Can we maybe stop screaming how many critical vulnerabilities were found in all the projects that are being scanned are found, this is pure insanity.
Why are you painting an even bigger target on all the projects? Scan the repos, contact the maintainers privately and stfu about it so not everyone and their mom gets curious since you are so loudly proclaiming tons of vulns
Everyone is always so opinionated and loud about responsible disclosure but now that theres a "bitcoin red team" we are all screaming about critical vulns they keep discovering?
Login to reply
Replies (33)
Next move: create a "black team" that verify the "red team" πππ
Nah


Worst case scenario is that scare is not sufficient to eliminate the complacency that got us in this mess.
worse case would be that this speeds up someone looking into something very commonly deployed and another fuckton of ppl lose their money cuz of it
What if red team was actually black team lol
They need more funding from open sats. Thatβs their justification lol
@calle food for thought my guy
where's the food?
Idk how to respond to this. I'm too autistic.
Felt appropriate to tag you since I thought I saw you call out how many critical vulns you've discovered with the red team.
we don't disclose which projects we scan, or the results
Because this is not an operation to save Hodlers, it is an operation to save opensats.
No! Keep digging! Keep sharing! I am happy to donate to the bitcoin red team!
@Rob Hamilton and @calle are spooks
When they do not disclose the projects publicly, this gives no advantage to blackhat hackers.
And the red team is the one which started out now to find vulnerabilities and exploit those in order to responsibly disclose them with the maintainers.
I would argue that it does.
It shifts from "is there a needle in the haystack?"
To: "there is one.... In EACH haystack".
Basically putting them in active search mode.
Bitcoin red team is a scam, that's why.
Half these vulnerabilities they are finding are not even real.
Like they are trying to drive consumers away from certain products or they're trying to frame certain companies as incompetent.
And all the members just happen to be core 30 supporters that previously promoted coldcard.
that assumption was already established by black hats as soon as cc exploit started happening
They announced vulnerabilities in 390/391 projects before they had time to patch. An attacker only has to guess one good one to take advantage during this window
But when someone thought it was not, then this was an illusion all the way. I hope you are aware, that every software with thousands of lines of code will have bugs. And in most of those there is unfound exploits. This is no new information. This is just normal for every software project from a certain number of features implemented.
This was not different before the red team started to attack.
Paper is from 19 May 2025. Ai has improved a lot since then. Also the paper is about AI changing the code, in the case oft the red Team the AI is only used to find the vulnerability which is then disclosed to the development team. So hopefully it's humans implementing the changes.
Valid point but using AI to prod other bitcoin projects will be an obvious play to any black hat given the coldcard debacle - hopefully red team is just front running them. Maybe we have got this far without a serious hack because people didnβt believe there would be something as simple as an entropy bug in a HWW as much as the new generation of frontier models. The cat is out of the bag in any case.
They were broadcasting to the world that there are critical vulnerabilities on basically every project before the attack? Where?
I think youre missing the point here.
What point am I missing?
I can tell you that your browser has critical vulnerabilities without checking the code.
The probability for a softwareproject to have no critical vulnerabilities is probably close to zero.
It's painting targets on projects backs when a simple disclosure + waiting a month would do. Broadcasting doesn't help anyone except the marketers trying to chase clout and distract from NVK and CC.
It is a funding based project. So clearly it is necessary, they report what they do in order to get donations. And you just assume maintainers are unhappy with the way they act.
Your attacks are without any factual backing. Hackers are not acting more or less, depending on the amount software developers put into security.
But when good guys find vulnerabilities, blackhat hackers got less holes to poke in. And they are getting more difficult to exploit.
i didn't say doing AI reviews of the projects makes sense, what I question is the need to spend all the effort in announcing the great successes of the beloved red team
not to mention the incredibly sloppy instances of public msgs across platforms tagging founders/maintainers saying "hey read your DMs we need to discuss something security related".
doing the work and making sure everyone knows you are doing the work are two different things.
incentives and expected value calculations are a bit different when you as an attacker need to guess/hope that some of the projects will bare fruit of your attacks vs having confirmation that theres tons of vulns so just dig and you'll find more gold. specially because theres no value in spreading the stats of the results besides telling everyone how great of a job you are doing.
The essence of that paper still is correct. At best AI is a distraction. 10000 vulnerability candidates from which 10 are getting fixed is not that useful imho.
Maybe.
But did the black hats virtue signal they're gonna start attacking everything?
Real G's move in silence like lasagna.
Don't interpret my attempt at a joke as a favorable view of black hats. Rather, see it as a critique of the virtue signaling the so-called "white hackers" have been doing.
"Hey everyone look at us we're gonna do the right thing. Now give us money"
Boi if you don't FOH


nostr://nevent1qqsqqqrn0q0up2lmt2ffvujyth2fy4nnptljt3lxdhej7nlgcqqmakq3p6zxk
Who verifies the Red Team, or should we just trust them? Maybe we could hire the Blackhats to double check their work.
In the current climate, it seems that #responsibledisclosure is definitely something we should be discussing and educating ourselves onβnow that technical knowledge is no longer as significant a barrier to entry for exploiting vulnerabilities and deploying attacks against software projects.
I appreciated this being discussed on todayβs @npub1cxyr...hz6x podcast with @npub1ug8c...d9ry, @npub1kuy0...kdj8 and @npub18lzl...ugm3. Check it out.
It appears @npub1hea9...g9v2 took the best-practices route in reporting the @npub155m2...dcvg vuln.
https://www.youtube.com/live/QW0Lo2T4pRc

View quoted note →
