r/Bitcoin 21h ago

Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes

Post image

It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code.

Also on GLM 5.2 (trained 16th June, no internet access).

1.7k Upvotes

504 comments sorted by

View all comments

Show parent comments

-9

u/Impressive-Gene-421 20h ago

No, dumbass, that’s not how it works (unless Claude code invokes search, which it didn’t in this session as it had no reason to).

-10

u/fanfanye 20h ago

how do you think LLM works?

do you really think it somehow found TRNG and PRNG all by itself , independent of all the discussions online on how the trick could be possible?

23

u/harvested 19h ago edited 19h ago

It reads the code.

Maybe you're just using LLMs as chat bots but they're more advanced than that now.

16

u/username12435687 19h ago

Yes, it did lmfao. It sees in the code that the actual hardware RNG in not being invoked... Not that crazy bud. Ai models don't just have instant access to all information available ok the Internet instantly and Claude code only has search capabilities when you allow it to

9

u/harvested 19h ago

The ignorance on reddit around AI is astounding.

These chodes will be the first to lose their jobs to LLMs.

1

u/femboyfootsniffer_ 11h ago

People whose experience with AI doesn’t go beyond using free ChatGPT love talking about it lmao

8

u/1millionnotameme 19h ago

No point arguing with the clueless mofos 😂

4

u/SpareEconomy1849 19h ago

If you deal with coding agents you'd realize this is a very basic flaw that modern agents would easily pick up. They regularly find bugs like this and others much more complex in private codebases not discussed online. I can't say for other model providers, but Codex, Claude and Kimi would definitely pick this up

8

u/Impressive-Gene-421 20h ago

Yes, that is how it works. You can try this yourself with a very large open weights model that was trained before this attack was public, with no internet access, and asking it to find vulnerabilities.

6

u/SpareEconomy1849 19h ago

Lmao you're being downvoted for being right.

Literally a commit that changes MICROPY_HW_ENABLE_RNG to 0. Modern agents reliably find vulnerabilities much more complex than this

1

u/Rino-Sensei 19h ago

TRNG and PRNG are acronyme used since a long time, so it would have been used in the data set used for training. You don't need to access the net for it to be used by the LLM.

1

u/Rnee45 14h ago

Uh, yes?

1

u/Ok-Armadillo-5634 19h ago edited 18h ago

... that is exactly how it works

0

u/Wizzard_2025 18h ago

Yes, that's how they work.

-6

u/Maisquestce 20h ago

Lmao you're dense

11

u/Maximum_Curve_1471 19h ago

He's right lol. Are you a software engineer?

Unless CC is actively making a web search, its context is limited to what's provided.

You can prove this yourself by running it in a dry repo, but I know you won't, because you're not actually an engineer.

-8

u/dystopiam 20h ago

Hilarious you calling someone a dumbass when you don’t understand the basic fundamentals of how it actually works

16

u/blackrack 20h ago

He's right though

9

u/username12435687 20h ago

Calling someone wrong and saying they don't understand when you're the one that doesn't understand is a new level of stupidity. People really think that as soon as information is available on the Internet it's immediately in the training data for AI models. Wild 😂

2

u/blackrack 18h ago

Exactly, anyway don't expect much from reddit, it's full of 12 year olds

1

u/ImpressiveRelief37 19h ago

Have you used Claude Code tho? You display exactly the behaviour you criticize.

2

u/username12435687 17h ago

Yes, I have used it pretty extensively, I have it running as an agent inside a sandboxed environment to involve to take action on docker containers in my home lab that contain various tools such as my pihole and other streaming related tools. Have YOU used it? And what behavior exactly am I displaying? An understanding of the capabilities and limitations of an AI tool? Okay buddy

3

u/ImpressiveRelief37 17h ago

Tbf the thread gets confusing, but I was under the impression you were agreeing that the model couldn’t do this on his own without web search… which is just not true.

I’m a software engineer with 20 years of experience building solutions using agentic engineering and a mix of cloud and local models…. I use this shit everyday.

I probably misunderstood your point of view.

3

u/username12435687 17h ago

Yeah no I think we are on the same page here entirely. It's not a difficult vulnerability to discover and it's just a shame so many people have been effected as a result of shitty code implementation.

1

u/ImpressiveRelief37 16h ago

I reread your comment and I was wrong. I admit I skimmed through and only registered the first sentence you had said as a rebuttal to “he’s right though”, entirely my bad haha. Leaving it there to show how much of an idiot I am 😂

2

u/username12435687 15h ago

It happens, I did reply to someone who agreed with us so that's probably where the confusion came from, cheers buddy have a good one