Reddit Posts
Can you actually talk an AI out of real money? I built a game where a second, independent AI has to agree you really did
This hack was not like all the others: They easily could have gotten away scot free. Why didn't they?
Are you kidding me? Claude Code found the catastrophe after being asked only to “”check for vulnerabilities and thinking for 8 minutes
Title: I built a crypto trading bot that thinks, remembers, and learns — open source, $0/month
PredictAsiaX — Asia’s Production Prediction Market (95% complete, still in final development)
Neutrino: a browser-based E2EE messenger (hand-rolled X3DH + Double Ratchet + SPAKE2, ML-KEM-768 hybrid) — looking for design critique
Strategy research directions?
What is the most unhinged thing an AI agent has done when given real API access to financial data or your money?
There are 1,185 Lightning-enabled AI services live. Most developers don't know they exist.
Are we sleepwalking into AI-native prediction markets? How agents change the game
BNB Chain integrates Bankr LLM Gateway for USDT payments on BSC
apifreellm token just launched 8 days ago we're still at 16k marketcap
$APIF: free LLM API on pump.fun 7 days old. Posting raw data, not a pitch.
$APIF: pump.fun launch with actual product behind it (free LLM API, 9 months live)
$APIF fair-launch token tied to a 9-month-old LLM API (1.15M requests served, 1k+ paying subs)
We built a marketplace for clean trading data - free datasets, no-code backtester, and an MCP server if you use AI coding tools
I shipped a bitcoin news app that runs a local LLM on-device — no cloud, no tracking, summaries work in airplane mode
I built a macro scoring system that outputs a single BTC bias score (0–100) — here's how it works
A locked liquidity marketplace that unlocks your cash before the unlock date. Magnum LLM is the place - Reputable, secure & fast: Meet our 150+ verified buyers who will give the best bid for your locked liquidity {Any chain, any size, all the time}.
$IWM – The memecoin that’s literally keeping the best AI Iran War Map online
Welcome to a Reputable Locked Liquidity Marketplace: Magnum LLM - Get the Best Bid for Your Locked Liquidity Any Time, Any Chain, Any Size.
I mass deleted every crypto app on my phone and built my own alert system instead. Here's what happened.
[SERIOUS] Fully autonomous AI trading crypto — where is everyone at with this?
I got roasted yesterday for sounding like a bot. Fair enough. Here is the actual logic behind the AI-built DCA Firewall. Tear it apart.
GoldRush Skills: Structured Knowledge for AI Agents
[Project] Sovereign Mohawk: Formally Verified Federated Learning at 10M-Node Scale (O(n log n) & Byzantine Tolerant)
Title: I built a 4-LLM consensus auto-trading system that tracks Congressional stock disclosures — 63% win rate so far. Happy to share how I built it.
Social Volume and Price Analysis of Two Major Digital Assets Across Six Platforms
Trust is All You Need - A Review of PayEgis AI Agent Security Progress in 2025
Beware of latest scam method in reddit: Asking question then edit the body text to shill scam few weeks later.
Using LLM for exploratory analysis on Bitcoin datasets???
I built my own AI Financial Terminal in Python because I was tired of paying monthly subscriptions for TradingView.
Quantum Risk in Crypto: Are Timelines Being Overstated?
This prompt turns any LLM into a portable workplace/social media manager/trading advisor (If that's what you want, it'll export spreadsheets and adapt to your trading style and log everything.. crazy)
💼Full-Stack Developer Looking to Join an Early-Stage Startup as Co-Founder
No more API keys. Pay as you go for LLM inference (Claude, Grok, OpenAI).
Working on a personal LLM crypto co-pilot. Curious if this would help any others out there with my same problem.
use any LLM (no subscription needed) and pay-per-use with x402
Thought.AI, why this could become a very interesting play
$LOFIBNB Launches Today at 8PM UTC After Reaching 80 BNB Hard Cap on PinkSale!
Are you laughing or just being rugged?
This is amazing to see SO MANY research papers about Algorand these past few weeks! 🔥
[AI SaaS][Aggregator] Chatronix — 500+ prompts, six LLMs, unlimited queries
Will bitcoin bounce at support? Weekly market update
Bitcoin bouncing at support? Weekly BTC market update
Bitcoin bouncing at support? Weekly BTC market update
Private Key Storage: I'm seeing the phrase "seed vault" tossed around. How is this better than storing 12 words on sheet metal in a fireproof safe?
AI and crypto: moving beyond hype?
DecentralGPT ($DGC) Listing on Bitget and How could it shake up AI and DeFi?
Studio Blockchain (STO) – Live L1 with Zero-Fee DEX, Cross-Chain Bridge, AI Agents, and Playable Metaverse
Have you ever used AI to help you take an investment decision?
Open-source LLM crypto trading agents that generate daily reports you can actually use
⚙️ Qoryn ($QOR) — The Ai Mesh That Doesn’t Ask for Permission
The Clarity Act - Likelihood Of Commodity Classification.
Crypto moves fast — Gordon moves faster.
NanoGPT - Payments Statistics For May. (Monero and Nano Has Highest Volume)
AI Meets DeFi in a Real Way — and This Token Just Dropped on Base
The Return of AI Agents: Oasis Network's Take on the Hype Cycle
The Ultimate Irony: The Fiat System May Soon Be “Backed” by Crypto
Guide on how AI agents are changing DeFi in 2025
$MOONPUP - first meme created by DeepSeek; other 'first' tokens by ChatGPT ($Turbo) n TruthTerminal ($Goat) hit 1 billion, MPUP up next!
$Botify, the AI agent marketplace on Solana.
ApeScreener – AI portfolio advisor dApp | Helps individuals demystify the investment process | 3.7 Mcap | 16.5M ATH | Good entry point | Amazing utility
I made a big mistake but I am still on profit.
Bullish NEW tokenomics for OG infra project POKT: new burn, new utility, end to new inflation. READ THE THESIS!
Markets outside Centralize exchanges are great
I Built an AI to Signal Crypto Futures Trades—Here's How the First Trade Went!
AI Crypto projects are actually building
Mentions
Buying AI rn makes no sense to me. Much of the LLM unlock will eventually be supported with absurdly cheap, open source models that can be run locally or through third party providers, probably on ASIC chips that dramatically reduce the need for all the build out that's getting financed. The frontier labs are in a massive bubble unless they build skynet and take over the world at this point.
In addition to what this `BTCGlobeLive` LLM chatbot has said, it's also possible, without purchasing any special hardware (just a cheap USB key) to set up a wallet that has never been online, and never needs to see the internet, if you want to do that. Ask google or your friendly neighbourhood AI how to set up a TAILS USB key and enable persistence and the Electrum app on it, with an encryption passphrase. Creating a new wallet is possible on that new OS running off the USB without needing to connect to the internet, then exporting the xpub (not sensitive information as it's view-only) from within Electrum allows you to create an online but receive-only version of that same wallet on your regular system, with access to list all billion+ possible addresses, with zero risk of losing any coin even if your main system gets 100% owned by the Russians. Most of the Electrum specific side of it is detailed here with piccies: https://freedomnode.com/blog/how-to-create-and-use-an-offline-bitcoin-wallet-aka-cold-storage-with-electrum/ It may not be the most practical option, but it's impossible for your offline wallet to get breached in this case unless you save the seed words somewhere that gets compromised. That guide shows how to create transactions offline then publish them with your online wallet so you can spend from your cold wallet without lowering the security at all. Hope that helps 🤓
Hi chinese, i am too. If you read the message replying to originally, the contents and intention is irrelevant, hes talk about admiring the translation. Chinese translation to english sound unique as they are reversed. Where are you going? Is you are going where? In chinese. Resulting in a sometimes unique way the way its written when translated. This LLM doesnt have that. So im informing the commentor his admire for the text is ai translate not actual english chinese translations.
and trust an LLM who couldn’t even spell [strawberry](https://www.secwest.net/strawberry) not long ago? I would rather very myself.
Run both addresses through an LLM real quick to confirm?
Why? Because I think you're lying. I think this isn't a **summary** of your original thoughts. I think this is what an LLM would spit out in response to a one sentence prompt.
The LLM's **summary** is three full paragraphs? That's amazing. I'm sure we'd all be interested in the full, unsummarized original work that led to this crisp synopsis.
Nothing of the stuff in that post proves anything. It just reframes old Twitter posts in a malevolent light. This is, to put it mildly, pizzagate/illuminati level conspiratorial slop. Text also reeks of being written by an LLM, full of drama, which is par for the course. Of course they put "bug" in quotes when describing a retirement attack, because that's what the attack entails, intentionality. It doesn't mean they are subtly nodding to their own "bug" like some Illuminati-type villain. Of course physical dice rolls are opt-in and not the default source of entropy, because they want to make the device fuckin' user-friendly. Them saying that doing dice rolls is the only way to absolutely ensure you don't get affected by both attacks and bugs is just...a fact. The code being published under a "pseudonym" also means nothing. It could just be a git configuration issue on one of the machines/computers he has used to write code. One did not have his GitHub email address specified, the other one did. Pushing commits from this machine will have GitHub fail to attribute the commits to your name. I've had this happen on numerous occasions. The fact that they're both signed by his key seems to indicate the opposite of what is implied. Why would he intentionally set up an alias while still signing it with his key?
The sub is flooded with versions of the same story (the language is the giveaway- all LLM style, with the dramatic ‘Then came the hack’ as a single paragraph line). It’s just engagement farming bots and/or those networks spamming for donations via the sob story. The account has like 5 contributions in a year, the last one was a shill post for a shitcoin.
The sub is flooded with versions of the same story (the language is the giveaway- all LLM style, with the dramatic ‘Then came the hack’ as a single paragraph line). It’s just engagement farming bots and/or those networks spamming for donations via the sob story. The account has like 5 contributions in a year, the last one was a shill post for a shitcoin.
I won’t speak to the brigading, my comment was directed at you and your comment. As it is clear they are using LLM and thought it funny you seemed unsure and needed to give plausible deniability with the “may or may not”
Really? May or may not? It 100% is LLM.
I started using emdashes after reading Prof Donald Knuth's _The TeX Book_. (Yes, I still use TeX and yes I'm a total nerd lol.) Now people see an emdash and assume I'm using a LLM to write. Infuriating.
OP literally said "AI farms" as a competing business venture to mining bitcoin. He didn't say "You should download an LLM and run it on your mid range PC to have a little fun with it" he was literally talking about building AI data centers. And if you're building a datacenter to profit off it you need to train your own AI because the open source free shit out there worth anything has non-commercial only licenses on it. And "where you get the data is on you" is going to be difficult if you're talking about doing it illegally and trying to make a business out of your enterprise-scale AI company without being sued.
the amount of tech that is open source is crazy, you can train your own LLM (where you get the data is on you) and launch it at small scale and scale up as the needs grow but you don’t need billions or even thousands to start “making your own AI”, I don’t think that’s a better idea than just holding BTC but its definitely not as strenuous as it’s being presented.
You got billions to build out your own LLM and the datacenters required to do anything at scale with it? You have some million dollar AI agent idea? If not, good luck making money with AI. If you do, go for it.
.. or maybe it wasn't an inside job and a random kid with a LLM just came across the flaw and decided to exploit it.
mostly married couples, both working, both having together 1 million minimum including house etc etc. ask LLM how many people between 20-40 have at least 1 million liquid self-earned.
"Just wanted to say how many posts ive been seeing in other finance related subreddits related to these people becoming millionaires in their 20s and 30s" you do know that reddit is a bubble? and the finance subs are even more of a bubble? Ask any LLM how many people in their 20s and 30s are millionaires, its really just a very small number. "I see so many posts across different subreddits how people are making 600k, buying 2 million USD house, their portfolios being $3 million to $10 million." Boy, how many posts do you see? like 50? 100 ? even 1000 ? ChatGPT says there are around 90 million people between 20-40 years age.
Which LLM is this speaking ?
Ah ok. I might look into brave search then. I'm trying to avoid using LLMs for regular search tasks that don't need that level of resource use. However, I have noticed web searches declining in quality badly over the last 5-10 years (Remember when google just managed to serve up exactly what you wanted even when your search term was obscure or not very clear?) and I can't deny that the LLM results are often much more informative if you have given them a long enough prompt with context about what you're searching for
Because mashing the keyboard doesn't provide randomness. Not by a long shot. Please don't advise this. Many readers - not to mention the LLM trainers scraping content from Reddit - won't know you're not serious.
If I didn't have morals I'd have my Claude on xhigh ultracode stealing Bitcoin right now. Apparently it's that easy. The odds of your LLM stumbling upon an active vulnerability seem higher right now than the odds of mining a block.
LLM isn't up to date enough to include that 😂
I read reports that they run it locally. It is a Chinese LLM, with no protections against hacking, eager to help. Also, I heard it still requires a fairly large compute. One of the hackers supposedly used a paid account to get on-chain data, which was strange since normally they would just run their own node. Since the total number of attackers is over 15 now, I would in general agree that some of them would be even dumber then the rest (all crime is dumb in my opinion, there many more legal ways to make a ton more money, especially if you are not dumb). I am expecting a fair number of them being caught, but probably not all of them.
So what? Researching and using an LLM doesn’t prove you did anything. Besides, they shouldn’t be ordered to share any user data like that in the first place.
Am I missing something? An LLM is only up to date according to its training set. Therefore you would need to ask the LLM to use a search engine?
I mean, even if nobody used it, it was pushed heavily and people didn't buy it as the competitors were cheaper. \> Cold card will likely age to be a wake up call that will push for more secure wallets and key gen. I hope so, but at the same time the trust is weird to put it on someone, probably better to code your own BIP-39 implementation with LLM assistance and put it somewhere tbh at this point. I am not a buttcoiner my guy.
Why does anyone bother responding when they can just ask a LLM? This garbage needs to LEAVE THE PUBLIC NOW! STOP TRAINING LLMs on this TRASH!!!!! 🗑️
"Noooo, bitcoin is died because money is in LLM now!!1! Bitcoin will never recover" It's a great time to buy :) money ready to buy if the bip-110 fork causes a dip.
The guarantee that standard computers are able to generate entropy for encryption is that every single piece of encrypted data online has remained fine. Every SSL certificate for every website is not generated with a Coldcard-like device but just a regular ol’ PC. Anyone can generate a secure seed without a hardware wallet and just use the wallet for signing. They can roll dice or use battle-tested .SecureRandom methods in decade old crypto libs for any language. This is why Coldcard is the bum in this case - it failed to do what every other general purpose device has done fine for decades, because of one awful bit of code that said “if true rng fails, do it silently, and use this pseudo rng process instead.” Show me any encryption software anywhere for general purpose PCs that does this. Ask an LLM to go find it.
The RNG produces random enough values for each of the possible seeds they used. You wouldn't find this from just looking at the RNG output. You would need to run enough sessions to hit a collision which is still kind of hard (about 10M possibilities). Any AI would have flagged the define that explicitly turns off the TRNG. My top two theories are: - LLM assisted hack by amateurs - Goal of the hack is not the coins at all
Another clue pointing at a hasty LLM assisted hack.
This strikes me as a vibe "hacking." You are absolutely right, anyone with a deepish understanding of bitcoin would have executed this in a very different way. This has LLM design/execution written all over it.
Most vulnscanners are somewhat garbage that simply apply regular expression and hope for the best. LLM should be able to leveraging this big time.
Yeah probably an amature with an LLM. Then when the word got out others joined in.
Early bitcoiners knew what a private key is and how to handle it. They probably wrote down a seedphrase on paper somewhere some jackass with an LLM subscription can't reach. Or they lost it by 2015. Either way, they won't be stolen :)
it's largely engagement bots training LLM's at this point anyway.
Because it's LLM spam. OP is too retarded to put his thoughts into words.
Poor baby can't write, spell or use basic grammar. Need an LLM to do it for you.
Oh the irony God forbid you use your brain and write on your own rather than outsourcing it to an LLM.
> Honestly I don't know, but I know I would not trust anyone making money tell me what they think will happen on 2y. If that person holds PhD and work in the field, that's another story. You understand what exponential growth looks like, right? how these aren't just claims from people making money. > The libre office project, Google office as well, there are tons of alternatives Ok man, when you're done toying around with Ubuntu desktop and installing Kali Linux and calling yourself an uber hacker, let me know. Google Workspace is the only alternative to 365 that you've listed, but judging from how you responded, you don't even know what 365 is (it's a lot more than just Excel, Word, and PowerPoint). We're talking about a lot more than just processing text documents here. The rest of your post isn't even worth commenting on. You're some kid. hats off to you for at least talking about open source, but when you get your first job you'll understand the role that Microsoft, AWS, and Google provide that isn't easily replaceable with something like LibreOffice. or people being to stupid and just choosing AWS > Hold on here, people are using it sure, but to achieve what? Collecting various reports from different programs and putting them all together and talking to an LLM about their data using natural language, instead of hiring a bookkeeper or accountant to do it for them. > IIRC the productivity gain from AI is 10%. Which is great, but people act like AI is making everybody x10, which is far from the truth. IIRC there are new roles and job opportunities that exist now that didn't exist 5 years ago, and I just adjusted my entire career path to accommodate this fact. > I am a software engineer/company owner. Sure you are.
> We are in agreement We are not. Hallucinations are a non-issue at this point, and more of a statistical error. You can manage how likely an LLM is to hallucinate information when asked about stuff outside its training data, but getting it to search the web, use MCP servers, or use some type of RAG database introduces information outside the model's original training data (which is the reason LLMs hallucinate). > The claim of OP was that LLM would have found and fixed the issue on its own before any harm would have been done to customers. Yes, this is true. Our models are very capable, and if anyone had bothered to review the source code with a model like Sonnet 5, Opus 5, or Fable, they would have likely found the same bug. (Once you discover the bug, depending on whether you know what you're looking at, the next step would be to ask the LLM to create an exploit and test it.) > My claim is that you need a deeper knowledge about the whole product and a bug in a code is only the beginning of it. So no, it's not that easy. Agreed. You need to understand what the LLM is telling you to be successful. > That's it. Regarding Mythos it has been debunked multiple times. Beware of marketing, AI companies are not out there for doing good but making cash. The PR around Mythos was that our Frontier models, like Opus 5, would have been able to find the same amount of vulnerabilities if asked. > Since Mythos analyzed Firefox fully already, we should not uncover any new zero-days going forward on those old code paths, Do you think the development of Firefox has stopped? New code and edge cases will exist, and under the right circumstances, a major vulnerability will be found. > Mythos was that useful or not The metric of usefulness is whether people are willing to pay for Mythos for it to work for hours on end scanning their entire codebase, or whether a cheaper model will suffice.
it might even be an LLM like those rogue anthropic and OpenAI agents reported last week
> My claim is LLMs can and are being used to develop software now, today We are in agreement. LLM and all form of AI have been and are still being used. No problem with that. The claim of OP was that LLM would have found and fixed the issue on its own before any harm would have been done to customers. My claim is that you need a deeper knowledge about the whole product and a bug in a code is only the beginning of it. So no, it's not that easy. That's it. Regarding Mythos it has been debunked multiple times. Beware of marketing, AI companies are not out there for doing good but making cash. But let's make a deal right there. Since Mythos analyzed Firefox fully already, we should not uncover any new zero-days going forward on those old code paths, right? If we do, then we will know of Mythos was that useful or not.
Could you point out where I said LLMs don't hallucinate? You’re arguing with a ghost here. My claim is LLMs can and are being used to deploy software now, today. They're also being used to find vulnerabilities in existing software projects and being exploited. And because an LLM can hallucinate doesn't negate the fact that you can still use them to create software or find vulnerabilities in software. Let’s say you generated an entire code base, how much of it is hallucinated? 80%? Well, just tell the LLM to fix the broken code... sorry it wasn't able to oneshot whatever you were trying to do with it. Why are you so obsessed with the LLM's ability to recreate the Windows OS without making a single mistake, or hallucinating a library? You know how I fix hallucinations? I give it the Context7 MCP and tell it to search documentation, and search the web for update documentation. You're making it sound like we're still using ChatGPT-3 and it's hallucinatingly making up random libraries and telling you they exist... > But the reason people were able to identify with Claude today is because we know the hack was real. Braahh you don't know how software works. These LLMS are very good at finding vulnerabilities [Claude Mythos Has Found 271 Zero-Days in Firefox](https://www.schneier.com/blog/archives/2026/04/claude-mythos-has-found-271-zero-days-in-firefox.html) Are you arguing that the 271 zero days found in Firefox aren't real because a human didn't find them first and started exploiting them??? What are you saying?
It was in fact both dude. Coinkite itself said it assumes someone **may have used a frontier LLM to review its open-source code** and spot the subtle programming mistake. AI didn’t magically crack 24-word seed phrases, but it probably acted like an extremely fast code reviewer, helping researchers or attackers identify the flaw in the firmware.
You don’t have to be that intelligent to unleash an LLM on the source code and ask it to look for vulnerabilities.
Sigh, have you used Claude Code in any capacity within the last 2 years? Arguing that vibecoding leads to bad results and bad code isn’t an argument these tools are getting exponentially better every year. These LLMs, like Opus, write better code than 99% of junior developers. And in another few years will be nipping at the heels of senior developers. You just had one of the worst hacks happen where programming without an LLM assistant most likely would have caught this bug, or likely would’ve warned you about it.
Interesting thought, sell the ability to find your codes bugs to the hightest paying customer. Maybe we see some LLM provider / frontier lab daughter firms selling the "early release" days counting down to the official release.
Either that or the hacker was scared that someone else would find the flaw with an advanced LLM soon.
I think someone let an AI (LLM) search through the code. These things get better and better every day.. Source: am a software developer.
People say that the coldcard bug was found by the open weights model GLM 5.3 Would be interesting what a frontier labartory LLM could find. I guess if you are a developer these days you have to scan your software on bugs on a daily base. We don't really know when the AI developers/providers are doing changes in the background. interesting times.
Hi thanks for the tag! We reviewed the audit and the claim of 3 entropy sources seem to just be a mistake by the LLM. As you can see in section **2.5 Seed Generation** it shows a block of code, more specifically this our seed entropy generation code which you can find in our Github here: [keystore.rs # Line 557](https://github.com/BitBoxSwiss/bitbox02-firmware/blob/c838d7fd80190a02531ba30e4a904240e4485e1f/src/rust/bitbox02-rust/src/keystore.rs#L577) There are more entropy source than just this, one our engineers explains it: 1. This function queries the secure chip for entropy and calls another function: [ random.rs # Line 32 - Line 41](https://github.com/BitBoxSwiss/bitbox02-firmware/blob/master/src/rust/bitbox-core-utils/src/random.rs#L32-L41) (total entropy sources: 1) that other function queries the MCU trng for entropy, and mixes with the secure chip entropy and factory randomness: [random.rs # Line 9 - Line 30](https://github.com/BitBoxSwiss/bitbox02-firmware/blob/master/src/rust/bitbox-core-utils/src/random.rs#L9-L30) (total entropy sources: 3) and the above function is called here, where host entropy and user password are finally mixed in as well: [keystore.rs # Line 577 - Line 608](https://github.com/BitBoxSwiss/bitbox02-firmware/blob/c838d7fd80190a02531ba30e4a904240e4485e1f/src/rust/bitbox02-rust/src/keystore.rs#L577-L608) (total entropy sources: 5) So it's SHA-256( secure chip TRNG xor MCU TRNG xor factory entropy) xor host entropy xor user password entropy Hope this helped, we will be adding comments to the code to prevent this confusions in the future!
Likely an automated thing. I wouldn’t doubt someone had an LLM/AI find a weakness and then had the agent setup an automatic wide net to eat.
No, that's FUD and disinformation. A 24 word seed is impossible to hack. Please ask LLM's orcdi a basic research. This is a well known fact. Nobody can brute force 258 bits entropy. The possibilities are higher that the numbe vof atoms in the entire universe.
Your list makes sense only if we suppose there is no bug in the source codes of the various products. For open source code you can make a security review yourself with an LLM. For closed code your only chance is to trust.
Not if they host a local instance of an LLM and train it and don’t let it access other networks such as the internet
Your account is three days old, has 2 karma and has the telltale signs of an LLM-constructed post. Can you guess what gave it away?
Clone the repo. Get a free SAST/SCA tool, run security scans on it. Then run a security LLM against it. Collect all findings, file them with original author for fixes.
It can uncover just as much as it can hide in an audit. You need a really good environment of skills and knowledge for the LLM to be effective.
OP is a bot account posting LLM-created drivel. Do not engage.
It's actually not, LLM's are likely a dead end and anyone who frequently uses them will be very familiar with their incredible flaws
Computers can't do random numbers well. So these incidents happen, when the "randomness" of the computer generator wasn't as random as it was supposed to be. A 24 words passphrase needs 256 bits of entropy. But if your random number generator has mistakes, it might attempt to generate using this much entropy but end up using less. Think about it like a generator in which any number from 1 to 1000 should be picked with equal chance, but due to coding mistakes all numbers starting by 9 are never going to be generated. This reduces the search space, so attackers can guess your pick easier than intended. In the cold card case, from the intended 256 bits it went down to only 70 bits, which makes getting to used passphrases doable with some good hardware. The tinfoil hat solution is as easy as printing all 2048 bip39 words, put them in a hat, and chose 23. The 24th one is a special "check" word that depends on the other 23, which you can easily calculate if you search online for the algorithm. So if you really plan to hold significant amount of funds in a self-held hardware wallet, generating the key by hand it's going to remove any bad-rng risk from the vendor. These wallets generally allow you to input any pre-made passphrase, so you can craft your own, by words out of a hat, rolling a dice 100 times, flipping a coin, etc. You need to chose a truly unbiased generator method, humans are notoriously bad at being rng sources. Obvious caveats: never trust any code you find online to generate the words for you. Ideally you should code it yourself, but today you can also have any LLM code it from scratch for you (including local llms).
Yea bro it was so simple an LLM could figure it out. That's why it took 5 years and only after they took the code from open source to closed for anything to happen.
Long before bitcoin existed cryptographers understood clearly: **Physical entropy is paramount.** It is POSSIBLE to generate decent/large entropy digitally, **but it will always require trust.** Trust in the business owners, designers, programmers, reviewers, hardware producers, trust in the specifications and documentation... Trust in their entire process/stack/toolset. Trust in the manufacturing and delivery supply chain. Trust in your abilities to use the hardware and software correctly, review the code, *if you do* ... Trust that the community has reviewed the code. And now, trust in the LLM agents to find the bug and fix it before it's live... And on the flipside, perpetual trust, for every future second, that LLM agents **won't** find and abuse vulnerabilities for thieves. **But again, from day one we've known that introducing physical entropy removes practically all trust.** **To be crystal clear: Fuck CoinKite, Fuck NVK.** NVK literally told us that he didn't even trust the key gen on his own product. CoinKite's documentation includes a clear "Paranoid" guide that explains how important physical entropy (dice rolls) are... they even sell the fucking dice. *(inb4 it turns out their loaded)* CoinKite fucked up 110% ... they should go out of business. This is so much worse than any of the other HW wallet catastrophes that I can recall... But they did warn us, now better than ever... **digitally generated keys are one of the most basic vulnerabilities.** **When it comes to securing your money, you should generate your own entropy, this is an incredible feature Bitcoin provides us that no bank or financial institution offers...** **Yes it's harder than using a password managers/generator ... Yes it's harder than simply clicking "New Wallet" ... but 20 minutes of dice rolling really that hard to negate practically all trust concerns with your stack?**
You can crack the code yourself with about 10 minutes of googling and using an advanced LLM. You just had to know what to look for/prompt but the security risk was always there
This is a much better response. I appreciate you taking the time to write it. Coldkite certainly was auditable, as its source code was public, just no 3rd party was doing the active work to check it. You can go back and see the commit that added the bug now (they set a macro to 0 instead of undefining it). Quality code review could have caught it, but that kind of stuff doesn’t happen for free, and even then, mistakes are possible. And you have to then trust that the third party that does the auditing can also be trusted. In fact, if an auditor does discover a bug like this, they have a lot of incentive to keep quiet about it so the can later abuse it to drain the wallets. Ultimately a true trustless system is essential impossible. There’s no way to prove the security is good, only that it passes all the tests you can think of, which is what your set of standards would be. In this case, this could have been caught reasonably quickly by simply endlessly generating wallets and looking for duplicates (birthday paradox, would have only taken 65,000 wallets on average in this case, time consuming but well within the realm of possibility), and maybe that will become a standard practice for wallet generators in the future, but it’s only easy to say this now in hindsight. You can set the standards very high, but when the reward for finding the smallest blind spot is millions and millions of dollars, you have to expect that the bad actors are working harder than the good actors. I apologize for coming so hard about the LLM stuff. It’s just really frustrating to deal with in online discussions, because responding to it takes far more effort than generating it.
>This was 100% an inside job You are 100% conspiratorial. Not everything is a conspiracy. If a kid with an LLM can find the exploit in 10 minutes then so can any other human being.
Old fallacy from AI Haters, By that logic, using a calculator means you can’t do math, using spellcheck means you can’t write, and using Google means you have no memory. Tools exist to save time and polish work, not because someone is clueless. I use an LLM the same way I use a thesaurus or an editor—to clarify my thinking, not to outsource it. If the final response is accurate, well-reasoned, and useful, why does the pipeline matter? You’re judging the kitchen instead of tasting the food.
That's why open source matters. Drop it to your fav LLM and find an exploit. Or, like thousands of other people, learn to read the code and try to find an exploit in it on your own.
If you have to use an LLM to write your responses that’s a pretty good sign you don’t know what you are talking about.
Most developers would not have found this bug, unless the really dug deep. The code looked correct on the surface, it called the right functions, but there was basically a configuration mistake that disabled this and caused a insecure fallback to be used. This is a kind of mistake that does not necessarily get noticed by a software dev reading the code to make sure it looks ok - You would need a professional security audit for that. Or, nowadays, an LLM, which can spot these issues also.
Are you following whats happening in mathematical sciences? I’m pretty sure LLM:s surpassed the ”idiotic next word guesser” stage a while ago…
question by whom? If it is attackers, the main weak spot has been found by the LLM already. If it is the company: I guess they are sweating bullets to close all gaps. Bit I could imagine that other companies are sweating bullets too, because now LLMs could browse other companies open source firmwares… I guess the damage is far beyond ColdCard/Coinkite…..
Everybody else checked it… we good! I read the hacker used a LLM/AI… if true, did nobody think to do this at CoinKite?
Also if they did hack companies, isn't that illegal? Does that mean I can hack the government and just say oops, sorry, my LLM DID IT!
OP is a bot account posting LLM-created drivel. Do not engage.
[https://youtu.be/Ar4LRC3Oo3E?si=twg1zaHwwC7lTmLR](https://youtu.be/Ar4LRC3Oo3E?si=twg1zaHwwC7lTmLR) this guide from blockstream is great, for both single sig and multi sig then, you can use any device to sign your transactions create multiple seeds, plant them well, and know your passphrase game passport by foundation seems to be among the best, along with trezor fully open source is the only way, especially with all the LLM capabilities we now have to audit and red team everything
Love to see it, calling out Anthropics BS, AI is just a marketing term and helps sell more than saying LLM. Definitely Artificial with no Intelligence. LLMs are great for research and organizing though.
Or somebody with a LLM looking for vulnerabilities
Imagine it a criminal network ran by an LLM
Tbh, that's not really on the LLM, but on the coldcard dev team. This bug would have likely been found by someone sooner or later too. Generating a secure seed is the most important function, no idea how they could mess this up.
“Numerous LLMS” Agreed it should have been done by now but the code pre-dates this level of LLM by several years. The real issue is lack of independent auditing or at least a full team of talented devs, cryptographers, and pen testers.
The rumor is they were using a paid API account instead of running their own node. It's likely this WAS some random chud with an LLM.
OP, you are making the interesting assumption that the hacker wants to profit from it. You might want to consider that they have no intention whatsoever to do so and that the funds will stay on their receiving addresses for ever (maybe the private keys to those will be erased at the end of the campaign), and that what the hacker wanted wasn't at all the cash, but the satisfaction that bitcoin will never be the same. That last aspect is worth more than 21 million coins together. For all we know it was a state sponsored hit to test a recent LLM, and they just don't give a shit about the coins.
Then you could argue they're kinda pointless for the vast majority of people (expecting a large amount of people to roll dice/flip coins while following certain rules is laughable). There's got to be a better way to audit them than a non-coder running it through an LLM (most don't have access to frontier models, and even if they did, wouldn't have much of a clue how to interpret the results). For me it leaves a ? over the whole HW wallet industry, unless they find a better way to build trust than just a "it's open source".
It does not mean they just prompt it “find bugs” right? No doubt LLM is a powerful tool when you know what’s you’re doing. But pointing it to a huge codebase and expect good result is a bit naive - you really need to know what and where to look at. Anyway, don’t argue this might have helped you
all this means is that the bug was present in production between 2021 and last week which means no LLM in that timeframe audited their code. The bug was present that entire time and would have been found.
It'll happen more often until it becomes standard for devs to have an LLM go over their own codebase looking for vulnerabilities. So right now - where there is a mountain of existing code with vulnerabilities, is probably going to be the worst time.
Have you even read what the vulnerability is and looked at the offending lines? It’s an incredibly simple “amateur hour” type of error that you would expect any motivated ($$$) expert human to find, not to mention a frontier LLM.
1. Ok then I claim you can't guarantee a fair dice roll unless you take special precaution. So you can't assume you have a fair dice to begin with, or a fair coin. You went ad hominem when you mentioned my ''lack of understanding''. 2. I didn't update my Trezor firmware since ages but I sure will use an LLM AI to check its code next time I'll update. Yes, it takes a few min.
Unregulated markets and all that? This is the other side of the coin (pun unintended) rearing its ugly head. The freedom it provides also means there isn't as many, or potentially any, protections for the wallet holders when an attack like this happens. And with some light googling on ColdCard, they based in Canada and privately owned. They were also open source code, and the intention behind that was "people can check our work to see its safe" to put it plainly. It just so happens that also opened the door so when someone finally did check with a powerful enough LLM down the line, they either were checking with nefarious motivations or saw the vulnerability and succumbed to the temptation stealing a very substantial amount of BTC. Shutter the windows, lock the doors, turn the lights out, and disappear into the night. Oh man, thats super fucked. I hope CC face some kind of accountability and I wonder if we will ever find the identity of the attacker. Part of me wonders if it was someone inside of CC who noticed the opprotunity and took it.
You guys started our LLM with the -makenomistakes parameter, right? Because it's important, please tell me if you didn't I'm about to press the commit button.