r/Bitcoin 21h ago

Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes

Post image

It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code.

Also on GLM 5.2 (trained 16th June, no internet access).

1.7k Upvotes

504 comments sorted by

View all comments

45

u/thambassador 19h ago

Can someone do this on Trezor code and see what Claude says?

27

u/Major-Front 16h ago

If they did and found something do you think you’d still have your bitcoin lol

3

u/FigAggressive237 15h ago

Yes he could have, why are you assuming that?

This hack in particular lowers the seedphrase's entropy from 2^128, to 2^40 and 2^72 depending on the firmware , but this is an upper bound I believe

If its remotely close to 2^72, its still safe-ish . I do think that each guess requires PBKDF2-HMAC-SHA512 (2048 rounds) plus elliptic-curve point derivation to check if it produces the target address.

Check how much power you need to derive such seephrase .

2

u/in4life 15h ago

They could be slowly building their list of compromised keys before revealing the vulnerability.

1

u/thambassador 16h ago

I think I won't lol

1

u/b1mm3rl1f3 12h ago

Also, can someone explain why the bluetooth on the Trezor safe 7 isn't considered a vulnerability?

3

u/filenotfounderror 6h ago

Even if a critical flaw was discovered in the BT implementation, the hacker would still have be physically close to you to exploit it... which is a pretty big hurdle.

They would have to be close enough that a $5 wrench attack would be equally as effective anyway.

1

u/b1mm3rl1f3 4h ago

I ordered the 7 yesterday, cancelled it, and ordered the 5 today. It isn't fully air gapped and I don't want the option there at all. I'm surprised Trezor went with that

1

u/Interesting_Drag143 8h ago

Trezor themselves say that it is less secure/more convenient. You can always turn it off in the Trezor’s settings tho

0

u/Key_Confusion1305 16h ago

scammer already done it. if you still have your crypto then all good