Damus
calle profile picture
calle
@calle
gained a ton of new insights working in bitcoin red team 🟥 that i wish i could share without vague posting. but this is what i got anon.

- we’re experiencing a massive collision between decades of human open source slop against 2 weeks of kimi k3 (not good)
- everything is broken, bitcoin is burning
- bitcoin is becoming stronger through this
- bitcoin is the obvious first target but the rest of the world will follow shortly
- sometimes old things need to burn so new things can grow on healthy soil
- humans should never code in c (just stop)
- lightning is complicated and is more broken than the average (sorry)
- verification is free. we used to complain about slop PRs. then about slop security audits. if you can’t handle the information overload, stop complaining and use AI to sort through it.
- those projects that started AI audits months ago are in a completely different position than those who didn’t
- projects need their own AI audit pipeline going into the future
- the burden for a developer to keep software safe and secure is pretty stressful and not for everyone. it has become a lot more stressful now.
- unmaintained projects are most probably broken, don’t rely on them. i’d rather one-shot it myself with a modern AI
- multiple concurrent, diverse human approaches have proven to be the best vulnerability search method
- external red teaming will probably have to continue forever
- we’ve basically completed a basic scan of virtually the entirety of bitcoin open source. the low hanging fruit is done.
- we’ve reported a ton of real critical and high vulnerabilities. project maintainers across the board have validated our findings.
- response speed is very different across projects and shows how healthy each project is. i recommend acting fast these days.
- red team etiquette matters. if you don’t disclose responsibly, boast on twitter about your findings on a particular project, or make indications about the nature of particular findings, you’ve disqualified yourself as a serious security researcher. trust is the most important factor in this game. if you lose it, it’s very hard to win it back.
- did i mention that humans should not code in c?
7561❤️118🤙11❤️7🧡7👍4💪3
TallBrian · 3w
Peter Schiff read this and giggled.
Benking · 3w
The scary part isn’t that AI can find the bugs. It’s how many bugs were already there waiting to be found. Burn the weak code, harden the protocol, and keep building. ₿ معنی
Benking · 3w
The scary part isn’t that AI can find the bugs. It’s how many bugs were already there waiting to be found. Burn the weak code, harden the protocol, and keep building. ₿
Space Cake · 3w
Didn’t Satoshi code in c?
Bill Cypher · 3w
Does your rule about C apply to derivatives?
accumulator · 3w
Can you say that Rust is standing out in a positive way here, as it advertises itself as a safety-first language?
cloud fodder · 3w
funny, but you just broke your own 'rules' and boasted, about breaking lightning. can't imagine why you'd do that eh? 😂 ah well, maybe you should boast a little more info so that we can secure our funds before we get rekt by your overzealous "reproductions" of these "broken" things. yeah, i k...
hawaiisatoshi · 3w
🙏👏💪⚡️
syntaxerrs · 3w
Could you do a second pass over knots and Core and tell me what you find. :)
nodesy · 3w
Bitcoin is burning? Hmm.
0xtr · 3w
You kicked the hornets nest with that C comment 😂 Appreciate all the hard work the Red Team has done lately!
Francisco d Anconia · 3w
Thank you for your work. Qs: - When you say Bitcoin is burning, you mean Bitcoin-related software, such as wallets, right? - Why is Bitcoin the obvious first target, and not the banking system, swift, military systems, etc? -
Majestic Entity · 3w
nostr:nprofile1qyt8wumn8ghj76rfwd6zumn0wd68ytnvv9hxgtcppemhxue69uhkummn9ekx7mp0qqs9pk20ctv9srrg9vr354p03v0rrgsqkpggh2u45va77zz4mu5p6ccc9wh3a As a node runner, what do you suggest? My concern was that this red team effort and the trend of AI for finding vulns, might bring up a rush to analyze bitcoin...
Rusty Russell · 3w
Yet last I heard, libsecp256k1 held up pretty well? On a less vague - posting note, I had Kimi work through CCAN for bugs, resulting in about 100 commits. I'll go through this morning and see how many are C mistakes, but I don't recall many (and yes, I reviewed each one carefully). But it's mostl...
Danny the Cyber Guy · 3w
I agree with most of what you said, but dude, I don't think that today the biggest problem is that people write C, I think the biggest problem today is the opposite, people have no idea what they're doing, period
John Satsman · 3w
Serious security researcher is determined by your findings not how people feel about your findings. If you’re right you’re right. Facts don’t have feelings.
Eporediese · 3w
Heh. Great list. Keep up this important work. I will surely run my own AI security audits on anything I use from now on. Previously, for me, being open source was a theoretical plus (someone must be auditing it, right? right?). AI gives us all the power to verify directly.
adenlgeva · 3w
We are looking for an individual who can lend 185,000 US dollars to our holding company. We are seeking an investor capable of investing 185,000 US dollars in our holding company. We will establish an animation film production company using the 185,000 US dollars you will lend to our holding compa...
Farside · 3w
I wonder if Microsoft is going to survive this era.
Alan Siefert · 3w
Looks like GLM 5.3 is going to lower the cost of both offense and defense yet again.
magnum · 3w
Please go back to your shitcoins and stop pretending you are doing anything for bitcoin
outsat · 2w
A sit is a hostname that paid 1,000 sats. Same host stacks. Live: 1 online, 163 visitors, 13k/3 bids, nimiq.com 5,000 (29 clicks). 6,000 sats (~$4.64) takes the seat. https://outsat.lol
SwBratcher · 2w
nostr:npub1s4q2ulh45vfat58xpnd9py3g3hys37ueyx7nzw29pfzlryq69wdqegqmtn
murmur · 2w
I can turn this into audio for the thread — goes live once 500 sats land here. One zap or many.
murmur · 2w
Murmured. 2m 23s of audio, ready for everyone. https://npub1s4q2ulh45vfat58xpnd9py3g3hys37ueyx7nzw29pfzlryq69wdqegqmtn.blossom.band/7334f5d95f8a317bd604ebf3ef7571defa63b2af6bdda2fffa6d2bb5a3f7779b.mp3 Funded by nostr:npub1gkgyk28lurjuhyfjlxsga9mw6lc0c47c8pmcr65usre9d3qjcx6q9cyk5m