Can we maybe stop screaming how many critical vulnerabilities were found in all the projects that are being scanned are found, this is pure insanity. Why are you painting an even bigger target on all the projects? Scan the repos, contact the maintainers privately and stfu about it so not everyone and their mom gets curious since you are so loudly proclaiming tons of vulns Everyone is always so opinionated and loud about responsible disclosure but now that theres a "bitcoin red team" we are all screaming about critical vulns they keep discovering?

Replies (33)

worse case would be that this speeds up someone looking into something very commonly deployed and another fuckton of ppl lose their money cuz of it
Idk how to respond to this. I'm too autistic. Felt appropriate to tag you since I thought I saw you call out how many critical vulns you've discovered with the red team.
@calle No one ever said you disclosed which projects you scan. @aljaz was simply saying to stop signaling that you're finding critical vulns because this can act as an incentive for ill-intended hackers. You're basically putting extra pressure on the red team by saying "we've found bugs".
LightningBuck's avatar
LightningBuck 3 weeks ago
Because this is not an operation to save Hodlers, it is an operation to save opensats.
I would argue that it does. It shifts from "is there a needle in the haystack?" To: "there is one.... In EACH haystack". Basically putting them in active search mode.
Bitcoin red team is a scam, that's why. Half these vulnerabilities they are finding are not even real. Like they are trying to drive consumers away from certain products or they're trying to frame certain companies as incompetent. And all the members just happen to be core 30 supporters that previously promoted coldcard.
But when someone thought it was not, then this was an illusion all the way. I hope you are aware, that every software with thousands of lines of code will have bugs. And in most of those there is unfound exploits. This is no new information. This is just normal for every software project from a certain number of features implemented.
LightningBuck's avatar
LightningBuck 3 weeks ago
Paper is from 19 May 2025. Ai has improved a lot since then. Also the paper is about AI changing the code, in the case oft the red Team the AI is only used to find the vulnerability which is then disclosed to the development team. So hopefully it's humans implementing the changes.
Valid point but using AI to prod other bitcoin projects will be an obvious play to any black hat given the coldcard debacle - hopefully red team is just front running them. Maybe we have got this far without a serious hack because people didn’t believe there would be something as simple as an entropy bug in a HWW as much as the new generation of frontier models. The cat is out of the bag in any case.
It's painting targets on projects backs when a simple disclosure + waiting a month would do. Broadcasting doesn't help anyone except the marketers trying to chase clout and distract from NVK and CC.
It is a funding based project. So clearly it is necessary, they report what they do in order to get donations. And you just assume maintainers are unhappy with the way they act. Your attacks are without any factual backing. Hackers are not acting more or less, depending on the amount software developers put into security. But when good guys find vulnerabilities, blackhat hackers got less holes to poke in. And they are getting more difficult to exploit.
i didn't say doing AI reviews of the projects makes sense, what I question is the need to spend all the effort in announcing the great successes of the beloved red team not to mention the incredibly sloppy instances of public msgs across platforms tagging founders/maintainers saying "hey read your DMs we need to discuss something security related". doing the work and making sure everyone knows you are doing the work are two different things. incentives and expected value calculations are a bit different when you as an attacker need to guess/hope that some of the projects will bare fruit of your attacks vs having confirmation that theres tons of vulns so just dig and you'll find more gold. specially because theres no value in spreading the stats of the results besides telling everyone how great of a job you are doing.
Eddie's avatar
Eddie 3 weeks ago
The essence of that paper still is correct. At best AI is a distraction. 10000 vulnerability candidates from which 10 are getting fixed is not that useful imho.
Maybe. But did the black hats virtue signal they're gonna start attacking everything? Real G's move in silence like lasagna. Don't interpret my attempt at a joke as a favorable view of black hats. Rather, see it as a critique of the virtue signaling the so-called "white hackers" have been doing. "Hey everyone look at us we're gonna do the right thing. Now give us money" Boi if you don't FOH image
Diyana's avatar Diyana
In the current climate, it seems that #responsibledisclosure is definitely something we should be discussing and educating ourselves onβ€”now that technical knowledge is no longer as significant a barrier to entry for exploiting vulnerabilities and deploying attacks against software projects. I appreciated this being discussed on today’s @npub1cxyr...hz6x podcast with @npub1ug8c...d9ry, @npub1kuy0...kdj8 and @npub18lzl...ugm3. Check it out. It appears @npub1hea9...g9v2 took the best-practices route in reporting the @npub155m2...dcvg vuln. https://www.youtube.com/live/QW0Lo2T4pRc image
View quoted note →
↑