l6la count <live-count> -more-stub: parent t1_p18crfw count <live-count> +more-stub: parent t1_p18c95s count <live-count> more-stub: parent t1_p188hon count <live-count>Extracted text as captured
post: 1vddeuy author: Impressive-Gene-421 created_utc: 1785662370 title: Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes body: It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code. [Also on GLM 5.2 (trained 16th June, no internet access).](https://www.reddit.com/r/Bitcoin/s/5x8CBk8Csk) comment: p1848pg parent: t3_1vddeuy author: TeaSipper007 created_utc: 1785663020 edited: false body: Can you do the same for Seedsigner? comment: p184hcb parent: t3_1vddeuy author: Dry_Mortgage_4646 created_utc: 1785663142 edited: false body: 😢 comment: p184nnw parent: t3_1vddeuy author: Powerful_Quarter691 created_utc: 1785663232 edited: false body: This was def preplanned and in the works for quite some time, since attackers knew that draining the wallets will alert everyone and once they start they will be in the race against time. But I agree with the part that someone with little to none knowledge could have also performed this attack, probably even attempted once the news was out. comment: p184yqj parent: t3_1vddeuy author: fanfanye created_utc: 1785663393 edited: false body: "thinking",Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
A large reshuffle: roughly ten previously collapsed comments are now expanded (a subthread on whether dev teams should pay for AI code review) and several low-quality comments (insults, "prove it", court-payout speculation) disappeared.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 128 lines
body: Funny thing is with this IC they even give you premade functions packaged with a pretty nooby GUI to configure the hardware. It's awful but it's enough to demonstrate the isolated capabilities of the chip. It seems even just copying that tool generated code and gluing it to theirs was too much hard work for them! +comment: p18a7ot +parent: t1_p188w2f +author: Level-Set5770 +created_utc: 1785666071 +edited: false +body: +The close source devs could easily do those security passes with AI themselves. + comment: p18aei5 parent: t1_p185x67 author: Rino-Sensei edited: false body: If OP didn't use the online search mode, there is no way for Claude to know the current situation. + +comment: p18aez1 +parent: t1_p18a7ot +author: Cryptizard +created_utc: 1785666172 +edited: false +body: +Sure so there is no security difference between open and closed source then, but open source is better for the community. comment: p18agg4 parent: t1_p185uzk Maybe you're just using LLMs as chat bots but they're more advanced than that now. +comment: p18bbec +parent: t1_p18a7ot +author: Aggravating_Stage996 +created_utc: 1785666618 +edited: false +body: +So every dev team no matter how small should require access to multiple top tier AI models? You realize these aren't free right? + comment: p18bfts parent: t1_p185wl3 author: aleqqqs body: No point arguing with the clueless mofos 😂 +comment: p18c95s +parent: t1_p18bbec +author: Level-Set5770 +created_utc: 1785667074 +edited: false +body: +Yes, moving forward I do expect every dev team to have access to top tier models. If you aren't even willing to pay $25 fucking dollar for a codex sub, you should not be in this business. + comment: p18clb4 parent: t1_p189cs8 author: mlhender You can’t get through a reputable CS degree without having at least a good grasp on how difficult it is to achieve true randomness with a computer +comment: p18crfw +parent: t1_p18c95s +author: Aggravating_Stage996 +created_utc: 1785667320 +edited: false +body: +I can't tell if you're dumb or trolling + comment: p18cs64 parent: t1_p18agg4 author: Level-Set5770 edited: false body: Except it is not like everyone has a different model. Everyone is running the same set of models. + +comment: p18e31w +parent: t1_p18bbec +author: dondondorito +created_utc: 1785667943 +edited: false +body: +With $100 per month you have practically unlimited Claude usage of their best model. It‘s absolutely negligible, especially because it can be booked on a month-by-month basis. comment: p18e9ef parent: t1_p18clb4 body: I don’t know what to say about that chief. I am working at a cybersecurity company developing very custom auth solutions, sandboxed infra and a lot of other kinds of security critical software, and we use both Claude and Codex to do preliminary security reviews to our changes before any human reviews and I lost count how many times the models raised legit and not obvious issues -comment: p18ew51 -parent: t1_p184yqj -author: NoInterraction -created_utc: 1785668316 -edited: false -body: -How do you explain the first time it (or another AI) found it? I hear it was an AI that found it - comment: p18fige parent: t1_p185i6q author: SpareEconomy1849 Lmao you're being downvoted for being right. Literally a commit that changes MICROPY_HW_ENABLE_RNG to 0. Modern agents reliably find vulnerabilities much more complex than this - -comment: p18g7bl -parent: t1_p184yqj -author: Next-Inevitable-Fag -created_utc: 1785668910 -edited: false -body: -prove it comment: p18g8zi parent: t1_p185i6q body: ... that is exactly how it works +comment: p18gaim +parent: t1_p18e31w +author: Aggravating_Stage996 +created_utc: 1785668951 +edited: false +body: +If the code is open source anyone can run any AI models over it countless of times if they wish. If people are actually using some software they will have a vested interest in doing this. + +If the code is closed source the dev team may run whatever AI's over their own code substantially less times than above. + +Of course this argument is also assuming AI is the be all end all of penetration tests which it is not. + comment: p18gc0p parent: t1_p18b7vt author: ImpressiveRelief37 body: Absolutely. You can even clone a random GitHub repo, and then with no internet access let Claude review the code and chances are it’ll find bugs. -comment: p18lsjs -parent: t3_1vddeuy -author: MyFrontTeethAreFake -created_utc: 1785671371 -edited: false -body: -COLDCARD must have hundreds of millions of dollars in Bitcoin, eh? - -they better, because payouts are going to wild after court. - comment: p18lv4f parent: t1_p188qas author: nestaa13 edited: false body: Exactly, patching overload right now! + +comment: p18o6x1 +parent: t1_p18a7ot +author: snek-jazz +created_utc: 1785672345 +edited: false +body: +And they can easily include any vulnerability they like, or are coerced to do, since it's closed source. comment: p18o9p0 parent: t3_1vddeuy Not saying you’re entirely wrong, but you’d be shocked at the lack of internal controls at some of these large companies. And indeed I agree that is the real problem ETA: also vibe coding is not limited to small Indy games or apps. Plenty of engineers do exactly as I described above and don’t test edge cases properly and they get past weak testing pipelines - -comment: p194ma0 -parent: t3_1vddeuy -author: ForsakenBet2647 -created_utc: 1785678138 -edited: false -body: -It makes me so hard bro comment: p194muo parent: t1_p18i6h2 body: A FUKING LOT TRUST ME BRAH! HIS ASS IS HUGE! -comment: p19e0xu -parent: t1_p18lsjs -author: insbordnat -created_utc: 1785681047 -edited: false -body: -You realize the company is like a super small shop. I'd be shocked if they had more than 20mm of insurance. - comment: p19ein6 parent: t1_p18rp2b author: Mallmagician body: Y2K flashbacks -comment: p1akfuq -parent: t1_p19e0xu -author: MyFrontTeethAreFake -created_utc: 1785692793 -edited: false -body: -so what happens now? they say "Sorry. we'll be better!" then everyone just moves on? - comment: p1aljse parent: t1_p1aa4m6 author: Opposite-Friend7275 body: security by obscurity isn't a strictly defined term - this is almost as objective of an example as you can get because there are very obviously different forms of obscurity. Relying on the fact that other people "probably" audited the code and just trusting $50k+ to that is absolutely a form of obscurity. Nobody with the time + knowledge actually audited the code, everybody trusted that they did, and everybody got bit. -comment: p1dghl4 -parent: t1_p1akfuq -author: insbordnat -created_utc: 1785724626 -edited: false -body: -Unfortunately, that's what typically happens. Doubtful there are any other assets to go after. - comment: p1dmdno parent: t1_p18svdv author: EDWARD_SN0WDEN more-stub: parent t1_p18l6la count <live-count> -more-stub: parent t1_p188w2f count <live-count> +more-stub: parent t1_p18crfw count <live-count> more-stub: parent t1_p188hon count <live-count>Extracted text as captured
post: 1vddeuy author: Impressive-Gene-421 created_utc: 1785662370 title: Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes body: It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code. [Also on GLM 5.2 (trained 16th June, no internet access).](https://www.reddit.com/r/Bitcoin/s/5x8CBk8Csk) comment: p1848pg parent: t3_1vddeuy author: TeaSipper007 created_utc: 1785663020 edited: false body: Can you do the same for Seedsigner? comment: p184hcb parent: t3_1vddeuy author: Dry_Mortgage_4646 created_utc: 1785663142 edited: false body: 😢 comment: p184nnw parent: t3_1vddeuy author: Powerful_Quarter691 created_utc: 1785663232 edited: false body: This was def preplanned and in the works for quite some time, since attackers knew that draining the wallets will alert everyone and once they start they will be in the race against time. But I agree with the part that someone with little to none knowledge could have also performed this attack, probably even attempted once the news was out. comment: p184yqj parent: t3_1vddeuy author: fanfanye created_utc: 1785663393 edited: false body: "thinking",Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Two duplicated RollingMeteors comments disappeared and two new comments were added: one asserting the developer did it on purpose, one recounting that the team was allegedly aware of the test-only bug.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 46 lines
body: [deleted] -comment: p1aqpgq -parent: t1_p18ekrz -author: RollingMeteors -created_utc: 1785694462 -edited: false -body: -> how fucking stupid ColdCard is and how they clearly did not test their RNG device sufficiently - - - - - -<priceIsRightSadTrombone.wav> - -comment: p1aqsh5 -parent: t1_p18ekrz -author: RollingMeteors -created_utc: 1785694485 -edited: false -body: -> how fucking stupid ColdCard is and how they clearly did not test their RNG device sufficiently - - - - - -<priceIsRightSadTrombone.wav> - comment: p1aqvkv parent: t3_1vddeuy author: YLCZ body: It’s crazy that this is wasn’t caught sooner +comment: p23xay4 +parent: t1_p19xhzr +author: zinornia +created_utc: 1786040023 +edited: false +body: +he did it on purpose + +comment: p265lbf +parent: t1_p18e9m0 +author: Coleyx123 +created_utc: 1786062428 +edited: false +body: +From my reading on this whole incident is that the team was well aware of the vulnerability, as the "bug" was there for testing purposes and was basically just left there, with no code check, even a cursory glance with AI prior to release. But like I said, just what I've read, so don't take it as the gospel until we get hard proof (if that day comes). + more-stub: parent t1_p19a2fb count <live-count> more-stub: parent t1_p1922vv count <live-count> more-stub: parent t1_p18n109 count <live-count> +more-stub: parent t1_p18ekrz count <live-count> + more-stub: parent t1_p1ufsx6 count <live-count> more-stub: parent t1_p19jcia count <live-count>Extracted text as captured
post: 1vddeuy author: Impressive-Gene-421 created_utc: 1785662370 title: Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes body: It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code. [Also on GLM 5.2 (trained 16th June, no internet access).](https://www.reddit.com/r/Bitcoin/s/5x8CBk8Csk) comment: p1848pg parent: t3_1vddeuy author: TeaSipper007 created_utc: 1785663020 edited: false body: Can you do the same for Seedsigner? comment: p184hcb parent: t3_1vddeuy author: Dry_Mortgage_4646 created_utc: 1785663142 edited: false body: 😢 comment: p184nnw parent: t3_1vddeuy author: Powerful_Quarter691 created_utc: 1785663232 edited: false body: This was def preplanned and in the works for quite some time, since attackers knew that draining the wallets will alert everyone and once they start they will be in the race against time. But I agree with the part that someone with little to none knowledge could have also performed this attack, probably even attempted once the news was out. comment: p184yqj parent: t3_1vddeuy author: fanfanye created_utc: 1785663393 edited: false body: "thinking",Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
A comment by THE_RETARD_AGITATOR ("honestly, good") was deleted, and one new comment by Valnaya says it is crazy this was not caught sooner.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 18 lines
edited: false body: Rumor is that they set it to 0 to test it without using the hardware and forgot to re-enable the trng on the shipping firmware. - -comment: p1937zz -parent: t1_p18i6h2 -author: THE_RETARD_AGITATOR -created_utc: 1785677686 -edited: false -body: -honestly, good. how can we keep apologizing past all of these critical flaws comment: p193c1q parent: t1_p18wm9r Estoy seguro al 100% que hay codigo metido en la mayoría de software actual de "día 0" que permiten estas cosas. Aunque la mayoría de la gente piense que una seed generada por el mismo sea mas insegura, os digo yo que eliminarias ese factor. De hecho creo que los que generaron su propia entropía no están afectados. Con esto quiero aclarar que yo tengo una cantidad insignificante de criptos, yo prefiero tener el respaldo del banco que me asegura 100k por cuenta bancaria. Además debido a las grandes fluctuaciones que tiene me parece un producto de altisimo riesgo, soy de un perfil conservador. Para luchar contra la inflaccion lo mejor es invertir en propiedades, alquiler, airbnb. Igual no haces un x100 o x1000 pero vives tranquilo, con la certeza de que tu propiedad no va a desaparecer como "humo" +comment: p226r1v +parent: t3_1vddeuy +author: Valnaya +created_utc: 1786024210 +edited: false +body: +It’s crazy that this is wasn’t caught sooner + more-stub: parent t1_p19a2fb count <live-count> more-stub: parent t1_p1922vv count <live-count> more-stub: parent t1_p184yqj count <live-count> -more-stub: parent t1_p1937zz count <live-count> +more-stub: parent t1_p18i6h2 count <live-count> more-stub: parent t1_p18jy2w count <live-count>Extracted text as captured
post: 1vddeuy author: Impressive-Gene-421 created_utc: 1785662370 title: Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes body: It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code. [Also on GLM 5.2 (trained 16th June, no internet access).](https://www.reddit.com/r/Bitcoin/s/5x8CBk8Csk) comment: p1848pg parent: t3_1vddeuy author: TeaSipper007 created_utc: 1785663020 edited: false body: Can you do the same for Seedsigner? comment: p184hcb parent: t3_1vddeuy author: Dry_Mortgage_4646 created_utc: 1785663142 edited: false body: 😢 comment: p184nnw parent: t3_1vddeuy author: Powerful_Quarter691 created_utc: 1785663232 edited: false body: This was def preplanned and in the works for quite some time, since attackers knew that draining the wallets will alert everyone and once they start they will be in the race against time. But I agree with the part that someone with little to none knowledge could have also performed this attack, probably even attempted once the news was out. comment: p184yqj parent: t3_1vddeuy author: fanfanye created_utc: 1785663393 edited: false body: "thinking",Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Two earlier comments disappeared (a "wtf are you talking about?" reply and a comment claiming GPG signatures prove switck is doc-hex), and one new Spanish-language comment argues self-generated entropy avoids the bug.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 30 lines
CC was well and truly screwed once this firmware shipped on devices. -comment: p1a7tod -parent: t1_p1937zz -author: jannies_doit_4_free -created_utc: 1785689413 -edited: false -body: -wtf are you talking about? - comment: p1a82q0 parent: t1_p18j0mj author: jannies_doit_4_free body: The guy stealing the btc himself and the guy accidentally allowing an exploit are two different things -comment: p1v54ic -parent: t1_p198qu8 -author: Napoleanna -created_utc: 1785940869 -edited: false -body: -it turns out that switck is doc-hex, [proven by GPG commit signatures](https://gist.github.com/jamesob/ca9b4ca384969b4cfd62813419854d69) - - - comment: p1vn1us parent: t1_p18dalk author: ScreenAppropriate679 body: I trust you pay close attention to small details r/PmMeUrTinyAsianTits +comment: p20y251 +parent: t3_1vddeuy +author: SingerLate3349 +created_utc: 1786008097 +edited: false +body: +No sé si es por mi profesión "Pero soy muy desconfiado" el hecho de que un dispositivo me genere su propia seed con las palabras que el quiere no me acaba de convencer. Como dice aquel "Poderoso caballero es don dinero". +Estoy seguro al 100% que hay codigo metido en la mayoría de software actual de "día 0" que permiten estas cosas. Aunque la mayoría de la gente piense que una seed generada por el mismo sea mas insegura, os digo yo que eliminarias ese factor. De hecho creo que los que generaron su propia entropía no están afectados. +Con esto quiero aclarar que yo tengo una cantidad insignificante de criptos, yo prefiero tener el respaldo del banco que me asegura 100k por cuenta bancaria. Además debido a las grandes fluctuaciones que tiene me parece un producto de altisimo riesgo, soy de un perfil conservador. Para luchar contra la inflaccion lo mejor es invertir en propiedades, alquiler, airbnb. Igual no haces un x100 o x1000 pero vives tranquilo, con la certeza de que tu propiedad no va a desaparecer como "humo" + more-stub: parent t1_p19a2fb count <live-count> more-stub: parent t1_p1922vv count <live-count> more-stub: parent t1_p184yqj count <live-count> +more-stub: parent t1_p1937zz count <live-count> + more-stub: parent t1_p18jy2w count <live-count> more-stub: parent t1_p18l6la count <live-count>Extracted text as captured
post: 1vddeuy author: Impressive-Gene-421 created_utc: 1785662370 title: Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes body: It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code. [Also on GLM 5.2 (trained 16th June, no internet access).](https://www.reddit.com/r/Bitcoin/s/5x8CBk8Csk) comment: p1848pg parent: t3_1vddeuy author: TeaSipper007 created_utc: 1785663020 edited: false body: Can you do the same for Seedsigner? comment: p184hcb parent: t3_1vddeuy author: Dry_Mortgage_4646 created_utc: 1785663142 edited: false body: 😢 comment: p184nnw parent: t3_1vddeuy author: Powerful_Quarter691 created_utc: 1785663232 edited: false body: This was def preplanned and in the works for quite some time, since attackers knew that draining the wallets will alert everyone and once they start they will be in the race against time. But I agree with the part that someone with little to none knowledge could have also performed this attack, probably even attempted once the news was out. comment: p184yqj parent: t3_1vddeuy author: fanfanye created_utc: 1785663393 edited: false body: "thinking",Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Reddit now marks the original author and one comment as deleted or removed, removes linked examples from that comment, and adds a later reply.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 38 lines
comment: p19gy7p parent: t1_p18rp2b -author: FastRelief3222 +author: [deleted] created_utc: 1785681912 edited: false body: -[https://www.reddit.com/r/coldcard/comments/17fy8cz/17\_btc\_drained\_instantly\_using\_sparrow\_to\_cold/](https://www.reddit.com/r/coldcard/comments/17fy8cz/17_btc_drained_instantly_using_sparrow_to_cold/) - -[https://www.reddit.com/r/Electrum/comments/id7bpj/the\_loss\_of\_bitcoin/](https://www.reddit.com/r/Electrum/comments/id7bpj/the_loss_of_bitcoin/) - -[https://www.reddit.com/r/coldcard/comments/17epqk8/040\_bitcoin\_taken\_instantly\_from\_my\_coldcard/](https://www.reddit.com/r/coldcard/comments/17epqk8/040_bitcoin_taken_instantly_from_my_coldcard/) - -Just imagine if they knew 6 years ago +[deleted] comment: p19h7ev parent: t1_p18khog body: Its opensource anyone can verify! -comment: p1a9jwi -parent: t1_p18rp2b -author: Forsaken-Stink -created_utc: 1785689879 -edited: false -body: -Stupid take but OK - comment: p1a9om4 parent: t1_p19yqn7 author: Aazimoxx edited: false body: Sauce? - -comment: p1ae4c2 -parent: t1_p18l6la -author: Objective_Digit -created_utc: 1785691113 -edited: false -body: -It wasn't open source. comment: p1aed92 parent: t1_p18v2ky body: increasing smelling like an inside job +comment: p1zgnr8 +parent: t1_p1d4sah +author: No-Good-One-Shoe +created_utc: 1785984353 +edited: false +body: +I trust you pay close attention to small details r/PmMeUrTinyAsianTits + more-stub: parent t1_p19a2fb count <live-count> more-stub: parent t1_p1922vv count <live-count> more-stub: parent t1_p19ein6 count <live-count> +more-stub: parent t1_p18rp2b count <live-count> + more-stub: parent t1_p194b74 count <live-count> more-stub: parent t1_p185wl3 count <live-count> more-stub: parent t1_p18jy2w count <live-count> +more-stub: parent t1_p18l6la count <live-count> + more-stub: parent t1_p188w2f count <live-count> more-stub: parent t1_p188hon count <live-count>Extracted text as captured
post: 1vddeuy author: Impressive-Gene-421 created_utc: 1785662370 title: Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes body: It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code. [Also on GLM 5.2 (trained 16th June, no internet access).](https://www.reddit.com/r/Bitcoin/s/5x8CBk8Csk) comment: p1848pg parent: t3_1vddeuy author: TeaSipper007 created_utc: 1785663020 edited: false body: Can you do the same for Seedsigner? comment: p184hcb parent: t3_1vddeuy author: Dry_Mortgage_4646 created_utc: 1785663142 edited: false body: 😢 comment: p184nnw parent: t3_1vddeuy author: Powerful_Quarter691 created_utc: 1785663232 edited: false body: This was def preplanned and in the works for quite some time, since attackers knew that draining the wallets will alert everyone and once they start they will be in the race against time. But I agree with the part that someone with little to none knowledge could have also performed this attack, probably even attempted once the news was out. comment: p184yqj parent: t3_1vddeuy author: fanfanye created_utc: 1785663393 edited: false body: "thinking",Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Reddit served five additional comments about the audit framing, source availability and inside-job speculation, while four previously held comments were omitted from this response.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 84 lines
edited: false body: Mythos found a bug used throughout the internet that had existed since 1998 and no security research team or individual ever spotted it. It was so significant that they had to stop the release, give it to 50 of the biggest American companies to patch their systems and then re-released it later. - -comment: p18qkhi -parent: t1_p1877qg -author: Chucklum -created_utc: 1785673267 -edited: false -body: -So many other comments pointed out why. If you had tried this 1 month ago you wouldn't have gotten the same results. comment: p18r5nc parent: t1_p18iyzy Check how much power you need to derive such seephrase . -comment: p19cu1k -parent: t1_p18n109 -author: Unable_Review3665 -created_utc: 1785680692 -edited: false -body: -Ai works on both sides so seems the attackers are more active than security employees. Id even say attackers have fewer resources… so pure lazyness - comment: p19cvp4 parent: t1_p19bc1a author: habbadee body: You're exactly right, and honestly it all exists in such a legal grey area I wouldn't be surprised if CC and their personnel just fade into non existence and face 0 real consequences for their actions. That's the unfortunate reality of BTC and recovering funds can sometimes be an impossible feat. I truly feel for all the people who have lost funds due to the complete negligence that CC has exhibited. -comment: p19kbuj -parent: t1_p19ein6 -author: ElMasAltoDeLosEnanos -created_utc: 1785682891 -edited: false -body: -That makes too much sense. - comment: p19kean parent: t1_p18zn1x author: Th4ab body: The guy stealing the btc himself and the guy accidentally allowing an exploit are two different things -comment: p1ul5oi -parent: t1_p1ufsx6 -author: slvbtc -created_utc: 1785935392 -edited: false -body: -What if they are not. Havent you seen the posts showcasing why the CTO of coinkite may have planted the bug on purpose in order to steal user funds himself. +comment: p1v54ic +parent: t1_p198qu8 +author: Napoleanna +created_utc: 1785940869 +edited: false +body: +it turns out that switck is doc-hex, [proven by GPG commit signatures](https://gist.github.com/jamesob/ca9b4ca384969b4cfd62813419854d69) + + + +comment: p1vn1us +parent: t1_p18dalk +author: ScreenAppropriate679 +created_utc: 1785945417 +edited: false +body: +Fable would have been prevented by safeguards to audit the codebase + +comment: p1w11om +parent: t1_p1vn1us +author: dondondorito +created_utc: 1785948875 +edited: false +body: +Why? The codebase was out there for everyone to read. Fable would have read it just fine when prompted to. + +comment: p1w3j2y +parent: t1_p1w11om +author: ScreenAppropriate679 +created_utc: 1785949482 +edited: false +body: +Because Anthropic doesn't want Fable to be used by everyone to identify vulnerabilities in open source software. + +Fable doesn't even allow me to audit my own softwares in depth. + +comment: p1x9o6p +parent: t3_1vddeuy +author: TechnologyGrouchy679 +created_utc: 1785960065 +edited: false +body: +increasing smelling like an inside job more-stub: parent t1_p19a2fb count <live-count> more-stub: parent t1_p1922vv count <live-count> -more-stub: parent t1_p1ul5oi count <live-count> +more-stub: parent t1_p18n109 count <live-count> + +more-stub: parent t1_p1ufsx6 count <live-count> more-stub: parent t1_p19jcia count <live-count> +more-stub: parent t1_p19ein6 count <live-count> + +more-stub: parent t1_p194b74 count <live-count> + more-stub: parent t1_p185wl3 count <live-count> more-stub: parent t1_p18d317 count <live-count> more-stub: parent t1_p188nay count <live-count> +more-stub: parent t1_p1877qg count <live-count> + more-stub: parent t3_1vddeuy count <live-count>Extracted text as captured
post: 1vddeuy author: Impressive-Gene-421 created_utc: 1785662370 title: Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes body: It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code. [Also on GLM 5.2 (trained 16th June, no internet access).](https://www.reddit.com/r/Bitcoin/s/5x8CBk8Csk) comment: p1848pg parent: t3_1vddeuy author: TeaSipper007 created_utc: 1785663020 edited: false body: Can you do the same for Seedsigner? comment: p184hcb parent: t3_1vddeuy author: Dry_Mortgage_4646 created_utc: 1785663142 edited: false body: 😢 comment: p184nnw parent: t3_1vddeuy author: Powerful_Quarter691 created_utc: 1785663232 edited: false body: This was def preplanned and in the works for quite some time, since attackers knew that draining the wallets will alert everyone and once they start they will be in the race against time. But I agree with the part that someone with little to none knowledge could have also performed this attack, probably even attempted once the news was out. comment: p184yqj parent: t3_1vddeuy author: fanfanye created_utc: 1785663393 edited: false body: "thinking",Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Reddit served new comments discussing the distinction between an exploit and deliberate theft, including speculation about a vendor employee, while several earlier comments were omitted from the captured thread surface.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 92 lines
body: which is hilarious since crypto is mostly tech heads… -comment: p18kd9p -parent: t1_p185i6q -author: Wizzard_2025 -created_utc: 1785670765 -edited: false -body: -Yes, that's how they work. - comment: p18kf7v parent: t1_p18frua author: mastermilian edited: false body: I work in IT and vulnerability remediation is part of my role. The last three months have seen record amounts of CVEs month after month. AI is giving so many threat actors tools to quickly identify vulnerabilities. We’re getting hammered - -comment: p18n25j -parent: t1_p18kvn1 -author: harvested -created_utc: 1785671889 -edited: false -body: -Advanced models have only been out a couple of months. Timing is obvious, no? - -Doesn't change the fact the OP comment with 200 votes doesn't understand how AI works and thinks they're just search engines. comment: p18n8vb parent: t1_p18jzsa body: Yes, that person verified, then took all the coins for themselves and got the reward.... -comment: p1bknub -parent: t1_p19jcia -author: Tomsonx232 -created_utc: 1785702764 -edited: false -body: -You could have them send a transaction with a specific message on chain from that address - comment: p1bnjee parent: t1_p1anhge author: PleaseDoTapTheGlass body: Doing nothing just means an attacker has time to prepare a plan before acting on it -comment: p1bufad -parent: t1_p1bknub -author: Rannasha -created_utc: 1785705577 -edited: false -body: -But the attacker would also control that address, which is exactly the problem. - comment: p1bvq4x parent: t1_p1ahgub author: Bascilian body: Oh wow that was quite the read. Thanks for sharing. Shit could get dark. -comment: p1hoi4s -parent: t1_p1bufad -author: Tomsonx232 -created_utc: 1785779511 -edited: false -body: -Yes but only the user would be given the message to send from Cold Card.... I.e. whatever email/shipping address you gave Cold Card during purchase they would email (or based on user preference, mail) you a specialized code. So sending that code on the blockchain confirms you control the original email address and the wallet. - -Part 1 of the message would be the unique code Cold Card would give you and part 2 of the message would be the public address of the new and wallet or CEX deposit address - comment: p1j13k9 parent: t3_1vddeuy author: flooberdoodler body: Next time I hear people talk shit about vibe coders and security vulnerabilities I’m going to point to this. Thanks! +comment: p1tzfe3 +parent: t1_p1bcmqz +author: Jogol +created_utc: 1785928051 +edited: false +body: +Someone did :) + +comment: p1uchyj +parent: t1_p1ap3h0 +author: MatixMint +created_utc: 1785932737 +edited: false +body: +Still no. It makes me realize a lot of yall dont understand how this works. + +comment: p1uegt8 +parent: t1_p1uchyj +author: slvbtc +created_utc: 1785933363 +edited: false +body: +What if theres strong evidence the safe maker also used this 1 digit pin code flaw to steal the contents of the safe. + +comment: p1ufsx6 +parent: t1_p1uegt8 +author: MatixMint +created_utc: 1785933778 +edited: false +body: +The guy stealing the btc himself and the guy accidentally allowing an exploit are two different things + +comment: p1ul5oi +parent: t1_p1ufsx6 +author: slvbtc +created_utc: 1785935392 +edited: false +body: +What if they are not. Havent you seen the posts showcasing why the CTO of coinkite may have planted the bug on purpose in order to steal user funds himself. + more-stub: parent t1_p19a2fb count <live-count> more-stub: parent t1_p1922vv count <live-count> +more-stub: parent t1_p1ul5oi count <live-count> + +more-stub: parent t1_p19jcia count <live-count> + more-stub: parent t1_p185wl3 count <live-count> more-stub: parent t1_p18d317 count <live-count> -more-stub: parent t1_p18n25j count <live-count> +more-stub: parent t1_p18kvn1 count <live-count> + +more-stub: parent t1_p185i6q count <live-count> more-stub: parent t1_p193er6 count <live-count>Extracted text as captured
post: 1vddeuy author: Impressive-Gene-421 created_utc: 1785662370 title: Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes body: It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code. [Also on GLM 5.2 (trained 16th June, no internet access).](https://www.reddit.com/r/Bitcoin/s/5x8CBk8Csk) comment: p1848pg parent: t3_1vddeuy author: TeaSipper007 created_utc: 1785663020 edited: false body: Can you do the same for Seedsigner? comment: p184hcb parent: t3_1vddeuy author: Dry_Mortgage_4646 created_utc: 1785663142 edited: false body: 😢 comment: p184nnw parent: t3_1vddeuy author: Powerful_Quarter691 created_utc: 1785663232 edited: false body: This was def preplanned and in the works for quite some time, since attackers knew that draining the wallets will alert everyone and once they start they will be in the race against time. But I agree with the part that someone with little to none knowledge could have also performed this attack, probably even attempted once the news was out. comment: p184yqj parent: t3_1vddeuy author: fanfanye created_utc: 1785663393 edited: false body: "thinking",Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Two earlier discussion comments disappeared, including a sceptical reply about the AI framing, and the thread gained two new replies advocating physical entropy and praising the vulnerability-audit example.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 38 lines
body: Dude don't even stress on it. Anyone with half a brain and a basic understanding of programming realizes you're 100% correct in this post. The people disagreeing are just technologically illiterate which is insane considering they're on a Bitcoin subreddit lmao -comment: p18b62v -parent: t1_p188nay -author: LeftMorning6141 -created_utc: 1785666544 -edited: false -body: -lmao???? - comment: p18b7vt parent: t1_p188nay author: LeftMorning6141 edited: false body: you don't need Fable. Any LLM with coding abilities can find this. "Security by obscurity" is gone for good. - -comment: p18p9gu -parent: t1_p18n25j -author: retro_grave -created_utc: 1785672766 -edited: 1785673130 -body: -It's not obvious to me as a software engineer/IT specialist. There are major data breaches and CVEs published weekly, long before AI were added to the process. Yes, AI is increasing the pace, but this could have been identified 6 months ago by the attacker and them quietly scanned/indexed wallets they could drain until they were confident to pull the trigger. Most vulnerabilities are in the wild for years before identified, so the timing isn't really suspect IMO. I would be curious about anything the attacker could say, but I doubt they want to be known which is why I asked. Once they trigger the drains they would want to move quickly to unload the BTC as well, and would likely want some plan in place. Curious about that as well. - -I would also say, the exploits I've seen reported are fairly trivial and similar PRNG "attacks" have a long history in crypto. Coldcard reaping their day doesn't make the attack any more likely to be AI. Maybe it is, but I just haven't seen evidence of it. comment: p18plhp parent: t1_p18d317 body: The remedy would be a civil suit for damages +comment: p1rs1nx +parent: t1_p1n9jvx +author: shedgehog-orchard +created_utc: 1785894333 +edited: false +body: +Yes 100% you should use either physical entropy entirely with a corresponding table (lots of options or can come up with your own) or some combination of software and hardware entropy but the core randomness generation shouldn’t be in software + +comment: p1rv3wn +parent: t3_1vddeuy +author: Braddles14 +created_utc: 1785895338 +edited: false +body: +Next time I hear people talk shit about vibe coders and security vulnerabilities I’m going to point to this. Thanks! + more-stub: parent t1_p19a2fb count <live-count> more-stub: parent t1_p1922vv count <live-count> more-stub: parent t1_p18d317 count <live-count> -more-stub: parent t1_p18p9gu count <live-count> +more-stub: parent t1_p18n25j count <live-count> more-stub: parent t1_p193er6 count <live-count> more-stub: parent t1_p187kfo count <live-count> +more-stub: parent t1_p188nay count <live-count> + more-stub: parent t3_1vddeuy count <live-count>Extracted text as captured
post: 1vddeuy author: Impressive-Gene-421 created_utc: 1785662370 title: Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes body: It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code. [Also on GLM 5.2 (trained 16th June, no internet access).](https://www.reddit.com/r/Bitcoin/s/5x8CBk8Csk) comment: p1848pg parent: t3_1vddeuy author: TeaSipper007 created_utc: 1785663020 edited: false body: Can you do the same for Seedsigner? comment: p184hcb parent: t3_1vddeuy author: Dry_Mortgage_4646 created_utc: 1785663142 edited: false body: 😢 comment: p184nnw parent: t3_1vddeuy author: Powerful_Quarter691 created_utc: 1785663232 edited: false body: This was def preplanned and in the works for quite some time, since attackers knew that draining the wallets will alert everyone and once they start they will be in the race against time. But I agree with the part that someone with little to none knowledge could have also performed this attack, probably even attempted once the news was out. comment: p184yqj parent: t3_1vddeuy author: fanfanye created_utc: 1785663393 edited: false body: "thinking",Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
An existing Reddit comment no longer appeared in the captured thread.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 12 lines
comment: p1ap6cu parent: t1_p18ho21 -author: b1mm3rl1f3 +author: [deleted] created_utc: 1785694050 edited: false body: -Also, can someone explain why the bluetooth on the Trezor safe 7 isn't considered a vulnerability? +[deleted] comment: p1aqpgq parent: t1_p18ekrz body: Then don’t use a styrofoam safe genius. -comment: p1d8gvr -parent: t1_p1cqp7r -author: b1mm3rl1f3 -created_utc: 1785721750 -edited: false -body: -I ordered the 7 yesterday, cancelled it, and ordered the 5 today. It isn't fully air gapped and I don't want the option there at all. I'm surprised Trezor went with that - comment: p1daxn2 parent: t1_p1brx6e author: IInsulinceExtracted text as captured
post: 1vddeuy author: Impressive-Gene-421 created_utc: 1785662370 title: Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes body: It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code. [Also on GLM 5.2 (trained 16th June, no internet access).](https://www.reddit.com/r/Bitcoin/s/5x8CBk8Csk) comment: p1848pg parent: t3_1vddeuy author: TeaSipper007 created_utc: 1785663020 edited: false body: Can you do the same for Seedsigner? comment: p184hcb parent: t3_1vddeuy author: Dry_Mortgage_4646 created_utc: 1785663142 edited: false body: 😢 comment: p184nnw parent: t3_1vddeuy author: Powerful_Quarter691 created_utc: 1785663232 edited: false body: This was def preplanned and in the works for quite some time, since attackers knew that draining the wallets will alert everyone and once they start they will be in the race against time. But I agree with the part that someone with little to none knowledge could have also performed this attack, probably even attempted once the news was out. comment: p184yqj parent: t3_1vddeuy author: fanfanye created_utc: 1785663393 edited: false body: "thinking",Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The captured reply tree gained a collapsed more-stub indicating two additional replies under an existing comment.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 18 lines
edited: false body: It’s almost certain that the developer was confident in python but forced to use C. - -comment: p18pzuj -parent: t1_p18p9gu -author: harvested -created_utc: 1785673048 -edited: false -body: -Okay, general consensus is around AI, in particular Kimi K3. - -https://x.com/w_s_bitcoin/status/2083539953892364400 - -This went unnoticed for 5 years then was found when the models advanced. - -But yeah you are welcome to disagree. - -I believe they have a lead on the original sweep attacker. comment: p18q1ij parent: t1_p18b4dc more-stub: parent t1_p18d317 count 4 -more-stub: parent t1_p18pzuj count 1 +more-stub: parent t1_p18p9gu count 2 more-stub: parent t1_p193er6 count 0Extracted text as captured
post: 1vddeuy author: Impressive-Gene-421 created_utc: 1785662370 title: Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes body: It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code. [Also on GLM 5.2 (trained 16th June, no internet access).](https://www.reddit.com/r/Bitcoin/s/5x8CBk8Csk) comment: p1848pg parent: t3_1vddeuy author: TeaSipper007 created_utc: 1785663020 edited: false body: Can you do the same for Seedsigner? comment: p184hcb parent: t3_1vddeuy author: Dry_Mortgage_4646 created_utc: 1785663142 edited: false body: 😢 comment: p184nnw parent: t3_1vddeuy author: Powerful_Quarter691 created_utc: 1785663232 edited: false body: This was def preplanned and in the works for quite some time, since attackers knew that draining the wallets will alert everyone and once they start they will be in the race against time. But I agree with the part that someone with little to none knowledge could have also performed this attack, probably even attempted once the news was out. comment: p184yqj parent: t3_1vddeuy author: fanfanye created_utc: 1785663393 edited: false body: "thinking",Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
An existing comment was deleted: its author and body now appear as “[deleted]”.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 10 lines
comment: p18z27c parent: t1_p18e9m0 -author: ContemptMarzipan +author: [deleted] created_utc: 1785676306 -edited: false -body: -Peter D. Gray made the commit to the code - https://x.com/grok/status/2083899371330916755 - -https://www.linkedin.com/in/doc-hex-04063811/ +edited: 1785852936 +body: +[deleted] comment: p18zjr8 parent: t1_p18l6laExtracted text as captured
post: 1vddeuy author: Impressive-Gene-421 created_utc: 1785662370 title: Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes body: It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code. [Also on GLM 5.2 (trained 16th June, no internet access).](https://www.reddit.com/r/Bitcoin/s/5x8CBk8Csk) comment: p1848pg parent: t3_1vddeuy author: TeaSipper007 created_utc: 1785663020 edited: false body: Can you do the same for Seedsigner? comment: p184hcb parent: t3_1vddeuy author: Dry_Mortgage_4646 created_utc: 1785663142 edited: false body: 😢 comment: p184nnw parent: t3_1vddeuy author: Powerful_Quarter691 created_utc: 1785663232 edited: false body: This was def preplanned and in the works for quite some time, since attackers knew that draining the wallets will alert everyone and once they start they will be in the race against time. But I agree with the part that someone with little to none knowledge could have also performed this attack, probably even attempted once the news was out. comment: p184yqj parent: t3_1vddeuy author: fanfanye created_utc: 1785663393 edited: false body: "thinking",Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
1 new Reddit comment was posted, including Peking_Meerschaum.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 30 lines
body: That's no different than a public announcement that there's a security flaw. Which brings everyone, thieves included, to seeking out that flaw to exploit. So now, not only did they introduce a fatal flaw, but they announced it's existence to the world as ready and available to be exploited. Imagine their liability after wallets are compromised after the announcement. -comment: p19d1hm -parent: t1_p18pzuj -author: Aazimoxx -created_utc: 1785680754 -edited: 1785681050 -body: -[xcancel link](https://xcancel.com/w_s_bitcoin/status/2083539952395067509) for the non-twittards 👍 - -And [Bitkey response](https://xcancel.com/clay_garrett/status/2083585966481068398) shortly after: - ->Sharing our initial findings on a reported vulnerability. Our recommendation is to continue to use your Bitkey normally. -> ->The reported vulnerability would require exceptional circumstances to exploit, and can only occur at a specific narrow time during inheritance setup. Even if an attacker was able to exploit this vulnerability (including exploiting TLS internet security), they would not have enough cryptographic material to access funds. This is Bitkey’s defense-in-depth in action. -> ->Our assessment is this presents no risk of remote drains or immediate funds loss. We appreciate @1440000bytes who reported this issue to us directly. -> ->We will share a more thorough technical report imminently, and follow that with a hosted space on X where the team will talk through the details with the community and answer any questions. We'll submit a patch to the mobile app to both stores today. - -This isn't a comment on the existing conversation here btw. The guy you're responding to makes one or two okay points but gets some of the fundamentals wrong. There's nothing to suggest the attackers in this case waited 6-18mths versus just planning it out over say a week, and there's zero need to rush to launder the BTC once it's been first moved. - comment: p19dcnp parent: t1_p192rll author: 99999999999999999989 body: So you mean, instead of using Trezor or Ledger's seed phrase generation, we should make our own? Like by rolling dice or something and picking words out of a corresponding book? +comment: p1ngeg4 +parent: t1_p1ap3h0 +author: Peking_Meerschaum +created_utc: 1785851668 +edited: false +body: +The remedy would be a civil suit for damages + more-stub: parent t1_p19a2fb count 2 more-stub: parent t1_p1922vv count 1 more-stub: parent t1_p18d317 count 4 +more-stub: parent t1_p18pzuj count 1 + more-stub: parent t1_p193er6 count 0 more-stub: parent t1_p184yqj count 2Extracted text as captured
post: 1vddeuy author: Impressive-Gene-421 created_utc: 1785662370 title: Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes body: It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code. [Also on GLM 5.2 (trained 16th June, no internet access).](https://www.reddit.com/r/Bitcoin/s/5x8CBk8Csk) comment: p1848pg parent: t3_1vddeuy author: TeaSipper007 created_utc: 1785663020 edited: false body: Can you do the same for Seedsigner? comment: p184hcb parent: t3_1vddeuy author: Dry_Mortgage_4646 created_utc: 1785663142 edited: false body: 😢 comment: p184nnw parent: t3_1vddeuy author: Powerful_Quarter691 created_utc: 1785663232 edited: false body: This was def preplanned and in the works for quite some time, since attackers knew that draining the wallets will alert everyone and once they start they will be in the race against time. But I agree with the part that someone with little to none knowledge could have also performed this attack, probably even attempted once the news was out. comment: p184yqj parent: t3_1vddeuy author: fanfanye created_utc: 1785663393 edited: false body: "thinking",Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
3 new Reddit comments were posted, including Crazy__Donkey,No-Newspaper8600,hrad95.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 69 lines
"Oh this is easy! \*Does 0 research.\* Grabs a popular chip and installs some libraries off git. Call this function and call that function and bam. There it is, the final product and it only took me a few days to make!" What do you mean TRNG? What's that? I don't need it! See it works fine! Entropy? What's that? I called Random(), so the result must be! - -comment: p189g94 -parent: t1_p188hon -author: Level-Set5770 -created_utc: 1785665690 -edited: false -body: -You just don't get it, do you? - -With closed source, you have: - -* A few dumb monkeys + A couple of god-tier AI programmers - -With open source, you have: - -* More dumb monkeys + The same couple of god-tier programmers - -The additional eyeballs the monkeys provide are a rounding error in the age of AI models. They no longer justify the risk of having your source code out in the open. comment: p189klg parent: t1_p189cs8 So this is a case where the code being open source made it less secure? Everyone was thinking that “everyone else” was auditing the code for vulnerabilities. Meanwhile the only ones checking the code were bad actors. -comment: p18on0b -parent: t1_p189g94 -author: snek-jazz -created_utc: 1785672521 -edited: false -body: -With closed source you can't audit what you're running. It could have intentional backdoors. It's a dealbreaker. - comment: p18oqrm parent: t1_p18ecvu author: dempsey1200 edited: false body: OP mentioned that his LLM was trained on june 16th and unconnected to the internet - -comment: p194ihp -parent: t1_p1922vv -author: Aazimoxx -created_utc: 1785678104 -edited: false -body: -Sounds like your company has made a decision to accept inferior review processes then? A decision that can have legal implications, depending on what your software is responsible for... comment: p194j8j parent: t1_p1945t4 body: In a way it's a good heads-up. We can no leverage AI to audit our own buggy code. No wonder every token is being run past Claude to check for vulnerabilities. +comment: p1m4xk8 +parent: t1_p18rp2b +author: Crazy__Donkey +created_utc: 1785834146 +edited: false +body: +may i ask, and i have ZERO vlue in the area, crypto, seed generating etc (had a crypto ride a few years back, gor burned hard, and stepped away for good). + +assuming they issue a firmware update, the user's current key is still compromised, isnt it? + +if they say "you need to generate a new address", than they admit the exact flaw.... so why I, as a user, create a new seed with their updated firmware and not with a new company's uncompromised hardware? + + +and on a more serious note, why those cold wallets are safer than a seed generated by online wallet like meta mask etc? + +comment: p1mvnve +parent: t1_p18e9m0 +author: No-Newspaper8600 +created_utc: 1785845401 +edited: false +body: +Outsource to Pakistan + +comment: p1n9jvx +parent: t1_p18ekrz +author: hrad95 +created_utc: 1785849732 +edited: false +body: +So you mean, instead of using Trezor or Ledger's seed phrase generation, we should make our own? Like by rolling dice or something and picking words out of a corresponding book? + more-stub: parent t1_p19a2fb count 2 +more-stub: parent t1_p1922vv count 1 + more-stub: parent t1_p185wl3 count 5 more-stub: parent t1_p18d317 count 4 more-stub: parent t1_p188w2f count 11 -more-stub: parent t1_p189g94 count 12 +more-stub: parent t1_p188hon count 14 more-stub: parent t1_p185uzk count 14Extracted text as captured
post: 1vddeuy author: Impressive-Gene-421 created_utc: 1785662370 title: Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes body: It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code. [Also on GLM 5.2 (trained 16th June, no internet access).](https://www.reddit.com/r/Bitcoin/s/5x8CBk8Csk) comment: p1848pg parent: t3_1vddeuy author: TeaSipper007 created_utc: 1785663020 edited: false body: Can you do the same for Seedsigner? comment: p184hcb parent: t3_1vddeuy author: Dry_Mortgage_4646 created_utc: 1785663142 edited: false body: 😢 comment: p184nnw parent: t3_1vddeuy author: Powerful_Quarter691 created_utc: 1785663232 edited: false body: This was def preplanned and in the works for quite some time, since attackers knew that draining the wallets will alert everyone and once they start they will be in the race against time. But I agree with the part that someone with little to none knowledge could have also performed this attack, probably even attempted once the news was out. comment: p184yqj parent: t3_1vddeuy author: fanfanye created_utc: 1785663393 edited: false body: "thinking",Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Three comments and their subthread (frankster p18ac4g, Level-Set5770 p18bgi4, frankster p18g2ma) disappeared from the thread, three new comments were posted (Either_Display_6624 p1kg6wz, Shepinion p1lcxyy, djscoox p1lmvzg), and the more-stub reply count under t1_p189g94 rose from 4 to 12.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 56 lines
edited: false body: Funny thing is with this IC they even give you premade functions packaged with a pretty nooby GUI to configure the hardware. It's awful but it's enough to demonstrate the isolated capabilities of the chip. It seems even just copying that tool generated code and gluing it to theirs was too much hard work for them! - -comment: p18ac4g -parent: t1_p189g94 -author: frankster -created_utc: 1785666132 -edited: false -body: -If closed source meant this bug took another 10 years to uncover, think how much more would have been stolen from the wallets when they were hacked comment: p18aei5 parent: t1_p185x67 body: It does find a lot of faulty code and backdoors anywhere, that's for sure. It doesn't do it unprompted so you still have to point it at a codebase. -comment: p18bgi4 -parent: t1_p18ac4g -author: Level-Set5770 -created_utc: 1785666688 -edited: false -body: -If Coldcard had been closed source, the bozos at Coinkite could've at least had a chance to run the AI models themselves before anyone else even knew the bug existed. - -What's changed is that AI has become incredibly good over just the last few months, and not everyone has realized this. Coldcard's shitty code was just sitting in the open, so some random person fed it into Claude before Coinkite ever had a chance. - comment: p18bkyp parent: t1_p1877qg author: harvested edited: false body: No, AI is actually very good in finding such things. (In fact any dev worth their salt should have found it during testing. Which is why I’m torn between “worst dev in history” and “deliberate backdoor”) The wallet dev just never bothered to run audits with frontier models. - -comment: p18g2ma -parent: t1_p18bgi4 -author: frankster -created_utc: 1785668852 -edited: false -body: -Why haven't coldcard run scanning tools already and detected the bug? This would have been possible for them comment: p18g3r3 parent: t1_p18fsoh body: I went on their website today just to see what was up. They are still claiming it is super duper fucking secure and cutting edge. But at the top is a link about the issues. And they say to update blah, blah, blah... As if anyone is trusting them with their BTC again. GTFOH 😂 +comment: p1kg6wz +parent: t3_1vddeuy +author: Either_Display_6624 +created_utc: 1785808154 +edited: false +body: + claude code was trained on this vulnerability and learned it from the web 😭 + comment: p1krpr6 parent: t1_p1a5nj3 author: quasides body: Less of an AI story than it looks. The model didn’t do anything clever, the randomness was just predictable enough that anyone actually looking would have found it. That’s the part worth being angry about. +comment: p1lcxyy +parent: t1_p18rp2b +author: Shepinion +created_utc: 1785820551 +edited: false +body: +That’s such a good point. Haven’t seen that discussed much. And yes to the people saying it would still be a better situation than what happened. But now I’m generally curious what the best way to handle would be. I would be worried it WAS a scam if I received a message from my cold wallet company that I needed to immediately create a new wallet with a new seed and move all my funds bc the current wallet is compromised…. That’s how every scam email and text and PM sounds…. + +Fascinating + +comment: p1lmvzg +parent: t3_1vddeuy +author: djscoox +created_utc: 1785825206 +edited: false +body: +In a way it's a good heads-up. We can no leverage AI to audit our own buggy code. No wonder every token is being run past Claude to check for vulnerabilities. + more-stub: parent t1_p19a2fb count 2 more-stub: parent t1_p185wl3 count 5 more-stub: parent t1_p188w2f count 11 -more-stub: parent t1_p18bgi4 count 5 - -more-stub: parent t1_p189g94 count 4 +more-stub: parent t1_p189g94 count 12 more-stub: parent t1_p185uzk count 14Extracted text as captured
post: 1vddeuy author: Impressive-Gene-421 created_utc: 1785662370 title: Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes body: It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code. [Also on GLM 5.2 (trained 16th June, no internet access).](https://www.reddit.com/r/Bitcoin/s/5x8CBk8Csk) comment: p1848pg parent: t3_1vddeuy author: TeaSipper007 created_utc: 1785663020 edited: false body: Can you do the same for Seedsigner? comment: p184hcb parent: t3_1vddeuy author: Dry_Mortgage_4646 created_utc: 1785663142 edited: false body: 😢 comment: p184nnw parent: t3_1vddeuy author: Powerful_Quarter691 created_utc: 1785663232 edited: false body: This was def preplanned and in the works for quite some time, since attackers knew that draining the wallets will alert everyone and once they start they will be in the race against time. But I agree with the part that someone with little to none knowledge could have also performed this attack, probably even attempted once the news was out. comment: p184yqj parent: t3_1vddeuy author: fanfanye created_utc: 1785663393 edited: false body: "thinking",Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
post: 1vddeuy author: Impressive-Gene-421 created_utc: 1785662370 title: Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes body: It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code. [Also on GLM 5.2 (trained 16th June, no internet access).](https://www.reddit.com/r/Bitcoin/s/5x8CBk8Csk) comment: p1848pg parent: t3_1vddeuy author: TeaSipper007 created_utc: 1785663020 edited: false body: Can you do the same for Seedsigner? comment: p184hcb parent: t3_1vddeuy author: Dry_Mortgage_4646 created_utc: 1785663142 edited: false body: 😢 comment: p184nnw parent: t3_1vddeuy author: Powerful_Quarter691 created_utc: 1785663232 edited: false body: This was def preplanned and in the works for quite some time, since attackers knew that draining the wallets will alert everyone and once they start they will be in the race against time. But I agree with the part that someone with little to none knowledge could have also performed this attack, probably even attempted once the news was out. comment: p184yqj parent: t3_1vddeuy author: fanfanye created_utc: 1785663393 edited: false body: "thinking",Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
0 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.