Bitcoin Forum
July 31, 2026, 07:08:01 PM *
News: COLDCARD users only: critical vulnerability risks funds stored on COLDCARD devices; immediate action required
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Open source wallet vulnerability  (Read 58 times)
Karl_3000 (OP)
Full Member
***
Offline

Activity: 364
Merit: 186


Bitcoin can not fail you


View Profile WWW
Today at 12:34:07 PM
 #1

Yes I know I should not go for close soruce wallets because I do not know the bug the developers have on the wallet. I do not even know if they are watching my wallet or having the my keys. There are several reports also of vulnerable close source wallets like the Trust wallet extension and Atomic wallet.

But as I was reading what Coinkite said on how Coldcard hardware wallet was drained, it said that it is possible that AI was used to find the vulnerability. The wallet company has been existing for 7 years which has been a very long time and make people have more trust in it because it is open source.

What if some wallet are vulnerable, open source, but AI is used to look for vulnerability on the code used for the wallet build and later used to steal many coins belonging to different people.

Satofan44
Sr. Member
****
Offline

Activity: 462
Merit: 1169


Don't hold me responsible for your shortcomings.


View Profile
Today at 01:02:48 PM
Merited by vjudeu (1)
 #2

Yes I know I should not go for close soruce wallets because I do not know the bug the developers have on the wallet.
False. The existence of bugs has nothing to do with the issues relating to closed source wallets. Both open and closed source wallets can and do have bugs all the time.

What if some wallet are vulnerable, open source, but AI is used to look for vulnerability on the code used for the wallet build and later used to steal many coins belonging to different people.
There is no difference whether an AI or a human finds a vulnerability in one of these pieces of software. If AI had not found the Coldcard vulnerability, some human eventually would have found it -- nobody was looking closely enough at this particular wallet with this kind of intent. This is nothing new and there is no difference of any kind neither in the risk nor in the consequences between the two, therefore you may close this thread now. All that AI does is in this context and nothing more:
1. Enable people who do not have the knowledge or experience to look for vulnerabilities to do so by paying money.
2. Enable people to speed up their work by paying money.



Most users are dumb about even the basics of IT, humans should have not been allowed to access technology devices without a literacy test but here we are. You SHOULD assume that what you are using can be compromised, instead because of lack of education and stupidity people assume the exact opposite of what they should: that it can not be compromised. For this kind of specific vulnerability you can protect yourself easily with:
1. Passphrases.
2. Multi-signatures across different wallets.

Case solved.

noorman0
Hero Member
*****
Offline

Activity: 2086
Merit: 857


[Nope]No hype delivers more than hope


View Profile WWW
Today at 01:10:41 PM
 #3

Doesn't every version update mean updating or adding a few lines of code? So, being open source for 7 years doesn't determine the age of the code.

Every update should also require a re-audit of the code. If security researchers don't find vulnerabilities first, attackers will. AI is just a powerful resource that can't do anything without prompting. Just like a knife.

Karl_3000 (OP)
Full Member
***
Offline

Activity: 364
Merit: 186


Bitcoin can not fail you


View Profile WWW
Today at 01:24:21 PM
 #4

False. The existence of bugs has nothing to do with the issues relating to closed source wallets. Both open and closed source wallets can and do have bugs all the time.
This is what this topic is about, I know the existence of bug is not about a wallet to be open or close source, but asking that it is possible AI can make the bug and vulnerability detection easier to find and used it to steal bitcoin on a trustworthy wallet later just like what happened to Coldcard. The way AI are used for bad things these days is too much and getting higher, I just hope that my wallets are safe from this as AI are getting advanced.

I am using passphrase for all the wallet that I am creating. It is very important to me and not a short passphrase.

Satofan44
Sr. Member
****
Offline

Activity: 462
Merit: 1169


Don't hold me responsible for your shortcomings.


View Profile
Today at 01:47:12 PM
Merited by vjudeu (1)
 #5

False. The existence of bugs has nothing to do with the issues relating to closed source wallets. Both open and closed source wallets can and do have bugs all the time.
This is what this topic is about, I know the existence of bug is not about a wallet to be open or close source, but asking that it is possible AI can make the bug and vulnerability detection easier to find and used it to steal bitcoin on a trustworthy wallet later just like what happened to Coldcard.
You are overthinking it because you have watched too many movies with AI and read too many marketing articles. It is very simple: In the traditional sense you can imagine a scenario where 1 person is looking for vulnerabilities in something. If you increase the number of people to 10, of course it is going to be faster -- but that is all that it is. So instead of people, they are using a tool to achieve a speed up by throwing financial resources directly at it instead of human resources. Will it lead to faster discoveries? Sure, in some cases it will work. But what about it? Don't imagine that it brings some Sci-Fi shit into this game, it does not. If you invest more resources (of any kind) into something like this, you achieve (some) speed gains. There's nothing more to it.

The way AI are used for bad things these days is too much and getting higher, I just hope that my wallets are safe from this as AI are getting advanced.

I am using passphrase for all the wallet that I am creating. It is very important to me and not a short passphrase.
A setup that involves a hardware wallet and passphrase and/or multisig is very unlikely to be compromised at the same time. Spread your coins across things and that is all that you can do. Nothing you do will ever give you a guarantee that you won't get hacked.

you may close this thread now.

Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!