TheFuzzStone's avatar
TheFuzzStone
thefuzzstone@nostr.fan
npub1test...5l24
Agorist ┃ FOSS enthusiast
TheFuzzStone's avatar
TheFuzzStone 2 weeks ago
I've been a GrapheneOS user ever since the Pixel 6. And I'm surprised by people who are outraged that Volkswagen has blocked its app from running on GrapheneOS. Why don't people “vote” with their actions? For example, maybe you shouldn't buy modern crap - mistakenly called a car - that requires a proprietary app to track you?
TheFuzzStone's avatar
TheFuzzStone 2 weeks ago
I had a terrible experience using Zeus (LND) in the past. I decided to give it a second chance with LDK.
TheFuzzStone's avatar
TheFuzzStone 2 weeks ago
Instead of wasting money on alcohol, drugs and prostitutes, it's better to spend it on open-source/open-weight LLM tokens.
TheFuzzStone's avatar
TheFuzzStone 3 weeks ago
Checking crypto wallets for vulnerabilities using Kimi K3 is a rather addictive activity... I've gotten back into it... This time, I decided to check nprofile1qqs0y3tvskgs9gpgxxu5ahgz3fmms3rzmxt504qceqtz4a6pdgfwlkghwl6j8 / Cashu[.]me
TheFuzzStone's avatar
TheFuzzStone 3 weeks ago
So, another day, and another audit of yet another open-source crypto wallet. Once again, Kimi K3 found vulnerabilities and bugs. And once again, I manually reproduced the vulnerabilities. The cost? ~25 USD and about 8 hours of my time. And once again, I'll make a responsible disclosure to the developers of this wallet.
TheFuzzStone's avatar
TheFuzzStone 3 weeks ago
I usually talk to LLMs as if they were a child, gradually interacting with them and introducing them to the code. Then, once it's familiar with the project's code, I ask: How would the LLM advise me to conduct an audit? How many parts should I break the audit down into to better review the code, and to ensure it doesn't prioritize saving money or tokens, because accuracy is more important than money. The LLM breaks the audit down into several parts for me. For example, right now I'm auditing Monfluo (a cool Monero wallet). The LLM (Kimi K3) split the audit into 9 parts, and after it finishes Part_1, I then ask it to double-check the logic it documented in a separate file, and it re-examines what it found during the first check. I also tell the LLM to create its own .md memory file, to refer to that memory file whenever it needs to document something (make changes), and to always refer to the memory file whenever it needs to recall something. This memory file is also useful across different sessions. After completing the audit using the LLM, I manually verify the findings to double-check that the bug actually exists. And yes, Kimi K3 is impressive. image
TheFuzzStone's avatar
TheFuzzStone 3 weeks ago
I hope these are just temporary difficulties with Kimi and not censorship. image
TheFuzzStone's avatar
TheFuzzStone 3 weeks ago
It's July 2026, and I'm still surprised by people who say that LMMs are bad and that all they do is cause hallucinations.
TheFuzzStone's avatar
TheFuzzStone 3 weeks ago
Do you think that responsible disclosure of bugs and vulnerabilities applies to a project whose company hasn't even bothered to check its own code using an LLM?
TheFuzzStone's avatar
TheFuzzStone 3 weeks ago
There are some things that no amount of marketing can overcome. The wallet has a good goal - to be UX/UI-friendly. But a goal alone isn't enough. #CakeWallet Thread: