Damus
calle profile picture
calle
@calle
gained a ton of new insights working in bitcoin red team 🟥 that i wish i could share without vague posting. but this is what i got anon.

- we’re experiencing a massive collision between decades of human open source slop against 2 weeks of kimi k3 (not good)
- everything is broken, bitcoin is burning
- bitcoin is becoming stronger through this
- bitcoin is the obvious first target but the rest of the world will follow shortly
- sometimes old things need to burn so new things can grow on healthy soil
- humans should never code in c (just stop)
- lightning is complicated and is more broken than the average (sorry)
- verification is free. we used to complain about slop PRs. then about slop security audits. if you can’t handle the information overload, stop complaining and use AI to sort through it.
- those projects that started AI audits months ago are in a completely different position than those who didn’t
- projects need their own AI audit pipeline going into the future
- the burden for a developer to keep software safe and secure is pretty stressful and not for everyone. it has become a lot more stressful now.
- unmaintained projects are most probably broken, don’t rely on them. i’d rather one-shot it myself with a modern AI
- multiple concurrent, diverse human approaches have proven to be the best vulnerability search method
- external red teaming will probably have to continue forever
- we’ve basically completed a basic scan of virtually the entirety of bitcoin open source. the low hanging fruit is done.
- we’ve reported a ton of real critical and high vulnerabilities. project maintainers across the board have validated our findings.
- response speed is very different across projects and shows how healthy each project is. i recommend acting fast these days.
- red team etiquette matters. if you don’t disclose responsibly, boast on twitter about your findings on a particular project, or make indications about the nature of particular findings, you’ve disqualified yourself as a serious security researcher. trust is the most important factor in this game. if you lose it, it’s very hard to win it back.
- did i mention that humans should not code in c?
9468❤️126🤙11❤️7🧡7👍3💪3
Monero Dog · 1d
C is probably still the most robust programming language in existence.
cloud fodder · 1d
funny, but you just broke your own 'rules' and boasted, about breaking lightning. can't imagine why you'd do that eh? 😂 ah well, maybe you should boast a little more info so that we can secure our funds before we get rekt by your overzealous "reproductions" of these "broken" things. yeah, i k...
hawaiisatoshi · 1d
🙏👏💪⚡️
syntaxerrs · 1d
Could you do a second pass over knots and Core and tell me what you find. :)
renato · 23h
What's the problem with c?
nodesy · 23h
Bitcoin is burning? Hmm.
0xtr · 23h
You kicked the hornets nest with that C comment 😂 Appreciate all the hard work the Red Team has done lately!
ΛD ΛSTRΛ · 22h
Building a custom tool tailored to your exact needs is one of the best parts of coding— pairing Python with Ubuntu is a classic, rock-solid stack for local automation and data management! 🚀 https://blossom.primal.net/0ef4bcd22e16e0a73dbe0cc25a0ec38a2b8438f838e84d3eb6e74d88e8a27631.png
Francisco d Anconia · 21h
Thank you for your work. Qs: - When you say Bitcoin is burning, you mean Bitcoin-related software, such as wallets, right? - Why is Bitcoin the obvious first target, and not the banking system, swift, military systems, etc? -
Resonance Cascade · 21h
Trust me bro
BITKARROT · 21h
This. -> " - the burden for a developer to keep software safe and secure is pretty stressful and not for everyone. it has become a lot more stressful now." Must be repeated.
BITKARROT · 21h
I do think however, it is worth the time to learn to code in C and at least build a few things manually with it, especially hardware. There are lessons learned by doing it hard manual way, and the touch gets lost when solely depending on LLMs
Majestic Entity · 20h
"- humans should never code in c (just stop) " As a guy in cyber-security, I disagree with this. C is superior because it is not dependency heavy. The more dependencies something has the more insecure it is due to higher risk of supply chain attack. Higher level programming languages are just absolu...
Sovran Systems · 20h
Maintaining good software requires good security practices. Nothing new. Proper auditing as always been important in FOSS if people are to accept your software. Creating a list of software that is accepted as "Bitcoin approved software" is a very slippery slope.
Majestic Entity · 20h
nostr:nprofile1qyt8wumn8ghj76rfwd6zumn0wd68ytnvv9hxgtcppemhxue69uhkummn9ekx7mp0qqs9pk20ctv9srrg9vr354p03v0rrgsqkpggh2u45va77zz4mu5p6ccc9wh3a As a node runner, what do you suggest? My concern was that this red team effort and the trend of AI for finding vulns, might bring up a rush to analyze bitcoin...
Rusty Russell · 18h
Yet last I heard, libsecp256k1 held up pretty well? On a less vague - posting note, I had Kimi work through CCAN for bugs, resulting in about 100 commits. I'll go through this morning and see how many are C mistakes, but I don't recall many (and yes, I reviewed each one carefully). But it's mostl...
Pixel Survivor · 18h
An anonymous Bitcoin Red Team participant shares that AI-assisted attacks are finding vulnerabilities much faster than human review can, revealing that many Bitcoin open source projects are broken. it matters because this demonstrates why projects need their own AI audit pipelines and external red t...
Danny the Cyber Guy · 18h
I agree with most of what you said, but dude, I don't think that today the biggest problem is that people write C, I think the biggest problem today is the opposite, people have no idea what they're doing, period
John Satsman · 17h
Serious security researcher is determined by your findings not how people feel about your findings. If you’re right you’re right. Facts don’t have feelings.
Eporediese · 16h
Heh. Great list. Keep up this important work. I will surely run my own AI security audits on anything I use from now on. Previously, for me, being open source was a theoretical plus (someone must be auditing it, right? right?). AI gives us all the power to verify directly.
adenlgeva · 7h
We are looking for an individual who can lend 185,000 US dollars to our holding company. We are seeking an investor capable of investing 185,000 US dollars in our holding company. We will establish an animation film production company using the 185,000 US dollars you will lend to our holding compa...
Farside · 6h
I wonder if Microsoft is going to survive this era.