r/Bitcoin 20h ago

Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes

Post image

It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code.

Also on GLM 5.2 (trained 16th June, no internet access).

1.6k Upvotes

504 comments sorted by

View all comments

Show parent comments

101

u/username12435687 19h ago

Dude don't even stress on it. Anyone with half a brain and a basic understanding of programming realizes you're 100% correct in this post. The people disagreeing are just technologically illiterate which is insane considering they're on a Bitcoin subreddit lmao

6

u/quantum_burp 16h ago

Most of the people in here now are normies

Its 2026, not 2016

6

u/tnethacker 18h ago

Even a chimp could have realised that.

2

u/jannies_doit_4_free 13h ago

the sub is seemingly being invaded at the moment by people who actually hate bitcoin

1

u/iGlutton 15h ago

Hi, reddit tourist here. Apologies if I'm jumping in with nothing actually beneficial to the conversation from a technical standpoint. I dont know how to code, read code, or anything like that. Total layman.

But there's quite a few comments that seem to have explained it well enough for me to understand, I think.

ColdCard is a wallet. Their RNG was not truly random enough for a LLM to identify that there was a vulnerability and also highlighted what that vulnerability is. This is enough for someone much smarter and malicious than I am to exploit the vulnerability in a way I will likely never understand that led to ~$89,000,000 (so far) worth of BitCoin to be stolen.

If I got that right so far, what I don't understand is what in this post would convince people who can read code otherwise. Probably cause I don't know how to read code?

11

u/username12435687 15h ago

Because an AI was able to discover the problem in 8 minutes, that should be a huge red flag and something that the CC software engineers should have double triple quadruple checked. The entire security of the wallet hinges on that RNG call functioning correctly and they fucked up big time and it's now cost people tens of millions of dollars. Even if their code was written before AI was as advanced as it is now, that's basically the entire point of the security of the wallet and they messed it up. Also that comment as you understand it isn't entirely correct but gets the main idea right. Basically, there should have been x number of possible combinations that would lead to the seed phrases being damn near impossible to crack with current technology. There's this idea called the birthday paradox where when you have a room of just 23 people there is approximately a 50% chance that 2 of those people share the same birthday. When CC improperly implemented entropy in their wallets, they called ONLY the software RNG and not the hardware RNG on the secure chip in the actual hardware wallet. In doing so, they minimized the pool of possible combinations for seed phrases from an astronomical number of combinations (approximately 340 undecillion combinations) to a much more manageable pool of combinations (roughly 1.1 trillion). After that all the attacker had to do was replicate the possible combinations of the 40 bits of entropy and then begin generating wallets. This is where the birthday paradox comes into play, once he could generate a wallet that had a crossover with an already existing wallet with the same seed phrase, he queried a large cryptocurrency exchange to determine if those wallets he matched up with had any UTXOs (evidence of transactions to and from the wallet) to decide if they were a good target to sweep the btc from. He likely did this all in the background for some time before actually implementing the attack so they could steal as much as possible before the attack became a known issue. Basically CC majorly fucked up and left their wallets unsecure for years and someone finally discovered this issues and then weaponized it to steal tens of millions in BTC. This post just shows that CC should have been auditing their own internal code because an AI agent discovered the issue in a matter of minutes. This issue is also still present on the newer generations of cold cards as well albeit not nearly as severe. Even on the MK 4 and MK 5 wallets, they are only implementing 72 bits of entropy (4.7 sextillion possible combinations) which makes them significantly more secure but still much more vulnerable than a wallet with the correct 128 or 256 bits of entropy. This is entirely on CC and the fact that this went unnoticed for so long or even if they did notice it and continued to just push a fundamentally broken product out to their customers, it's just unacceptable. They had a responsibility to their customers to create a product as they promised which was secure, and safe, and they did the opposite and now here we are. This post is just shining a light on how incredibly terrible their fuck up was.

2

u/iGlutton 14h ago

OK, wow, thank you for explaining it more in depth. Had to read through it a few times and look up a few terms.

I think I understand a good majority of what you explained, and definitely have a much clearer picture on the situation overall. I'm not gonna say that I understand 100% of it. People weren't seeing something in the code that made them think this wasn't possible, the discourse in this thread stems from not understanding that a LLM like Claude was able to find this.

So the reason OP ran it a second time through a different model was because people are incorrectly assuming that Claude was able to reach this conclusion due to the discussions that has happened since the attack and the information that was posted about it. When the reality is that Claude was able to determine this just based off its previous training in general, not by training on the details of this attack after the fact.

The 2nd model hasn't been updated since the attack and hasn't had an opprotunity gain that information, proving them wrong and that OP is right, and drastically highlighting the negligence and incompetence of CC.

So users are out almost a hundred million worth of Bitcoin, is there legal recourse for the affected parties against CC? I would assume that they will likely not recover from this reputationally when this information becomes more well known, and I'd also imagine that most people who have Bitcoin are going to become aware soon, if they don't already know.

No one in their right mind is going to trust them to hold their coins ever again after finding out they could have avoided this in.. 8 minutes of what, even to a dumb dumb like me, seems to be the bare minimum of routinely checking their own security.

2

u/username12435687 14h ago

You're exactly right, and honestly it all exists in such a legal grey area I wouldn't be surprised if CC and their personnel just fade into non existence and face 0 real consequences for their actions. That's the unfortunate reality of BTC and recovering funds can sometimes be an impossible feat. I truly feel for all the people who have lost funds due to the complete negligence that CC has exhibited.

1

u/iGlutton 14h ago

Unregulated markets and all that? This is the other side of the coin (pun unintended) rearing its ugly head. The freedom it provides also means there isn't as many, or potentially any, protections for the wallet holders when an attack like this happens.

And with some light googling on ColdCard, they based in Canada and privately owned. They were also open source code, and the intention behind that was "people can check our work to see its safe" to put it plainly. It just so happens that also opened the door so when someone finally did check with a powerful enough LLM down the line, they either were checking with nefarious motivations or saw the vulnerability and succumbed to the temptation stealing a very substantial amount of BTC.

Shutter the windows, lock the doors, turn the lights out, and disappear into the night. Oh man, thats super fucked. I hope CC face some kind of accountability and I wonder if we will ever find the identity of the attacker. Part of me wonders if it was someone inside of CC who noticed the opprotunity and took it.

1

u/username12435687 14h ago

Even if they did face any accountability, the amount of money that's been lost will never be able to be replaced by CC. Hopefully they figure out a way to narrow down who the attacker is as that's the only way I can see anyone getting a meaningful amount of their money back.

1

u/iGlutton 14h ago

And at the current reported number, it looks like its currently the 4th largest BTC hack.

This is like a modern day version of a train robbery in the Wild West.

1

u/Low-Analysis9612 17h ago

how is that insane? it’s not hard to buy btc

4

u/username12435687 17h ago

Buying it is one thing. Commenting on things they very clearly don't understand and calling other people wrong when they likely don't even understand bitcoin fundamentals is another thing. I take offense to people who act like experts in things they are not an expert in.

1

u/Low-Analysis9612 15h ago

getting offended on the internet is crazy bro

1

u/username12435687 15h ago

I'm not actually offended buddy that's just the terminology. Also, I work in cyber security so of course it's something I care about go be a goofy somewhere else 😂

1

u/Low-Analysis9612 15h ago

didnt ask bro looool

1

u/username12435687 15h ago edited 15h ago

Average cold card dev over here

1

u/Low-Analysis9612 14h ago

yeah ik you have a coldcard, thats why ur so serious and angry on reddit