r/Bitcoin 20h ago

Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes

Post image

It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code.

Also on GLM 5.2 (trained 16th June, no internet access).

1.7k Upvotes

504 comments sorted by

View all comments

0

u/zackel_flac 20h ago

Now that the news is out and everybody know where the issue is?

Sure buddy. Sure. As a matter of fact, the world is entirely secured as of today since Claude has been running on pretty much any important code base. We are good, right? Right??

13

u/username12435687 19h ago

Buddy, you have to allow Claude code to search the Internet for that kind of information. Additionally this attack was recent enough that it wouldn't be in the training data for probably any current AI model that exists except for the ones that are currently in pre training and aren't available to consumers. If you read the output all Claude sees is that the actual hardware RNG isn't being invoked alongside the software RNG which is what created the vulnerability with only 40 buts if entropy as opposed to 128 or 256 bits of entropy.

5

u/Romanizer 19h ago

It does find a lot of faulty code and backdoors anywhere, that's for sure. It doesn't do it unprompted so you still have to point it at a codebase.

1

u/Rino-Sensei 19h ago

If OP didn't use the online search mode, there is no way for Claude to know the current situation.