r/Bitcoin: LLM tracing for coldcard attackers
reddit-llm-tracing-attackers
https://www.reddit.com/r/Bitcoin/comments/1vi6ify/llm_tracing_for_coldcard_attackers/
Latest reviewed change
source content difference between and
The thread gained a reply distinguishing exploiting a vulnerability from researching one, arguing the evidence does not prove attacker identity.
edited: false
body:
?what
+
+comment: p2ot161
+parent: t3_1vi6ify
+author: area51user1
+created_utc: 1786299299
First lines only. The complete diff is in the timeline below.
- Organisation
- Evidence role
- Community discussion
- Published
- not established
- Source changes
- 1
- Detected differences
- 1
- Unreviewed
- 0
- Copies held
- 2
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
The thread gained a reply distinguishing exploiting a vulnerability from researching one, arguing the evidence does not prove attacker identity.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 10 lines
edited: false body: ?what + +comment: p2ot161 +parent: t3_1vi6ify +author: area51user1 +created_utc: 1786299299 +edited: false +body: +This don't prove anything. + +Exploiting vulnerability != Researching vulnerabilityExtracted text as captured
post: 1vi6ify author: Sensitive-Variety561 created_utc: 1786122593 title: LLM tracing for coldcard attackers body: I’m assuming this is not the case but I had this idea pop into my head and I don’t know what to believe anymore so I figured I’d share. If any of these cold card hackers used LLMs and stupidly used an API key instead of a local / offline model to write the code to sweep the coldcard wallets, couldn’t the inference companies be subpoenaed to identify any users who prompted suspicious things around the time of this attack? Most likely the code was written for a long time prior to the attack by the main attacker but any follow up attacker would’ve likely used LLMs. comment: p2avf8i parent: t3_1vi6ify author: Inevitable-Waltz-889 created_utc: 1786122772 edited: false body: Are you advocating for this? comment: p2avgfp parent: t3_1vi6ify author: rudelysmugalligator created_utc: 1786122780 edited: false body: most of these goons just use stolen api keys anyway so the paper trail leads to some random dude whose aws account got popped. the real pros aren't dumb enough to paste their malicious payload into chatgpt with billing info attached. comment: p2b69el parent: t3_1vi6ify author: LifterNineFour created_utc: 1786125536 edited: false body: So what? Researching and using an LLM doesn’t prove you did anything. Besides, they shouldn’t be ordered to share any user data like that in the first place. comment: p2b6z3r parent: t1_p2b69el author: Sensitive-Variety561 created_utc: 1786125719 edited: falseExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
post: 1vi6ify author: Sensitive-Variety561 created_utc: 1786122593 title: LLM tracing for coldcard attackers body: I’m assuming this is not the case but I had this idea pop into my head and I don’t know what to believe anymore so I figured I’d share. If any of these cold card hackers used LLMs and stupidly used an API key instead of a local / offline model to write the code to sweep the coldcard wallets, couldn’t the inference companies be subpoenaed to identify any users who prompted suspicious things around the time of this attack? Most likely the code was written for a long time prior to the attack by the main attacker but any follow up attacker would’ve likely used LLMs. comment: p2avf8i parent: t3_1vi6ify author: Inevitable-Waltz-889 created_utc: 1786122772 edited: false body: Are you advocating for this? comment: p2avgfp parent: t3_1vi6ify author: rudelysmugalligator created_utc: 1786122780 edited: false body: most of these goons just use stolen api keys anyway so the paper trail leads to some random dude whose aws account got popped. the real pros aren't dumb enough to paste their malicious payload into chatgpt with billing info attached. comment: p2b69el parent: t3_1vi6ify author: LifterNineFour created_utc: 1786125536 edited: false body: So what? Researching and using an LLM doesn’t prove you did anything. Besides, they shouldn’t be ordered to share any user data like that in the first place. comment: p2b6z3r parent: t1_p2b69el author: Sensitive-Variety561 created_utc: 1786125719 edited: falseExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
0 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.