Kimi K3 uncovered 5,000 security vulnerabilities in a day, is the Bitcoin ecosystem's security extremely dangerous?

CN
50 minutes ago
Bitcoin security is "extremely bad": AI discovered nearly 5,000 vulnerabilities in one day.

Written by: Forbes

Translated by: AididiaoJP, Foresight News

Bitcoin and cryptocurrency traders have yet to recover from a massive attack worth approximately $100 million, which once ignited panic over a new round of price drops.

Since the news of the hardware wallet Coldcard being attacked first emerged, Bitcoin's price has rebounded, but it still hovers near recent lows. Traders are on edge, fearing another severe shock.

Against this backdrop, Bitcoin developers used AI tools to uncover nearly 5,000 security vulnerabilities across nearly 400 projects in just 24 hours. The situation has been described as "extremely bad."

A team of volunteer Bitcoin developers is conducting a large-scale, coordinated security audit. They have confirmed that the overall security status of the ecosystem is "extremely bad."

In 24 hours, they scanned about 390 Bitcoin-related projects and discovered a total of 4,962 security vulnerabilities, including 85 critical vulnerabilities and 635 high-risk vulnerabilities. The vast majority of the vulnerabilities have been verified by the project teams.

"We have grown to 16 people, distributed globally, working around the clock," an anonymous developer of the Cashu ecash protocol, Calle, wrote on X, "We are conducting a large-scale ecological security audit of the Bitcoin codebase."

The audit team is using the Kimi K3 model from Moonshot—an open-source AI tool from China. Calle revealed that the team spends about $10,000 daily on computing power, which is covered by OpenSats.

"We have been working non-stop day and night," said Rob Hamilton, the CEO of Bitcoin insurance company AnchorWatch and a member of the audit team, on X, "The team has already found some 'critical issues.'

The efficiency of this audit is astonishing. Some developers state that on average, they can uncover a critical vulnerability almost every hour. AI is simultaneously becoming an accelerator for both defenders and attackers—this has already been hinted at in the recent Coldcard incident.

Over the past year, Bitcoin's price has significantly retraced, and the market is already highly sensitive to further declines. The sudden outbreak of hardware wallet security incidents has brought the question of "whether self-custody is truly secure" back to the forefront.

Last week, the Coldcard Bitcoin hardware wallet was exploited, with nearly 2,000 Bitcoins (worth just over $100 million) being drained from over 5,200 addresses within a few days. The attackers exploited a key generation flaw that has existed for five years.

The Coldcard team has urgently called on users to move their funds and repeatedly requested everyone on social media to "help spread the message."

"Please treat this as an emergency," the official Coldcard account wrote, "immediately migrate your funds. Follow the recommendations for your device model, upgrade your device, generate a new seed, and carefully transfer your funds... the threat is ongoing."

A wallet address linked to the hackers currently holds about $36 million in Bitcoin, most of which is believed to be stolen. Since the incident was exposed, the address has received multiple incoming transfers, some of which included messages via Bitcoin's OP_RETURN feature.

One message stated: "I launder BTC, do KYC, and cash out. I receive 10%." This has been interpreted as a recruitment for money laundering, trying to turn hackers into clients. More messages directly plead for the return of the stolen Bitcoins.

On-chain analysts have pointed out that the vulnerabilities have been made public, drawing high attention, and the cutting-edge large models are almost accessible to everyone, which means multiple hacker teams may already be simultaneously researching ways to expand their gains. "You are racing against time."

Another anonymous co-owner of bitcoin.org, Cobra, bluntly expressed that he has a "very bad feeling"—AI is likely already involved in the draining of funds in this Coldcard event.

This AI-driven vulnerability scanning, along with the previous large-scale theft at Coldcard, is pushing the security issues within the Bitcoin ecosystem to a new breaking point. Developers are using AI to accelerate vulnerability discoveries, while attackers may also exploit the same tools to rapidly take advantage of these vulnerabilities. The window for fixing and migrating is shrinking.

Currently, Bitcoin's price is still fluctuating at low levels, with traders waiting for the next potential shock. This audit, which burns $10,000 daily in computing power, may just be the beginning of a larger scope of security checks.

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink