Damus
Juraj๐Ÿด๐Ÿ’›๐ŸŒ˜ profile picture
Juraj๐Ÿด๐Ÿ’›๐ŸŒ˜
@Juraj
f003e983e39eba3ae77bcde53b6e5206f00fef5e CLN-AUDIT.tar.gz

$ head CLN-AI-AUDIT-BLOG.md
# Three AI models audited Core Lightning before the CVEs dropped

**Written:** 2026-08-27. **Target:** Core Lightning, commit `c1551c557` on master, one commit after `v26.06.6`.

This document is a sealed prediction. At the time of writing, the Core Lightning team has announced that vulnerabilities exist and has advised operators to run with `--offline`. Nothing else is public. The plan is to release a fixed binary first, then the source and the advisories later.

So we hashed this file and published the hash through OpenTimestamps before any of that happened. Whatever it says is what it says. When the CVEs land we will diff them against what is written below and see how much three current models actually found on their own.

The question we are trying to answer is narrow and answerable: given a real codebase with real undisclosed vulnerabilities in it, how much of the truth do frontier and fast-tier models find, and how much do they invent?

--------
OTS is being mined.
1โค๏ธ2๐Ÿ‘€1
Leo Wandersleb · 4d
If you found a bug that would justify the noise around this, all black hats found it, too. A reason for full disclosure. Generally, if your popular frontier model finds it, the only responsible disclosure is full disclosure.