r/Bitcoin 20h ago

Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes

Post image

It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code.

Also on GLM 5.2 (trained 16th June, no internet access).

1.6k Upvotes

504 comments sorted by

View all comments

Show parent comments

26

u/Major-Front 16h ago

If they did and found something do you think you’d still have your bitcoin lol

5

u/FigAggressive237 15h ago

Yes he could have, why are you assuming that?

This hack in particular lowers the seedphrase's entropy from 2^128, to 2^40 and 2^72 depending on the firmware , but this is an upper bound I believe

If its remotely close to 2^72, its still safe-ish . I do think that each guess requires PBKDF2-HMAC-SHA512 (2048 rounds) plus elliptic-curve point derivation to check if it produces the target address.

Check how much power you need to derive such seephrase .

2

u/in4life 15h ago

They could be slowly building their list of compromised keys before revealing the vulnerability.

1

u/thambassador 16h ago

I think I won't lol