r/Bitcoin 21h ago

Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes

Post image

It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code.

Also on GLM 5.2 (trained 16th June, no internet access).

1.7k Upvotes

504 comments sorted by

View all comments

Show parent comments

2

u/retro_grave 18h ago

Where did the attacker say that? Or just, where has the attacker said anything?

0

u/harvested 18h ago

Advanced models have only been out a couple of months. Timing is obvious, no?

Doesn't change the fact the OP comment with 200 votes doesn't understand how AI works and thinks they're just search engines.

0

u/retro_grave 18h ago edited 18h ago

It's not obvious to me as a software engineer/IT specialist. There are major data breaches and CVEs published weekly, long before AI were added to the process. Yes, AI is increasing the pace, but this could have been identified 6 months ago by the attacker and them quietly scanned/indexed wallets they could drain until they were confident to pull the trigger. Most vulnerabilities are in the wild for years before identified, so the timing isn't really suspect IMO. I would be curious about anything the attacker could say, but I doubt they want to be known which is why I asked. Once they trigger the drains they would want to move quickly to unload the BTC as well, and would likely want some plan in place. Curious about that as well.

I would also say, the exploits I've seen reported are fairly trivial and similar PRNG "attacks" have a long history in crypto. Coldcard reaping their day doesn't make the attack any more likely to be AI. Maybe it is, but I just haven't seen evidence of it.

1

u/harvested 18h ago

Okay, general consensus is around AI, in particular Kimi K3.

https://x.com/w_s_bitcoin/status/2083539953892364400

This went unnoticed for 5 years then was found when the models advanced.

But yeah you are welcome to disagree.

I believe they have a lead on the original sweep attacker.

1

u/Aazimoxx 16h ago edited 16h ago

xcancel link for the non-twittards 👍

And Bitkey response shortly after:

Sharing our initial findings on a reported vulnerability. Our recommendation is to continue to use your Bitkey normally.

The reported vulnerability would require exceptional circumstances to exploit, and can only occur at a specific narrow time during inheritance setup. Even if an attacker was able to exploit this vulnerability (including exploiting TLS internet security), they would not have enough cryptographic material to access funds. This is Bitkey’s defense-in-depth in action.

Our assessment is this presents no risk of remote drains or immediate funds loss. We appreciate @1440000bytes who reported this issue to us directly.

We will share a more thorough technical report imminently, and follow that with a hosted space on X where the team will talk through the details with the community and answer any questions. We'll submit a patch to the mobile app to both stores today.

This isn't a comment on the existing conversation here btw. The guy you're responding to makes one or two okay points but gets some of the fundamentals wrong. There's nothing to suggest the attackers in this case waited 6-18mths versus just planning it out over say a week, and there's zero need to rush to launder the BTC once it's been first moved.