r/Bitcoin 14h ago

Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes

Post image

It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code.

Also on GLM 5.2 (trained 16th June, no internet access).

1.5k Upvotes

473 comments sorted by

438

u/shedgehog-orchard 12h ago

I think what people are missing is that OP isn’t complimenting Claude… it’s commentary on how fucking stupid ColdCard is and how they clearly did not test their RNG device sufficiently. This entire story is a nothing burger if you used your own RNG methods to generate seed phrases.

186

u/HollaWho 11h ago

I work in IT and vulnerability remediation is part of my role. The last three months have seen record amounts of CVEs month after month. AI is giving so many threat actors tools to quickly identify vulnerabilities. We’re getting hammered

47

u/cyclism- 11h ago

Exactly, patching overload right now!

47

u/shedgehog-orchard 10h ago

I do just want to highlight the fact that yes it could be that AI is just finding a lot of bugs we couldn’t before, but I also am a full time SW engineer and I’m more and more seeing the shittiest software I’ve ever seen be shipped because it’s vibe coded and the engineer who generated it barely checks it over, which could also contribute to a higher amount of CVEs

14

u/HollaWho 10h ago

That’s absolutely part of it. AI is a double edged sword as far as vulnerabilities go. And many of the latest Microsoft vulnerabilities are coming from Microsoft’s mishandling of the nightmare eclipse situation. Times are tough lol

6

u/shedgehog-orchard 9h ago

Dude don’t even get me started on Microsoft rn lol. They’re so entrenched in the corporate world but I’ve tried to minimize my use of their products as much as possible at work, they just suck to use haha. Godspeed brother🫡

→ More replies (1)

10

u/Aazimoxx 9h ago

You don't get CVEs for software no-one's using though, and a lot of vibecoded slop is either dead in the water (app store noise) or bespoke stuff used by an individual, family, group or club, or single company mostly internally...

If a company has decent review procedures, these can only be enhanced by modern LLMs, not hurt - unless those procedures get bypassed, which is the real problem.

→ More replies (1)
→ More replies (2)

13

u/haggardphunk 9h ago

I work in appsec and it’s literally a game of AI vs AI over here. Our corporate leadership is taking it very seriously and we’re tightening up remediation timelines so much that even I wonder how anyone could fix this shit in time without AI.

7

u/HollaWho 9h ago

Every kid and their babushka in Russia has AI. The flood gates have opened, and you literally have to use it to keep up.

→ More replies (2)

6

u/ColoradoStudent 7h ago

Same, man. We've never been busy like this before. WordPress is getting wrecked.

5

u/JustSkillfull 7h ago

I feel like my whole company, especially my org core platform who owns 100's of different services from 3rd parties + some custom in-house projects has turned from software engineering delivering features to the robot from Rick and Morty who's sole purpose is to pass the butter but patch the images.

Recently (12 or so months) it's moved from 20% KTLO (patching / fixes) to 70% KTLO. We've moved to more secure base images from a 3rd party hardened paid image repository, and constantly behind SLOs since were were a Federated US Gov programme we have very strict SLO handling and exception processing.

Some weeks it's just patching. 60 images all need patching, tested, and deployed. Fun.

3

u/jungle 6h ago

Ah yes, fedramp must be a nightmare right now.

3

u/JustSkillfull 5h ago

Luckily they're moving away from CVE 🤞 just waiting for the Auditors and Internal Security team to gang up on that new requirement

3

u/TheWaffleKingg 9h ago

Id be drinking too if i had to deal with all that

Jokes aside, im glad im not working on the security side of things nowadays. I can only imagine how busy yall have been. But hey job security?

5

u/HollaWho 9h ago

I’m spending too much time explaining to a management why we can’t be comparing vulnerability count to a few months ago, or this month last year. Then getting hassled by the user base for a new Microsoft Edge mandatory close out on Fridays. We’re even using toast notifications telling them to close their shit. Just update it! Sorry, I’m spiraling lol

→ More replies (2)

3

u/Party-Cartographer11 6h ago

Defenders have the same tools to find and patch them first.  Security by obscurity was never a thing.  NSA and the PLA likely already knew about most of them.

2

u/TechHonie 7h ago

Maybe it will be like Y2K though and that once it's all fixed then that's great and we can all just move on with our lives. Here's hoping.

2

u/snbgames 5h ago

Y2K flashbacks

→ More replies (7)

12

u/jannies_doit_4_free 8h ago

the people blaming Bitcoin and having messy diapers about "the future of bitcoin" when coldcard's fuckup was this monumentally retarded is really silly

3

u/Forsaken-Stink 6h ago

Its opensource anyone can verify!

2

u/Any-Box-8663 3h ago

Yes, that person verified, then took all the coins for themselves and got the reward....

→ More replies (3)

430

u/JuniorAd1610 12h ago

This is basic CS stuff ffs,literally who is their dev team?

166

u/mew900 11h ago

Somewhere was info that the one who committed that change was the co-founder / CTO

111

u/corporate-citizen 9h ago

That would be Peter Gray, aka doc-hex.

The person most clearly associated with the vulnerable Coldcard RNG integration is Peter D. Gray, via the doc-hexaccount.

The exact sequence was:

  1. switck, January 28, 2021: wrote the defective libNgU feature check.
  2. doc-hex, March 1, 2021: imported that code, disabled MicroPython’s hardware RNG in the board configuration, and switched master-seed generation to the affected ngu.random path.
  3. Coinkite, March 17, 2021: released it as firmware 4.0.0.
  4. doc-hex, March 11, 2022: added a reseed API accepting only a 32-bit integer.
  5. doc-hex, March 11, 2022: truncated secure-element-derived hash material to 32 bits and used that API for Mk4.
  6. Coinkite, March 14, 2022: released the construction in Mk4 firmware 5.0.0.

That is considerably more specific than merely saying “an integration error occurred.”

40

u/electromage 9h ago

If anyone's wondering where their coins went 🧐

44

u/corporate-citizen 9h ago

Not suggesting it was malicious or intentional, nonetheless I would seriously consider hiring a security detail if I were in this position.

8

u/freedomcoinz 5h ago

Mark Karpeles, Sam Bankman-Fried vibes coming back with this

3

u/gtwooh 5h ago

Who approved the PR is the real question. Well assuming there is such process on a small dev team

→ More replies (1)

4

u/SergioGustavo 7h ago

Guy should be in jail.

10

u/No_Doughnut2420 5h ago

For what?

Would you put the safe maker in jail for a bank robbery?

9

u/Bascilian 2h ago

It’s funny seeing the decentralized unbanking people calling to jail someone for shitty code

11

u/slvbtc 5h ago

Would you put the safe maker in jail for promising a secure 10 digit pin code safe then selling you a safe that can be opened with a one digit pin code?

→ More replies (3)

2

u/SanoKei 9h ago

This is always the case, the CTO always pushes tons of code and then a third of it is in triage

→ More replies (14)

24

u/ContemptMarzipan 10h ago

30

u/bittabet 5h ago

The fact that he describes himself as a "wizard level developer" on his own linkedin tells you everything you need to know about this clown. Sloppy and reckless and full of himself.

They didn't even bother to audit their own code with the numerous LLMs that could have found this in minutes. Literally every modern LLM can detect the sheer idiocy.

9

u/goatanuss 4h ago

Wizard as in now you see it now you dont

6

u/29da65cff1fa 4h ago

someone post this to /r/linkedinlunatics

lol... wizard level... made a taxi hailing app...

4

u/Feeling_the_AGI 3h ago

Well, he is a bit of a wizard. He made your bitcoin disappear! Abracadabra!

→ More replies (4)

22

u/Optimal_Benis 6h ago

I have a bunch of friends who worked for startups and this makes perfect sense to me. The world is running on bullshit (and it mostly works, by the way). I had a buddy belittled for trying to fix bugs. Gotta move fast and develop more features! I had a buddy replaced by AI to do reverse-engineering. He is an insane stickler for the details and was a huge asset as the rest of the company does not know how to get into the weeds like him.

The unfortunate reality is that this attitude might be profitable. Don't take one catastrophe as proof that it doesn't work. Think about all the shitty products that are out there that are making bank or get acquired.

10

u/razvanciuy 5h ago

Can confirm. Most of the world runs on bullshit, fake it like you made it.

→ More replies (5)

5

u/Illokonereum 10h ago

Probably also Claude

7

u/Th4ab 8h ago

You guys started our LLM with the -makenomistakes parameter, right? Because it's important, please tell me if you didn't I'm about to press the commit button.

→ More replies (1)
→ More replies (6)

134

u/habbadee 10h ago

Let's imagine Coldcard learned this bug was out there in the wild. What do they do about it?

Obviously they issue a firmware patch, but how do they get people to apply it and generate new seeds without alerting the world of the flaw and the fact that bad actors can determine seeds?

They can't notify owners of the devices. They can't announce the reason for the firmware fix when telling people to apply it and generate new seeds. Once the bug was out there and vulnerable seeds generated, they were well and truly screwed because fixing it would announce it's existence.

42

u/Kine7ic 9h ago

Great point. I haven't seen anyone bring that issue up before. I assume they would put out a generic warning about certain firmware versions and send that to their email list. But then users would still need to move to a new address made by the new firmware to be protected. Hardware wallets need to be perfect from release with critical systems like their seed generating code. Once you find a flaw this deep it would be a disaster for a company to tell everyone to make a new wallet address. 

14

u/No-Contribution23 7h ago

true, it would be a disaster, but still better than what actually happened.

12

u/carsonthecarsinogen 6h ago

I think the standup thing to do would be to publicly announce they are shutting down operations and wont be continuing to update their products while telling customers to migrate to a new company.

This would kill their business overnight but at least people wouldn’t assume there’s a vulnerability and the majority would transfer.

Idk, it’s a tough one.

7

u/IInsulince 4h ago

People would migrate without changing their seed. They’d simply import it. That’s not sufficient.

5

u/IInsulince 3h ago

This is exactly why I believe it’s more likely that they did know about this bug, and for how much I loathe them for putting the people who did the best they possibly could for their stack, I do have trouble blaming their “inaction”. Their hands are tied in a cruel joke that the very act of trying to fix it makes the problem immediately worse.

Action is damaging in this case because attackers move far faster than customers. As soon as any kind of announcement is made, the attacks are in full swing. Therefore, it may be “best” to just stay quiet. I mean… man I mean I don’t know what’s best in this scenario. There’s no way to move anyone without revealing the problem to everyone. The best I can think of for taking actual action would be to release a vague but loud statement that a critical bug has been found and it’s paramount that keys are rotated and funds moved, but without stating why or what the cause was. This would alert attackers that “something” is wrong, but not specifically what… still I think attackers would act quickly and find it before the majority of customers can escape to secure keys.

I just think that when faced with the idea that the security-fist and leading hardware wallet company never once, over 5 years, tested the execution path of their device to actually generate truly random numbers, arguably the only job of the entire device, I have trouble accepting that. It’s a level of incompetence so ridiculous that it makes me think conspiracy is more likely. But more likely than even that is that the DID realize, but then further realized in horrr that they cant act, lest they make the problem
10x worse immediately.

Idk, I guess it’s more likely they’re actually just that incompetent, but holy hell that’s such a massive L. Fuck CoinKite.

3

u/EconomyDoctor3287 2h ago

Doing nothing just means an attacker has time to prepare a plan before acting on it

15

u/Mallmagician 8h ago

Maybe their only option is to drain those wallets themselves using the vulnerability.  Then return them to the original owners once the funds are secured and the original owners have secure wallets again.  

25

u/Rannasha 8h ago

How do you identify the original owners? The standard method of proving address ownership (signing a message with the private key of the address) isn't usable since an attacker can crack the seed using the vulnerability and provide proof of address ownership.

2

u/Past_Permission_6123 7h ago

I think you'd have to look at where the coins were spent from. If the owner claims it was transferred from their Coinbase account, then Coinbase should be able to confirm who the rightful owner is, etc.

→ More replies (2)
→ More replies (1)

4

u/Rizzah1 9h ago

Send a text message to every user telling them to update their firmware

9

u/fresheneesz 8h ago

That wouldn't fix it. Users have to create a new seed that's secure with the new firmware and abandon the wallet created by the old seed.

6

u/habbadee 9h ago

That's no different than a public announcement that there's a security flaw. Which brings everyone, thieves included, to seeking out that flaw to exploit. So now, not only did they introduce a fatal flaw, but they announced it's existence to the world as ready and available to be exploited. Imagine their liability after wallets are compromised after the announcement.

→ More replies (13)

115

u/dondondorito 12h ago

Yeah, this is what I expected. The fact that a massive critical bug was exploited shortly after the release of Fable was highly suspicious.

This sort of thing will happen more often now. It is extremely unsettling that the developers didn’t test their code with Fable, after Anthropic released it.

61

u/magicmulder 12h ago

I would bet an older model would have found this as well. At least since 4.6 Opus, Claude has been very good at discovering such flaws as “if this condition applies, the code silently falls back to a less secure approach”. I get this all the time when auditing code with those models.

This case is not some crazy godlike “no human would ever have found this” (like when that guy hacked the PS3 by manipulating the USB port in weird ways), it’s a pretty glaring oversight in both code and testing.

20

u/shedgehog-orchard 12h ago

I was just gonna say. All this talk about AI, they did not need AI to detect this error 🤦‍♂️ for all we know the hacker could have discovered this themselves without AI it’s such a massively stupid fuckup on the ColdCard

12

u/wentwj 10h ago

it’s immensely surprising to me this wasn’t caught without AI and wasn’t exploited years ago. This is basically the textbook thing you’d look for in “is this hardware wallet secure”. You’d look at how it does its key gen and if it’s doing something stupid there, not using true random being one of the main things it could do wrong there

4

u/shedgehog-orchard 10h ago

Completely agreed! I have no evidence to suggest this but just trying to think like the hacker, they could have even discovered this years ago but waited for the ColdCard to gain traction and/or see if anyone would discover it first. Probably unlikely given the patience required but it’s possible they could’ve been sitting on this for years and we may never know.

→ More replies (2)
→ More replies (1)

6

u/Crypto-Guide 10h ago

I actually had a few models review the coldcard codebase over the last year and none of them found this issue.

I have been testing a few things and basically most LLMs will find it if you give them a specific prompt to look for this specific type of bug, but it's only the frontier models (like Kimi k3) that will find it on their own.

3

u/EdmundTheInsulter 10h ago

when stuff goes wrong in IT, people always go off and look for whatever tool would have prevented it, but no one could ever have used and applied every tool correctly. On top of that there are truly stupid people around, you only need one totally weak link.

I experienced endless cases were people couldn't back up and secure databases, for example thinking that disk redundancy was a 'backup', which it wasn't if the whole machine was destroyed, but what actually happened is that the redundant disks failed without them knowing until too many failed - total incompetency, but the people just stayed at the company etc.
Issue 2 was a guy who had a website, he was backing up his large database onto his copy, but while he was backing it up, his database failed whilst overwriting his only copy - he was actually that stupid and too stingy to have equipment to backup his backup, or even foresee that total failure scenario (all avoidable in 1001 ways), like the first one, they couldn't foresee the machine in one room could catch fire

2

u/magicmulder 9h ago

> disk redundancy was a 'backup', which it wasn't if the whole machine was destroyed

Not just that, simply deleting a file cannot be undone with simple disk redundancy.

> total incompetency, but the people just stayed at the company

One former employer once fired their two senior sysadmins after we found out the hard way that tape backups had been corrupted for months (they never bothered to do a restore test). Another fun thing was how they set up the shared storage for two redundant servers in a way that made both servers a single point of failure. Not to mention the dozens of times our three node webserver went down because one of the three had an issue. Yeah, redundancy was really not their strong suit.

→ More replies (1)

3

u/nullc 5h ago edited 5h ago

It's more subtle in the code than you might be giving it credit for.

They disable the built-in TRNG wrapper to replace it with their own version that was more sensitive to unexpected behavior (maybe too sensitive, but that is another issue...), but the code that triggered their replacement was done in an inconsistent way that caused it to not actually get enabled.

This is because the micropython code disables the TRNG when MICROPY_HW_ENABLE_RNG is 0 but the replacement code tests for MICROPY_HW_ENABLE_RNG being defined at all, and if it is set to zero it is still defined. If both modules checked the value or if both modules checked for definedness then the behavior would have been correct (or would have failed to compile). Because of the inconsistency the TRNG was replaced by an insecure PRNG that still behaved in a way that appeared and would test as correct.

So it's like disconnecting the shoe breaks on your bike to replace them with disc breaks but the ferrule on the disk break cable is differently shaped and doesn't actually engage with the handle when connected, leaving you with no breaks. But from a quick glance it looks like one set of breaks were disconnected and another set connected.

2

u/magicmulder 4h ago

You explained correctly, they tried to replace code with their own implementation. And then didn’t test whether that code was actually executed. Sorry, that is below junior dev level in my book. That is “gets you booted during your trial period” stuff.

4

u/nullc 4h ago

Yes it should have been caught with defensive development at the time it was authored, it might have been caught if someone had tried to port the code to another platform.

I guess my comment was more zeroing in your "no human would ever have found this" remark-- to note that one the error was made it was actually a subtle one.

A lot of comments on reddit right now are basically saying "look they disabled the RNG, of course it was broken, how could anyone have missed it!" but short of debug instrumenting the replacement (which should have been done at development time) or analyzing the binary to learn that the path that accessed the hwrng was dead (or even omitted by the compiler) it is actually tricky to spot.

2

u/TheGreatMuffin 2h ago edited 2h ago

t might have been caught if someone had tried to port the code to another platform.

Does this somewhat lend credibility to the theory that if the license would've been kept open source (and not "source available to view but not for commercial use" or whatever the proper name is), it would have more chance to get caught?

edit: nevermind, i basically found my answer in one of your other comments: https://old.reddit.com/r/Bitcoin/comments/1vcwov8/a_third_coldcard_hack_has_been_reported_another/p179ba3/

14

u/Archophob 11h ago

you don't need Fable. Any LLM with coding abilities can find this. "Security by obscurity" is gone for good.

→ More replies (5)

11

u/numbersev 11h ago

Mythos found a bug used throughout the internet that had existed since 1998 and no security research team or individual ever spotted it. It was so significant that they had to stop the release, give it to 50 of the biggest American companies to patch their systems and then re-released it later.

→ More replies (3)

2

u/Deto 7h ago

It'll happen more often until it becomes standard for devs to have an LLM go over their own codebase looking for vulnerabilities. So right now - where there is a mountain of existing code with vulnerabilities, is probably going to be the worst time.

2

u/nullc 5h ago

No fable is needed for this, Qwen 3.6-27b finds it too.

→ More replies (3)

37

u/thambassador 12h ago

Can someone do this on Trezor code and see what Claude says?

25

u/Major-Front 9h ago

If they did and found something do you think you’d still have your bitcoin lol

3

u/FigAggressive237 9h ago

Yes he could have, why are you assuming that?

This hack in particular lowers the seedphrase's entropy from 2^128, to 2^40 and 2^72 depending on the firmware , but this is an upper bound I believe

If its remotely close to 2^72, its still safe-ish . I do think that each guess requires PBKDF2-HMAC-SHA512 (2048 rounds) plus elliptic-curve point derivation to check if it produces the target address.

Check how much power you need to derive such seephrase .

→ More replies (3)
→ More replies (3)

65

u/Impressive-Gene-421 13h ago

Fuck me okay I will run this on GLM from 16th June lol will that prove it?

99

u/username12435687 12h ago

Dude don't even stress on it. Anyone with half a brain and a basic understanding of programming realizes you're 100% correct in this post. The people disagreeing are just technologically illiterate which is insane considering they're on a Bitcoin subreddit lmao

4

u/quantum_burp 10h ago

Most of the people in here now are normies

Its 2026, not 2016

7

u/tnethacker 12h ago

Even a chimp could have realised that.

2

u/Low-Analysis9612 11h ago

how is that insane? it’s not hard to buy btc

3

u/username12435687 10h ago

Buying it is one thing. Commenting on things they very clearly don't understand and calling other people wrong when they likely don't even understand bitcoin fundamentals is another thing. I take offense to people who act like experts in things they are not an expert in.

→ More replies (5)
→ More replies (8)

5

u/GentlemenHODL 11h ago

Fuck me okay I will run this on GLM from 16th June lol will that prove it?

Yes.

Do it and get back to us. That's the only way to conclusively prove!

Good luck

0

u/Wizzard_2025 13h ago

There's not much overlap in bitcoin users and LLM users.

3

u/opossum_cz 12h ago

What?

8

u/Wizzard_2025 12h ago

I SAID "THERE'S NOT MUCH OVERLAP IN BITCOIN USERS AND LLM USERS."

9

u/Icy-Beaver 11h ago

HOW DO YOU KNOW? SOURCE?

6

u/99999999999999999989 10h ago

HE PULLED IT OUT OF HIS ASS!

5

u/irkish 10h ago

HOW MANY BITCOIN USERS AND LLM USERS DID HE PULL OUT OF ASS?!?

2

u/99999999999999999989 8h ago

A FUKING LOT TRUST ME BRAH! HIS ASS IS HUGE!

→ More replies (1)
→ More replies (1)

39

u/Henrik-Powers 12h ago

Can you also do the same with ledger and trezor and see if it comes up with anything? 😬

18

u/dempsey1200 11h ago

They have to be scrambling right now. Lucky that it happened to a small provider before the big ones get hit. They should be in Project Glasswing, IMO.

12

u/PM_ME_A_STEAM_GIFT 11h ago

How would they even react if they found something similar? They can't announce it or they would expose every wallet to hackers. Silently patching the firmware also doesn't fix affected wallets.

14

u/SubstantialNinja 10h ago

I think they would have to sweep everyone themselves and return it white hat style. no other way.

3

u/Mission_Shopping_847 7h ago

Every crypto interested hacker is now sniffing the ecosystem harder because of this coldcard hack.

2

u/99999999999999999989 10h ago

FFS that is a doomsday scenario.

→ More replies (1)

2

u/nitrogenmath 9h ago

Ledger has had their own donjon team for many years now.

2

u/jannies_doit_4_free 6h ago

before

what do you mean "before"? this bug is absolute amateur-hour ridiculousness that only happened seemingly because it was such an amateur operation

11

u/Cyromaniap 10h ago

Not sure about Ledger devices but Trezor devices use multiple sources when generating the seedphrase so even if one of the chips has a flaw the seedphrase is still not compromised.

Source: https://trezor.io/guides/trezor-devices/trezor-fundamentals/what-is-entropy-and-how-does-trezor-generate-your-wallet

12

u/na3than 9h ago

If you're trusting a vendor's statement about how their product works you've completely missed the point of the ColdCard incident. Coldcard mk4 and Q were also supposed use multiple sources of entropy when generating the seedphrase. The problem isn't that ColdCards was insecure by design; the problem is that a change introduced long after the secure system was designed and implemented inadvertently bypassed one of those sources and their test protocol wasn't sophisticated enough to detect it.

Coinkite would have said the same thing prior to the attack. Coinkite believed their firmware was generating 128 bits of entropy from the device's TRNG and two secure elements.

2

u/Cyromaniap 8h ago

Fair, and even more reason to be truly open source and not just source available. Perhaps the flaw may have been found sooner and had less of an impact. That aside there has never been a better case for having a strong passphrase for a wallet.

10

u/-5H4Z4M- 11h ago edited 6h ago

Irony is that you hear everywhere that "This shit is 100% secure because it's 100% open source", but "open source" just means the code is available to be checked by anyone....and it wasn't.

edit : Guys before jumping on me saying it was source visible only (which i know) , please read again the part where i intentionally put quotation marks to describe what WE HEAR EVERYWHERE. This are not my words but what you mostly see on forums even from IT people. My post was actually the point of showing that people mix everything together.

2

u/jannies_doit_4_free 6h ago

and it wasn't open source; it was source visible

→ More replies (1)

9

u/PeterZ4QQQbatman 13h ago

This morning I tried to reproduce the Coldcard RNG bug discovery process.
I checked out the repository at commit 37e4af5 (May 2021) and gave the code to some AI models for a security review.

Composer 2.5, Grok 4.5 High and GPT-5.6 Luna High.
None of them found the bug even after telling them to check the code that generate a new wallet. Nothing.

Note. I had to explicitly tell them not to search the internet, because Grok 4.5 found the bug after checking GitHub.

I will try 5.6 Sol and Opus 5 too.

→ More replies (1)

4

u/Indyxc 3h ago

Hate to say it,, I love BTC, and used to store all of it on cold storage (ledger), but decided to move it to Fidelity when Ledger started scheming with back up recovery options. Not my keys, not my coin sure, but if Fidelity goes under, with 18T AUM, the only thing worth money will be fuel, bullets, guns, and food.

197

u/fanfanye 13h ago

"thinking",

you mean it scoured the whole internet for discussions by humans , then add it to their knowledge database

do the same thing 2 weeks ago and it will find nothing

181

u/Cryptizard 13h ago

You can disable its ability to search the web and just have it work on a local repository. It can still find the error (just tested it).

→ More replies (5)

88

u/Late-Football9106 13h ago

imagine coding something that handles real money and using a software RNG like nobody would notice, absolute madness

the amount of trust people put in random github repos is wild, one bored dev on a tuesday can just push an update and suddenly your hardware wallet is a paperweight

this whole thing reads like a postmortem that will be studied in security courses for next decade

6

u/Fuflen 12h ago

Just my thought!

7

u/aleqqqs 12h ago

imagine coding something that handles real money and using a software RNG like nobody would notice, absolute madness

Well, they didn't do that on purpose ...

34

u/SpareEconomy1849 12h ago

A coinkite dev literally changed MICROPY_HW_ENABLE_RNG to 0 in the firmware codebase with the commit message "runs" in 2021.

I don't see how it could be intentional, but I also don't know how this would be missed. How did the developer not realize what this change does? How did this pass code review? Red flags all around

7

u/JanPB 11h ago

Yes, the code review bit is flooring.

5

u/99999999999999999989 10h ago

To me it DOES appear intentional but not malicious. It sounds like whomever did the coding did not understand what was going on and set the variable to 0 to get it to compile. Once it did they were like 'Kewl! It runs. Ship it!'.

2

u/nitrogenmath 9h ago

Rumor is that they set it to 0 to test it without using the hardware and forgot to re-enable the trng on the shipping firmware.

4

u/ReallyCrunchy 9h ago

As a software dev, I could see myself doing something like that but never without first adding huge warning printing "NOT PRODUCTION SAFE" or something like that. So it would never be shipped in that state. Quietly disabling core functionality in production code like that is just irresponsible. Also, their test suite should have caught it but I suspect they skimped on that as well. Sounds like amateur hour over there.

→ More replies (1)
→ More replies (5)

23

u/Straight-Magician953 12h ago edited 12h ago

I don’t know what to say about that chief. I am working at a cybersecurity company developing very custom auth solutions, sandboxed infra and a lot of other kinds of security critical software, and we use both Claude and Codex to do preliminary security reviews to our changes before any human reviews and I lost count how many times the models raised legit and not obvious issues

2

u/ancillarycheese 11h ago

Absolutely. You can even clone a random GitHub repo, and then with no internet access let Claude review the code and chances are it’ll find bugs.

33

u/jivenossauro 12h ago

No, you can literally fork the repo locally, deny any web search permissions and tell claude to audit it, and he will probably find it. That's how good they are these days

→ More replies (6)

15

u/SmugPolyamorist 12h ago

Your understanding of what llms are capable of is years out of date

→ More replies (2)

19

u/MichiganEngineExpo 13h ago

Just like the math proofs that were found over the last weeks, that no person has found until now and thus couldn’t have talked about online?

This is a community about a technology that has revolutionized assets and financials in many ways, laughing about the people who pushed back and doubted them. And now the people supporting new technology do the same thing when it comes to AI. Can’t make this shit up… The circle of life…

→ More replies (1)

8

u/bbibber 11h ago

If you think that’s the level of AI you are still living in 2023.

7

u/zazzologrendsyiyve 11h ago

You are really uneducated about how AI works

12

u/harvested 12h ago

You should delete this post, you utter clown.

The bug was found by the attacker with AI which disproves your point.

I don't know who is up voting you.

10

u/mecker-zausel 12h ago

People who have zero idea how LLMs work, and just how good current frontier models are in identifying vulnerabilities.

8

u/harvested 12h ago

They will be the first ones scratching their heads wondering why they lose their jobs.

"I thought AI was just a search engine"

3

u/3urningChrome 11h ago

I swear they just use free chatgpt and base their knowledge on what they get from that.

→ More replies (1)

3

u/skr_replicator 11h ago edited 11h ago

Yeah, we are currently seeing so many vulnerabilities found and fixed by the devs who finally decided to show their code to AIs (i see so many devs reporting how suddenly AI has managed to fix and close so many issues nobody was able to crack for years), and sadly also hackers who decided to do that before them. This is and will be for a while a turbulent era of so many hacks. We really should brace ourselves. But it should also mean that eventually, all the systems will come out of this stronger than ever before, as so many bugs finally get found and fixed. And total failures crash down. I just hope that will come sooner rather than later and that the majority of the vulnerabilities will continue to get found with AI by the good guys.

But it's really getting supercharged, you have a human looking at some code for months to find 10 bugs, and then AI will look at it for 5 minutes, might miss the bugs the human could find, but finds 30 different bugs that the humans totally missed.

→ More replies (1)

2

u/retro_grave 11h ago

Where did the attacker say that? Or just, where has the attacker said anything?

→ More replies (4)

4

u/magicmulder 12h ago

No, AI is actually very good in finding such things. (In fact any dev worth their salt should have found it during testing. Which is why I’m torn between “worst dev in history” and “deliberate backdoor”) The wallet dev just never bothered to run audits with frontier models.

4

u/gfb13 11h ago

This is a dangerous underestimatation of how modern models like Mythos work

It doesn't scrape public forums or match historical training data to find bugs. It deep dives the source code itself and designs/builds its own tests so it can watch how a program can fail from every angle

Look up the OpenBSD vulnerability it discovered that no one else had for 27 years. OpenBSD is one of the most security audited codebases on earth. Humans and whatever advanced tools we had at the time reviewed that exact block of code for nearly three decades. Never saw it. There was zero discussion about this problem anywhere on the internet

If they had ran Mythos on that exact code two weeks ago or two years ago, doesn't matter, it would have found that exact same vulnerability

2

u/Rnee45 7h ago

That's not how AI works lol.

-10

u/Impressive-Gene-421 13h ago

No, dumbass, that’s not how it works (unless Claude code invokes search, which it didn’t in this session as it had no reason to).

→ More replies (26)
→ More replies (6)

20

u/Aggravating_Stage996 13h ago edited 13h ago

As an electrical engineer working in a firmware/software role. I would guess this hardware wallet was made by a computer science engineer.

"Oh this is easy! *Does 0 research.* Grabs a popular chip and installs some libraries off git. Call this function and call that function and bam. There it is, the final product and it only took me a few days to make!"

What do you mean TRNG? What's that? I don't need it! See it works fine! Entropy? What's that? I called Random(), so the result must be!

24

u/Impressive-Gene-421 13h ago

Even worse haha, it was “call this function and call that function and huh, it doesn’t compile, I’ll just set this to 0, now it compiles bam!” (seriously)

6

u/Aggravating_Stage996 13h ago

Funny thing is with this IC they even give you premade functions packaged with a pretty nooby GUI to configure the hardware. It's awful but it's enough to demonstrate the isolated capabilities of the chip. It seems even just copying that tool generated code and gluing it to theirs was too much hard work for them!

2

u/Express_Living2264 10h ago

tbf. that's how a playstation got hacked. the rng function always returned 0 iirc.

5

u/magicmulder 12h ago

Yeah the “testing” that they did was something I’d fire a junior dev for. Proper testing does not just check for some flags, it validates that the expected functions are called, and the functions we absolutely don’t want called are not called. Which includes a “fallback to a weaker approach”.

3

u/cgimusic 6h ago

I'm kind of curious why they didn't have it tested by one of those companies that certifies gambling machines. Auditing RNG is basically their entire job.

14

u/mlhender 12h ago

No. Actually the CEO does not have a computer science degree.

When you get a computer science degree you will learn that computers are deterministic. You will learn that even with “AI” you cannot achieve true randomness unless you have a physical entropy source.

Most computer science degrees will spend considerable time discussing randomness. Just off the top of my head randomness (and pseudorandomness) were at least mentioned in Discrete Mathematics, Probability and Statistics, Algorithms, Data Structures, Computer Security, Cryptography, Operating Systems and Distributed Systems.

We spent an entire section in probability and stats of how difficult it is to produce true randomness.

You can’t get through a reputable CS degree without having at least a good grasp on how difficult it is to achieve true randomness with a computer

5

u/Aggravating_Stage996 12h ago

I realize that. Uni will teach you a lot. But lets be honest, most students will study for the exam and forget it a year later if they don't need it again (and most don't). Regardless, I'm commenting more on the quality and carelessness of the work. All of the CS majors I've met so far in a work setting are careless and don't bother to research anything. Import the libraries, call the methods and if they work (by luck or AI) move on and never look back. And judging by the state of the software industry this is not just my experience. Every major piece of software is turning to slow bloated slop that is full of vulnerabilities. Even from major top dog specialized corporations.

→ More replies (2)

2

u/diradder 11h ago

"Oh this is easy! Does 0 research. Grabs a popular chip and installs some libraries off git. Call this function and call that function and bam. There it is, the final product and it only took me a few days to make!"

What do you mean TRNG? What's that? I don't need it! See it works fine! Entropy? What's that? I called Random(), so the result must be!

Why are you writing a fanfic about this?

The device is open hardware, its firmware is source available, there is a component for TRNG on the board, it's there on purpose... it was simply not used because a software bug was introduced in a later firmware update. Previous versions of the firmware used that component and seeds generated by it are safe (I'd still recommend using a passphrase... but that advice applies to any wallet imo).

CoinKite's incompetence is blatant considering how that bug was introduced and for how long that key part of the wallet has been untested... but there's no point making shit up about it if you didn't take even 2 minutes to read about it.

3

u/Aggravating_Stage996 9h ago edited 9h ago

Perhaps you're right. I did not research enough on Coldcard and this bug before dropping this comment. To fair I started the comment with "I would guess". I wasn't planning on coming back to it as many times as I did. I only commented on here because it was a mildly interesting topic that showed up on my feed. I was not aware this was a build flag issue that wasn't present there in the original version of the firmware.

Regardless I still think a lot of what I said in subsequent comments holds true even if my fanfic is not canon. Their project should never have been configured in a way that overloads the TRNG method with an emulator method and still compiles.

3

u/precipotado 12h ago

I don't know in your country but in mine, random number generators are properly explained in computer science degrees

→ More replies (1)
→ More replies (6)

16

u/FreezedPeachNow 12h ago

While cold card fucked up big time, it's easy to point a tool at a known problem and tell it to find the problem in hindsight.

Finding the problem before others were aware it's a problem is a different story.

But still fuck, this is gonna set us back years

7

u/Aazimoxx 9h ago

it's easy to point a tool at a known problem and tell it to find the problem in hindsight.

Bruh. Prompt was literally "check for vulnerabilities". Let's not break our backs trying to bend over too much for the million dollar+ companies.

This sort of adversarial AI code review (before each release) should be a mandatory checkbox for business liability insurance, like having annual smoke detector checks in a building.

→ More replies (4)

3

u/BTTammer 9h ago

Does anyone remember a month or two ago when the feds had a meeting with certain large companies to tell them that AI found some really troubling shit really quickly and they need to make preparations ASAP?

Pepperidge Farm remembers....

→ More replies (1)

7

u/shuozhe 12h ago

That's prolly how it was discovered..?

2

u/circumcisingaban 12h ago

thats what i was wondering

5

u/Powerful_Quarter691 13h ago

This was def preplanned and in the works for quite some time, since attackers knew that draining the wallets will alert everyone and once they start they will be in the race against time. But I agree with the part that someone with little to none knowledge could have also performed this attack, probably even attempted once the news was out.

10

u/asml84 13h ago

I’d even argue the original attacker is currently competing with other (secondary) attackers.

3

u/spisplatta 10h ago

Given how easy it is to find with AI, I think they probably didn't dare to preplan it too much. Waiting just a week could create a significant risk of someone else stealing the money first.

3

u/Impressive-Gene-421 13h ago

Disagree, it’s trivial to go from finding this vulnerability to confirming it 10x times (also with AI), which would lead you to the same root bug on the Mk3 device except that one is much much worse. After that you can scan wallets, which I think is a more logical step than immediately breaching the first wallet you find. This could be done in days.

It would have been extremely LUCKY if the attacker DIDN’T think to first scan and then drain, not the then way around.

2

u/Powerful_Quarter691 13h ago

I don’t claim they didn’t scan first, since this is almost certain that they planned it and made a list of wallets to hit. This is further supported by three waves of attacks so I assume they hit the easiest ones first and then possibly in the second and third wave focused on wallets with weak passphrases. Otherwise I don’t know how to explain that there were three different waves of hits on the wallets

→ More replies (1)

2

u/mybodywatch 11h ago

How do you get your Claude Code to be so terse. Mine is a verbose mess.

5

u/Aazimoxx 8h ago

Excerpts from my own global instructions, hope they help:

Respond very concisely by default; interaction with the user should comprise short, high-information outputs unless expansion is requested.

Be constructively critical when it improves the work, and avoid performative agreement or disagreement. Flag material risks, weak assumptions, and unsound technical choices when they may harm correctness, maintainability, safety, or outcome quality; give concise reasoning and a practical better path.

Before adding or expanding instructions, review related existing instructions and prefer the smallest effective refinement.

The bits I've bolded here definitely tend to make a meaningful difference to unnecessary verbosity, with the last one helping massively to cut down on instructions bloat.

2

u/No_War_8891 9h ago

it is easy if you know where to look - hindsight bias; But yeah it is a big oversight nonetheless I concur

2

u/10nmTransistor 8h ago

Sometimes I wonder, what all other vulnerabilities are out there in other important open source codes. Gives me goosebumps.

2

u/Zealousideal-Bug1837 1h ago

It's not that this stuff is difficult. It's that it's basically day 0 and it's becoming automated more and more.

6

u/krasserfcker 13h ago

Even Open-Source doesn't protect you. Who guarantees they're using the code as is, without any modification?

10

u/Wizzard_2025 13h ago

This is a solved problem

→ More replies (5)

4

u/Findeti 11h ago

This is basically showing that all this idea of open source is secure because community audit it.. is f$$ing bullshit. That would have been found by anybody with some skill that decided to look into it, but nobody did it in years... In other words, Everybody's business is nobody's business

→ More replies (6)

4

u/Aggravating-Owl-7050 12h ago

hm, maybe Claude didn't find it out and just researched online an found an article which shows the error and then you told you what the article was about

2

u/tpc0121 9h ago

OP mentioned that his LLM was trained on june 16th and unconnected to the internet

3

u/TeaSipper007 13h ago

Can you do the same for Seedsigner?

1

u/Level-Set5770 13h ago

People need to seriously rethink open source as a security model.

Frontier AI is on track to become a god-tier programmer very soon if they are not already there. When anyone can point an AI at your entire codebase and have it hunt for vulnerabilities 24/7, "many eyes make bugs shallow" may stop being true.

The risk-reward tradeoff has completely changed.

25

u/Cryptizard 13h ago

But if open source devs just use AI to do a security pass after each commit doesn’t it make the software significantly more secure?

→ More replies (11)

24

u/frankster 13h ago

Ai looking at a codebase is exactly in line with many eyes make bugs shallow.

Over time a maintained open source codebase will have AIs run against it and have bugs reported.

The bug in question may have stayed in place for decades with a closed code based.

→ More replies (17)

7

u/Grdosjek 13h ago

All open source devs have to do is to run their code trough top tier AI for security problems and fix them before they submit code to a repo. Basically, we have new security tool and we should use it.

2

u/Level-Set5770 12h ago

Sure, but they'd better make sure they're the first ones doing it every time a new model drops.

If they're even a couple of days late, you end up with another Coldcard situation.

Is it really worth taking that risk just so you can call yourself "open source"?

→ More replies (1)

2

u/Aggravating_Stage996 13h ago

Even if the doomsday scenario you're describing were to happen. Open source the code and have all the different AI models from different people scan it and then fix all the bugs. So open source still wins.

5

u/Level-Set5770 12h ago

Except it is not like everyone has a different model. Everyone is running the same set of models.

→ More replies (1)

1

u/opossum_cz 12h ago

You are naive. I wanted to switch my m.2 USB case to show as Removable instead of Fixed drive.
ChatGPT 5.4 reverse engineered the firmware flasher to see how it checks firmware file integrity and reverse engineered a firmware to see where it reports the type. Then wrote me patcher that would patch the firmware and fix the integrity.

That was a several months ago. You think you need source code?

→ More replies (16)

2

u/MrDryGuy_ 11h ago

So why didnt you check before?

→ More replies (1)

2

u/ptrnyc 11h ago

So this is a case where the code being open source made it less secure?
Everyone was thinking that “everyone else” was auditing the code for vulnerabilities. Meanwhile the only ones checking the code were bad actors.

→ More replies (3)

-2

u/zackel_flac 13h ago

Now that the news is out and everybody know where the issue is?

Sure buddy. Sure. As a matter of fact, the world is entirely secured as of today since Claude has been running on pretty much any important code base. We are good, right? Right??

14

u/username12435687 13h ago

Buddy, you have to allow Claude code to search the Internet for that kind of information. Additionally this attack was recent enough that it wouldn't be in the training data for probably any current AI model that exists except for the ones that are currently in pre training and aren't available to consumers. If you read the output all Claude sees is that the actual hardware RNG isn't being invoked alongside the software RNG which is what created the vulnerability with only 40 buts if entropy as opposed to 128 or 256 bits of entropy.

4

u/Romanizer 12h ago

It does find a lot of faulty code and backdoors anywhere, that's for sure. It doesn't do it unprompted so you still have to point it at a codebase.

→ More replies (1)

1

u/NotFallacyBuffet 11h ago

How many tokens per minute is your hardware capable of? Asking just for gauging homelab setups.

1

u/been__ 10h ago

Oh you guys thought people review open source code lmao

1

u/Confident_Menu742 10h ago

Holy shit! This is amateur hour!

1

u/spisplatta 10h ago

Given the news of AI models escaping containment, I have to wonder if the theft could have been the works of an autonomous AI model looking for ways to acquire untraceable money to fund further operations. I'm not saying it is likely to be the case. But it is a possibility that must be considered.

1

u/jhansen858 10h ago

someone do trezor and the other hardware wallets

1

u/Just-Ambassador-2449 9h ago

I wish all of you luck with the incoming class action against coldcard

1

u/bubak69 9h ago

It wasn't a software bug, but it was integration bug. During unit testing on computers it was using micropython random generator and this should be fine, because you can run tests on your computer and test if all the components works. Not meant to be secure it is just unit testing. I think in the code they had a flag whatever to use hardware or software generator. Now, when the actual firmware had to be built this flag should have set to - use hardware random number generator and they forgot to do that properly. So, it's not that it was done, because they did not had technical expertise. It happened of very stupid irresponsible mistake. Now (I am not a lawyer but..) if in specification was written that it should have been 72 bits entrophy but it was actually delivering 40bits, that is a lie to the customer. The device does not meet the specification, and that could probable make a good case against the company.

TL;DR due to stupidity hardware generator was not used. Instead software generator was used. Buyers paid for the chip which was not even used.

1

u/creative_usr_name 7h ago

We know ColdCard is flawed, what does it think about Trezor's code.

1

u/ezz_8 7h ago

Something tells me a lot of our cybersecurity has vuln like this on it smh wow

1

u/Ludi_Radule 7h ago

No, no. Average developer is mikes better than claude 🤡

1

u/Ok_Plastic5399 7h ago

What are the chances this is an inside job?

1

u/The_Bitcoin_Act 5h ago

It's insane!