Bitcoin Forum
August 11, 2026, 01:03:07 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 [3]  All
  Print  
Author Topic: What's your take on this moment?  (Read 478 times)
tread93
Hero Member
*****
Offline

Activity: 1988
Merit: 674



View Profile
August 09, 2026, 12:23:19 AM
 #41

I am highly disappointed in every crypto companies out there, like AI is everywhere now, what are they doing that these people are the ones coming together to form a team? The likes of Red team should be the ones creating open source hardware wallet, because that's are ready to find every vulnerability possible.

This get together is something that Ledger and others should form themselves, hardware wallet companies should be the ones doing this, why are third parties coming together to clean the mess of people who are supposed to protect against vulnerabilities in crypto space? I don't get it.

This is a great point. I mean I am sure that big cold storage wallet companies like Trezor have a very robust team that is searching for vulnerabilities and of course they are open source so you have pretty much anyone who can take a look and point out a vulnerability, right? But I agree, these companies should already have a pretty secure and advanced security solution to actively look for faults and loop holes and be watching and maintaining this nearly 24/7 to keep the confidence of their clients. Coldcard really messed up.

Tamaperdana
Full Member
***
Offline

Activity: 882
Merit: 208



View Profile
August 09, 2026, 02:23:41 AM
 #42

After the incident of Coldcard happened, a group of people which consist of user @Rob1Ham on X (CEO of AnchorWatch), @callebtc , @PortlandHODL, @danielabrozzoni, @lylepratt, @stutxo, @benthecarman, @thesimplekid, etc.

Created a team called Bitcoin Red Team, aka Red Team, whose aim was to work endlessly launching a huge wave of reviews on many core Bitcoin projects, especially the crypto libs, wallets, infra, and more.
Checking for critical exploits and vulnerabilities through the use of human effort and AI (like Kimi K3, GPT Sol, Fable, Opus, and GLM5.2).

In 27.5 hours, with almost 10k spent in 24hours, and they have reported  

1 4,962 security findings
2 85 critical vulnerabilities
3 635 high-severity vulnerabilities


Which the ckpool was among the security findings the Red Team detected, and according to @-ck statement, all the possible security holes were swiftly addressed.

At the time of posting this, the Red Team has no website or GitHub repository link.
Having people like this who care about Bitcoin is truly helpful and makes us, as Bitcoin investors, feel safer. So, I think their efforts deserve appreciation. Checking whether a wallet or any project supports Bitcoin will clearly improve control, and any problems can be detected immediately. Furthermore, I didn't expect the numerous vulnerabilities they discovered in the systems of these projects or wallets.

If these issues aren't addressed thoroughly, incidents like the Coldcard incident could recur in the long term. Fortunately, there are still people like them who care about the Bitcoin and crypto community. Hopefully, this will help Bitcoin and all its projects remain secure and improve. If an incident like Coldcard were to happen again,, it would be traumatizing for many. Hopefully, things will improve now.

jcojci
Full Member
***
Offline

Activity: 1918
Merit: 202


Bitz.io Best Bitcoin and Crypto Casino


View Profile
August 09, 2026, 07:52:41 AM
 #43

They should get a sponsor to cover their costs because those costs could increases in the future. Imagine how much it costs for a month, a year and if they just waiting for the donation, that will takes time. Bitcoin community appreciates their works helping with security and finding many core Bitcoin projects.

That should gives awareness to all Bitcoin project owners and their teams to secure the projects. They can collaborate with the Red Team to find the holes in their project and fix them immediately.

pawanjain
Legendary
*
Offline

Activity: 3500
Merit: 1004


Nothing lasts forever


View Profile
August 09, 2026, 08:37:02 AM
 #44

After the incident of Coldcard happened, a group of people which consist of user @Rob1Ham on X (CEO of AnchorWatch), @callebtc , @PortlandHODL, @danielabrozzoni, @lylepratt, @stutxo, @benthecarman, @thesimplekid, etc.

Created a team called Bitcoin Red Team, aka Red Team, whose aim was to work endlessly launching a huge wave of reviews on many core Bitcoin projects, especially the crypto libs, wallets, infra, and more.
Checking for critical exploits and vulnerabilities through the use of human effort and AI (like Kimi K3, GPT Sol, Fable, Opus, and GLM5.2).

In 27.5 hours, with almost 10k spent in 24hours, and they have reported  

1 4,962 security findings
2 85 critical vulnerabilities
3 635 high-severity vulnerabilities


Which the ckpool was among the security findings the Red Team detected, and according to @-ck statement, all the possible security holes were swiftly addressed.

At the time of posting this, the Red Team has no website or GitHub repository link.



I am not really sure if this is good or bad because it weakens our trust on these projects.
Besides that, these are huge numbers but we are not sure if all of those are actually true and valid issues.
Further more, what are they spending 10k on per day ? Isn't it too much just to find issues in existing projects?

Popkon6
Hero Member
*****
Offline

Activity: 1414
Merit: 537



View Profile WWW
August 09, 2026, 08:57:11 AM
 #45

They should get a sponsor to cover their costs because those costs could increases in the future. Imagine how much it costs for a month, a year and if they just waiting for the donation, that will takes time. Bitcoin community appreciates their works helping with security and finding many core Bitcoin projects.

That should gives awareness to all Bitcoin project owners and their teams to secure the projects. They can collaborate with the Red Team to find the holes in their project and fix them immediately.

Bitcoin Red Team seems to be undermining our trust, because they have found so many flaws, it is really impressive. Because they are spending 10k per day, does this amount of money seem like a lot?
And is it really necessary to spend so much? It seems suspicious to me, because if this continues day after day, week after week and month after month, can you imagine how much it will cost?

Stalker22
Legendary
*
Offline

Activity: 2324
Merit: 1632



View Profile
August 09, 2026, 12:30:56 PM
 #46

I am not really sure if this is good or bad because it weakens our trust on these projects.

It may be uncomfortable in the short term, but it is 100% a net positive.  This does not weaken our trust in these projects, especially if they actively respond to these vulnerabilities and promptly patch them. Any of these critical bugs could mean another multi-million-dollar drain tomorrow if left unpatched.

Besides that, these are huge numbers but we are not sure if all of those are actually true and valid issues.

Do we have reason to doubt their findings?  But just for the sake of argument, lets say that 80% or 90% of the raw output turns out to be low-priority noise or edge cases, we still have 85 critical and 635 high-severity vulnerabilities that have been verified by human security engineers that needed fixing immediately.  Some of them have already been confirmed and fixed, as in the case of BTCPay Server.

Further more, what are they spending 10k on per day ? Isn't it too much just to find issues in existing projects?

API token costs.  Besides, no one said that they are still spending $10k a day.

█████████████████████████
███████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
███▀░░██████▀░▀████░░▀███
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
███▄░░██████░░████░░▄███
█████▄░░▀███░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
 ROOBET .██████. BET ON WORLD CUP  🗺 ⚽︎.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
|.
   BET NOW   
henmark
Sr. Member
****
Offline

Activity: 1447
Merit: 340



View Profile
August 09, 2026, 05:30:43 PM
 #47

They should get a sponsor to cover their costs because those costs could increases in the future. Imagine how much it costs for a month, a year and if they just waiting for the donation, that will takes time. Bitcoin community appreciates their works helping with security and finding many core Bitcoin projects.

That should gives awareness to all Bitcoin project owners and their teams to secure the projects. They can collaborate with the Red Team to find the holes in their project and fix them immediately.
They do have donators and supporters for this, if you read this tweet, you will notice that they have mentioned the funds being covered by OpenSats, which seems to be a firm for funding technologies probably related to Bitcoin or decentralization or something. Apparently, NVK has been a part of the board of the OpenSats organization and stepped down on 2 August, after the recent attack.

Anyway, the tweet also mentions that people can make donations in tokens or accounts that they can use for their work, which means they are not going to be short on funds, I believe. Their work is getting a lot of appreciation and getting highly widespread across the internet, which means that a single announcement from them that they need funds to continue will probably pour in a lot of donations from different individuals and companies who know the value of their work, because if a company is able to save their reputation and their customers from a similar exploit or attack, they would surely appreciate it.

They have already found so many vulnerabilities and reported them, I'm sure those companies or owners of the software or apps will be appreciative of their work and would always be ready to donate some funds towards their work.

Somegory
Full Member
***
Offline

Activity: 378
Merit: 186



View Profile
Today at 09:51:26 AM
 #48

After the incident of Coldcard happened, a group of people which consist of user @Rob1Ham on X (CEO of AnchorWatch), @callebtc , @PortlandHODL, @danielabrozzoni, @lylepratt, @stutxo, @benthecarman, @thesimplekid, etc.

Created a team called Bitcoin Red Team, aka Red Team, whose aim was to work endlessly launching a huge wave of reviews on many core Bitcoin projects, especially the crypto libs, wallets, infra, and more.
Checking for critical exploits and vulnerabilities through the use of human effort and AI (like Kimi K3, GPT Sol, Fable, Opus, and GLM5.2).

In 27.5 hours, with almost 10k spent in 24hours, and they have reported  

1 4,962 security findings
2 85 critical vulnerabilities
3 635 high-severity vulnerabilities


Which the ckpool was among the security findings the Red Team detected, and according to @-ck statement, all the possible security holes were swiftly addressed.

At the time of posting this, the Red Team has no website or GitHub repository link.



My take on this is that there are still many vulnerabilities within this crypto space, we need a more effective way to start going after those vulnerabilities before it turned very ugly for us just like what happened with ColdCard.

AI will help alot, and I believe that AI is been used by hackers to find vulnerabilities before the team of a crypto company can, it's completely weakness for Blockchain companies to not add AI to their security chain to find problems before someone else.

The Red Team won't do it all alone,

oll
Full Member
***
Online Online

Activity: 334
Merit: 153


old oll


View Profile
Today at 12:54:19 PM
 #49

Which the ckpool was among the security findings the Red Team detected, and according to @-ck statement, all the possible security holes were swiftly addressed.
At the time of posting this, the Red Team has no website or GitHub repository link.

I sincerely thank these guys for their initiative. They made a global deal in less than a couple of days. I am one of those investors who only hold bitcoin and no other assets, and therefore I would always like to be sure that my way of holding BTC will lead to the fact that bitcoins will always be safe, but unfortunately, incidents such as the one with coldcard show that even if you once you bought bitcoins a long time ago and just keep them from year to year, you also cannot be safe, because you need to constantly check the news, because new vulnerabilities are being discovered. Because once upon a time, developers (ordinary people who make mistakes) wrote this code for the wallet, and even the oem themselves cannot be absolutely sure that it will not contain any new errors over time and progress, and therefore one must always keep abreast of the news. At least watch the social networks of those wallet developers where you currently keep your bitcoins.

Pages: « 1 2 [3]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!