Sorry for the loss but was there not a warning like "Do not deposit real Bitcoin into these wallets". If they are confidence in what they built, let it go public and this happened, then the company can be sued.
The AI models do and can make mistakes. It's up to the developer to control them. In this case, it was completely my fault.
A seed phrase isn’t just secure because it looks random, but it’s because it security comes from cryptographically secure randomness generated by a trusted CSPRNG (cryptographically secure pseudorandom number generator).
Correct, but theoretically an LLM can call a function that uses a CSPRNG; it simply chose not to. In any case, never trust your guts with it. It may simply skip it.
Did you ever check the security vulnerability created by the AI? My guess would be either weak RNG as entropy source or k nonce (when signing the TX).
It does not have to do with k nonce, because I did not make any transactions spending from the wallet. I only sent BTC
to the wallet, and they were immediately drained. I did not check exactly what the issue is, but I'm certain Claude simply guessed the seed phrase (as in "guessed the next word") when I asked to generate the wallets. It did not use a CSPRNG or a standard way to create the wallet (such as with bitcoin-cli).
Considering the technology behind the LLM is stochastic, it's entirely plausible some kid out there (or 35-year old loser who stays in his mom's basement) has gathered millions of seed phrases the AI is likely to "guess" and is just waiting for his bots army to collect the money of the unfortunates.
Edit: Let me share you the TXID of the drain: f825ac515b8e1f1a3c93975bb445bb9ffd095be6e98aca70052b548678b5ab20. The attacker's address is
bc1q5mran5zu4rdzv4ced58hxmk6jldm28hkpj8888 and apparently, there are a few other people who've lost money too.