Damus
calle profile picture
calle
@calle
🚩 Bitcoin Red Team update 55 hours into the campaign

We're now 24 people working around the clock.

We've scanned 425 projects so far and have produced 1029 high+critical (H+C) findings.



We generated 6700 findings so far and are hitting 7.7 projects per hour.

Our H+C rate per person per hour is back at ~1 as we work off a massive backlog and as the team grows and naturally divides up roles.

We have hunters, wizards, outreachers, sugar daddies, and gigglers.



Our H+C ratio is at 15.4% of all findings, increased by a percentage point compared to yesterday.

This is great, our accuracy is stable, and even slightly increasing. We're trying out best to reproduce all critical findings in local regtests before reporting them to projects.



Our biggest bottleneck is outreach. Most projects don't have a SECURITY .md in their repos (19.5%). Only 13.1% have an email in there.

We're working on better ways to reach folks. In the mean time, the best thing you can do as a project maintainer is to leave an email address in your repo.



Thank you to the sponsors and donors who cover the costs of this campaign and help to keep it alive.

Specifically @OpenSats, FPuklowski, @vik sharma, and everyone who has donated to OpenSats Red.

https://opensats.org/funds/red

An incredible team of some of the most hard core Bitcoiners I know have assembled and dedicated their last days to this effort.

We've seen shit.

I don't want to reveal anyone personally, they can choose to do that themselves, but I think the way that people came together to join forces was and still is the most beautiful part about this entire program.

It makes me very hopeful, seeing so many people step up and give their time and energy to Bitcoin, especially during times of pain.

We're not done yet.

5246❤️93🤙9❤️8👍4🚀31
Small Batch Steve · 2w
I like the idea of these security MD files... interrsting.
king · 2w
Thx for all the work you and nostr:nprofile1qqsvak4cr0jzaarahhn98a9602e94sa2xt8u9dnjac8cns86lzp0z0spp3mhxue69uhkyunz9e5k7qg4waehxw309ajkgetw9ehx7um5wghxcctwvsyn87stand team are doing. How thorough are the assessments, do you rerun against completed repos (A) once you find additional attack vectors ...
Laser · 2w
"Most projects don't have a SECURITY .md in their repos (19.5%). Only 13.1% have an email in there." This is the smoking gun that reveals the complacency across the #Bitcoin space.
John ₿ Wick · 2w
Thank you for broadcasting to attackers the vulnerabilities are there! You are so stunning and brave!
VOLKER - Voice Of Logic Knowledge Experience & Responsibility · 2w
Looks like you need another agent just to prioritize the work and findings 🫪 Thank you all for your work. LMK if I can be of any assistance.
vinney...axkl · 2w
why didn't you use an open and permissionless funding model like https://grantless.org
TKay · 2w
Are Lightning implementations, Umbrel, start9, and other Lightning nodes in your scope of scrutiny?
S!ayer · 2w
Oh no not the gigglers nostr:nprofile1qqsxua0hju3e0j3jjhs0fjs0h3htnnreh6zm4lw4d0fhsgsv4rhwwnspzamhxue69uhhyetvv9ujuurjd9kkzmpwdejhgtcprdmhxue69uhhyetvv9ujumn0wd68yurvv438xtnrdakj7qgnwaehxw309amk7apww468smewdahx2tcjkk4fj
Aedifico · 2w
Do you also measure cost per outcome, or so? Would be interesting.
🇵🇸 whoever loves Digit · 2w
I know you're a lying faggot that has me muted so you won't see me ask this, but could you check if retro-crypto by bowler-bear will always convert BIP-39 seeds correctly? I noticed today its dice roll mode doesn't accept enough dice rolls for a 128 bit seed, which calls into question the entire im...
Diyana · 2w
Let me know if you need help with outreach, communications or community coordination. I am available and happy to help however I can.
Decentral · 2w
Tell us if a hardware wallet is weak please!!
Kevin's BLAKE2bacon · 2w
Glad you guys are having fun with your new empire! (I mean that sincerely.)
syntaxerrs · 2w
👍
OzzyHB · 2w
Surely node software's are going to be targeted..
incoghs102 · 2w
Incorporatating the security[.] md into my project stack now.
Eddie · 2w
Why quantity over quality?
Branca playing blake2b · 2w
All the fed working together to bring down the remains. Pathetic clowns.
Pixel Survivor · 2w
The Bitcoin Red Team, now 24 volunteers, has scanned 425 projects and discovered over 1,000 high and critical security vulnerabilities using AI-assisted audits. it matters because this rapid-response security initiative helps projects patch vulnerabilities faster, especially crucial after the Coldca...
BitLo · 2w
Bitcoin’s immune system is alive and well.
Sun of the Moon · 2w
Conspiracy theory: Coldcard Hack was the bootloader for the Red Team Feds to burn it all down... ... too soon🤔🤪
james_r · 2w
psyop
Akamaister · 2w
This is very encouraging!
arbadacarba · 2w
🤔 Added a reverse lookup to find clones on nostr git announcements for repos from github / codeberg / gitlab / gitea to enable you to DM them on nostr. findReposBySource returns sourceurl, npub, repourl and profile url with more repos of that npub. You could also look for external identities ann...
Tauri | Bitcoin BLAKE2b · 2w
https://blossom.primal.net/4cae4efc647abc0e46a278b5b8436d28486fce5ce7ccc4b165d621c18c82b9b0.png
Cypherpunk AI · 2w
Interesting finding volume, but what's the distribution of H+C issues by project type and severity score?
Stephan · 1w
What doesn't kill us makes us weirder.
Kevin Ravens₿erg ⚡️ ☁️ · 1w
Anything in LNBits or BitTipBot so far?