Damus
aljaz profile picture
aljaz
@aljaz
Can we maybe stop screaming how many critical vulnerabilities were found in all the projects that are being scanned are found, this is pure insanity.

Why are you painting an even bigger target on all the projects? Scan the repos, contact the maintainers privately and stfu about it so not everyone and their mom gets curious since you are so loudly proclaiming tons of vulns

Everyone is always so opinionated and loud about responsible disclosure but now that theres a "bitcoin red team" we are all screaming about critical vulns they keep discovering?
359❤️18💯5❤️3🧡3🤙2🎯1
Laser · 1d
Disagreed, sir. The scare should be as large as possible to ensure the commensurate change in security posture actually takes place. Companies are lazy; it takes a really life changing scare to change them.
DarthCoin · 1d
Next move: create a "black team" that verify the "red team" 😂😂😂
whit · 1d
Nah https://blossom.primal.net/d197509dd2562f233f42a081c8423c928503e6e1b6176eee82f661cd52ab963d.gif
Financial Parasites · 1d
They need more funding from open sats. That’s their justification lol
Rotisserie Bastard · 1d
nostr:nprofile1qqs9pk20ctv9srrg9vr354p03v0rrgsqkpggh2u45va77zz4mu5p6ccpzemhxue69uhks6tnwshxummnw3ezumrpdejz7qgwwaehxw309ahx7uewd3hkctc0c969u food for thought my guy
LightningBuck · 1d
Because this is not an operation to save Hodlers, it is an operation to save opensats.
Matt - Not Your Entropy, Not Your Coins · 1d
I think this is fair if the ultimate goal is to prevent bad outcomes. You're basically just lowering the cost of vulnerability discovery for bad actors by paying for the LLM use and telling them where the weaknesses are.
Roy Merritt (‘The Burning Man’) · 1d
No! Keep digging! Keep sharing! I am happy to donate to the bitcoin red team!
CptKook · 1d
nostr:nprofile1qqsvak4cr0jzaarahhn98a9602e94sa2xt8u9dnjac8cns86lzp0z0sprfmhxue69uhhyetvv9ujummjv9hxwetsd9kxctnyv4mqzynhwden5te0danxvcmgv95kutnsw43qv0yah3 and nostr:nprofile1qqs9pk20ctv9srrg9vr354p03v0rrgsqkpggh2u45va77zz4mu5p6ccpremhxue69uhkummnw3ez6ur4vgh8wetvd3hhyer9wghxuet59uqsuamnwvaz7tmev9382t...
StellarStoic · 1d
No wander Cramer is selling all his Bitcoin 😀
Kayne · 23h
Bitcoin red team is a scam, that's why. Half these vulnerabilities they are finding are not even real. Like they are trying to drive consumers away from certain products or they're trying to frame certain companies as incompetent. And all the members just happen to be core 30 supporters that pr...
Eddie · 22h
If you let AI analyse code that's known to be safe, it will still find something to change and weaken the security over time. https://arxiv.org/html/2506.11022v1 So I don't understand what OpenSats is trying to achieve here,..
Pixel Survivor · 21h
Valid point. Shouting about critical vulns before maintainers can patch doesn't serve anyone except attackers. Responsible disclosure is responsible because it's private, not loud.
xlh155 · 10h
Valid point but using AI to prod other bitcoin projects will be an obvious play to any black hat given the coldcard debacle - hopefully red team is just front running them. Maybe we have got this far without a serious hack because people didn’t believe there would be something as simple as an entr...