Bitcoin Forum
August 10, 2026, 07:52:01 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2]  All
  Print  
Author Topic: Critical vulnerability discovered in BTCPay Server  (Read 324 times)
DanWalker
Hero Member
*****
Offline

Activity: 2688
Merit: 590


Leading Crypto Sports Betting & Casino Platform


View Profile
August 08, 2026, 08:52:18 AM
 #21

As open source projects are being targeted now, what then is our last line of defense? A lot of people suggested in other posts that using multisig wallets and generating the seed phrase offline and others, but are these methods enough to protect people's money. I really do not feel at ease when I see  with open source system because they were supposed to be rhe safest means of storing Bitcoin.

In fact it is not correct to say that Open source mean the safest. Also finding a vulnerability does not mean that open source is unsafe.

Big advantage of open source is that you can easily inspect or audit the code and even if a vulnerability is found, it can be patched very quickly. But open source will never free us from security responsibility.

Anyway, the most sensible approach for me is to reduce exposure of our fund. We can use small hot-wallet for daily spending. And for big saving we should use properly configured multisig. I agree with you, we should practice keeping seeds offline and keeping backups in separate place. And we should not keep more BTC than necessary in any internet-facing service.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
Pmalek (OP)
Legendary
*
Offline

Activity: 3584
Merit: 9435



View Profile
August 08, 2026, 03:40:11 PM
 #22

The ColdCard case could be the beginning of something good and so far it's looking like it, maybe from now on the main focus will be 100% on the vulnerabilities on the Blockchain system.
It's always going to be a race between good actors vs bad actors. The Coldcard case has shown that both types exist (as if we didn't know that before). Some people use AI to help them take advantage of vulnerabilities to steal money. Others use it to help discover and correct problems.


And for big saving we should use properly configured multisig. I agree with you, we should practice keeping seeds offline and keeping backups in separate place.
If the keys are not generated with enough entropy, a properly generated multisig won't help you. If 2/3 keys in a multisig setup were generated by Coldcard, hackers would have the needed quorum to empty such addresses. Keeping your keys offline won't help either. Coldcard keys were offline.


Anyways, we are moving into of topic territory here so let's get back to BTCPay Server stuff.

Video instruction for updating BTCPay Server on Umbrel:
https://x.com/nmfretz/status/2085966668011028533

Two addresses connected to the theft of funds from BTCPay Server have been identified. Luckily, the scammers haven't stolen much. One contains 1.74760889 BTC, the other 0.46608022 BTC
https://x.com/pavlenex/status/2086012989262401863

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
logfiles
Copper Member
Legendary
*
Offline

Activity: 2800
Merit: 2386



View Profile WWW
August 08, 2026, 03:58:21 PM
 #23

<...>
The warning shots were already there, but the hackers were most targeting smart contracts of different DeFi and crypto bridges. They had all the time to use AI to detect some vulnerabilities and have them fixed

I guess they are not going to act accordingly though I feel like there will always be avulnariabilty waiting to be discovered. The issue is who discovers it. The good actor or the bad actor?

▄███████████████████████▄
███████████████████████
████████████▀▀██████████
████████████████████████
██████████▄▄██████████
█████████████████████
███████████████████████
█████████████████████
██████████▀▀██████████
████████████████████████
██████████▄▄████████████
███████████████████████
▀███████████████████████▀
 
 MoBit 
████
██
██
██
██
██
██
██
██
██
██
██
████
 NO   LOGS
 
 LOW  FEES
 
 PGP  GUARANTEE
████
██
██
██
██
██
██
██
██
██
██
██
████
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
Faisal2202
Hero Member
*****
Offline

Activity: 2016
Merit: 604


#kycfree 🗽


View Profile WWW
August 08, 2026, 08:55:58 PM
 #24

Am just fascinated by how AI has quickly become a concern to open source wallets when it is quantum computers that we should have been more scared off. If AI is already doing this, what chance would we stand against quantum computers?
Brother, since the start of 2026, I haven't gone a single day or week without hearing about a hack in the DeFi sector. Bridges, liquidity pools, and other platforms are being exploited by hackers who are finding even the tiniest loopholes in them and then draining as much money as they can. I have read about almost every hack since the start of 2026, and I can tell you for sure that this year could see an all-time high in hacking incidents.

But the last week of July was very calm. I didn't hear about any such incidents during that week, but eventually, I heard about Coldcard, Zeus Wallet, Boltz Swap, then BTCPay Server, and so on. I am sure this month is going to be a crazy month for platforms that still haven't prioritized strengthening their security.

I know what I am going to say is very brutal for those who have lost their funds, but I think this is just one phase. After this phase, AI might become less useful for finding these vulnerabilities. It is like preparing these projects to defend against AI-driven attacks so they can eventually be better prepared for quantum computers.

▄███████████████████████▄
███████████████████████
████████████▀▀██████████
████████████████████████
██████████▄▄██████████
█████████████████████
███████████████████████
█████████████████████
██████████▀▀██████████
████████████████████████
██████████▄▄████████████
███████████████████████
▀███████████████████████▀
 
 MoBit 
████
██
██
██
██
██
██
██
██
██
██
██
████
 NO   LOGS
 
 LOW  FEES
 
 PGP  GUARANTEE
████
██
██
██
██
██
██
██
██
██
██
██
████
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
OsaiEmma
Full Member
***
Offline

Activity: 434
Merit: 173



View Profile
August 09, 2026, 06:22:07 PM
 #25

The ColdCard case could be the beginning of something good and so far it's looking like it, maybe from now on the main focus will be 100% on the vulnerabilities on the Blockchain system.
It's always going to be a race between good actors vs bad actors. The Coldcard case has shown that both types exist (as if we didn't know that before). Some people use AI to help them take advantage of vulnerabilities to steal money. Others use it to help discover and correct problems.
This is just hitting the nail on the head. AI can be dangerous and good depending entirely on who is operating it. And besides, before the emergence of AI, there have been automated tools used in different sectors, AI just made the whole process seem effortless and smooth. It's funny seeing forum members saying AI will take over the world lol, the only one taking over the world are the humans behind these AIs.

Well, I'm glad serious losses haven't occurred yet with respect to this BTCpay vulnerability, good one from the red team and every other person who assisted. Even though the coldcard case left a sour taste in our mouth, at least it has significantly improved the security consciousness of these service providers.

Livingleged
Full Member
***
Online Online

Activity: 280
Merit: 154



View Profile
Today at 06:40:20 AM
 #26


My guess is that this is another open-source project that's being targeted with the help of AI.
This is even similar to what happened with the COLDCARD firmware, from what I have be reading online the coinkite it self suspected the vulnerability and let people know about how unsafe it is if your seed were generated by the older models which  is the MK2 and MK3, because they discovered it was compromised. I also learnt that afterwards they also said the newer version of the firmwares were also not safe. The issue was with the seed generating entropy and even the Mk4 and 5 weren’t safe. What I don’t know is if people that were having their holdings on wallets that used the newer models in generating seed were also sweeped.
It’s best when vulnerabilities like this are discovered early and information is passed, that could save a lot.

Franctoshi
Hero Member
*****
Offline

Activity: 1624
Merit: 752



View Profile WWW
Today at 07:50:37 AM
 #27

Last month or two, I'm still trying to recall if it was either on the news or someone's YouTube channel I followed that said there's going to be different cyberattacks in the coming months, but because I doubted the source of the information, I didn't put effort into making some research about that or bringing it here, and if anyone has heard such information too.

These recent events not only teach me the level at which these AI tools can be used in the hands of attackers to do their exploits but also not to totally disregard some certain information just as this in the future and to put in some research efforts.


Our analysis confirms that the attacker used exposed LND .macaroon credentials to access funds. Only LND users are affected, but we recommend everyone update to BTCPay Server 2.4.2.

We found no evidence that on-chain or hot wallets created in BTCPay Server were affected.

Thank you to everyone in the community who sounded the alarm, helped us spread this information quickly, and contacted merchants. Please continue reaching out to BTCPay Server operators you know and ask them to update.

I am deeply sorry to the users who suffered devastating losses. If you were affected or have more questions my DMs are open.

What happens to the user who suffered devastating losses? Would the company compensate them or are their funds gone?


 
█▄
R


▀▀██████▄▄
████████████████
▀█████▀▀▀█████
████████▌███▐████
▄█████▄▄▄█████
████████████████
▄▄██████▀▀
LLBIT▀█ 
  TH#1 SOLANA CASINO  
████████████▄
▀▀██████▀▀███
██▄▄▀▀▄▄████
████████████
██████████
███▀████████
▄▄█████████
████████████
████████████
████████████
████████████
█████████████
████████████▀
████████████▄
▀▀▀▀▀▀▀██████
████████████
███████████
██▄█████████
████▄███████
████████████
█░▀▀████████
▀▀██████████
█████▄█████
████▀▄▀████
▄▄▄▄▄▄▄██████
████████████▀
........5,000+........
GAMES
 
......INSTANT......
WITHDRAWALS
..........HUGE..........
REWARDS
 
............VIP............
PROGRAM
 .
   PLAY NOW    
[/quote]
Code:
[center][table][tr][td][/td][td][size=20pt][nbsp]
[size=6pt][color=#65e]█▄[/td]
[td][font=arial black][size=24pt]R[/size][/font][/td]
[td][size=2pt]


[color=#fec]▀[color=#fda]▀[color=#fc9]▀[color=#eb7]▀[color=#eb5]▀[col
Aanuoluwatofunmi
Sr. Member
****
Offline

Activity: 1414
Merit: 465



View Profile
Today at 11:00:25 AM
 #28

Coldcard turned out to be an eye-opener to many other vulnerabilities already existing that we don't pay attention to. I know that one thing will definitely lead to another, and that is where we have to be more conscious of the kind of wallet used.

It is a time to increase more on the security measures we have in place before now, because definitely there so many hackers that are willing to continue in this manner of attack to areas of vulnerabilities to any type of wallet they discover has such weakness, more attacks are coming to be discovered, and we should always be updated with some of this information to prevent us from being a victim.

████
██
██
██
██
██
██
██
██
██
██
██
████
████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
 JACKSCLUB.io       FAIR CRYPTO CASINO & SPORTSBOOK     270% BONUS UP TO $20K   |    NO KYC       PLAY & EARN      [  PLAY NOW  ] 
████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
████
██
██
██
██
██
██
██
██
██
██
██
████
MusaMohamed
Sr. Member
****
Offline

Activity: 1596
Merit: 449



View Profile
Today at 01:13:26 PM
 #29

Coldcard turned out to be an eye-opener to many other vulnerabilities already existing that we don't pay attention to. I know that one thing will definitely lead to another, and that is where we have to be more conscious of the kind of wallet used.

It is a time to increase more on the security measures we have in place before now, because definitely there so many hackers that are willing to continue in this manner of attack to areas of vulnerabilities to any type of wallet they discover has such weakness, more attacks are coming to be discovered, and we should always be updated with some of this information to prevent us from being a victim.
The danger is with many AI tools nowadays, it's very helpful for hackers and attackers to quickly scan for similar security weakness from other wallets, other projects for example and can do their similar attacks.

The attacks and hacks on Coldcard is unprecedented but the attack pattern as I said already happened with altcoin projects. In the last two or three years, attacks on altcoin projects appeared like waves with projects attacked in similar way, on similar security weakness and actually there are reasons for that. I believe that attackers will try to do the same with other Bitcoin wallets if they find such wallets to do their attacking jobs.

It's about two weeks since Coldcard attack so people so far have already had enough time to move their bitcoins to new wallets. If they don't do that, and lose their bitcoins, they must be completely responsible for their careless ignorance. Create a new wallet with a passphrase, then move their bitcoin to that new wallet will help them safer during this turmoil time.

Satofan44
Sr. Member
****
Offline

Activity: 476
Merit: 1186


Don't hold me responsible for your shortcomings.


View Profile
Today at 01:34:43 PM
 #30

Quote
To stay safe, make sure that even after the update, you:
- Completely refresh macaroons and macaroons.db
- Completely refresh auth strings for other LN backends
- If you generated a hot on-chain wallet in BTCPay, you want to move those funds and recreate the wallet
https://x.com/BtcpayServer/status/2085771939008667869
At least it stayed pretty contained then, it could have been worse.

I haven't seen any evidence so far that this BTCPay Server vulnerability was exploited by AI.
This is a stupid counter claim, it is a pointless as it gets. What kind of fucking do you think will come to light, somebody's personal chat log with their offline and custom LLM?  Roll Eyes Most of these will be done by AI, security researchers are limited and they are busy. 99.999% of the internet users are not able to find even the simplest attack vector, so the more that we see surface the more we can be sure they are AI. No evidence is needed, we are not going to the fucking court. If you understood how AI actually worked, then you would not waste time talking about "evidence".

The time they took was very short, so they did an amazing job. Sophisticated attacks still require sophisticated attackers. Some people could pick the low-hanging fruit with some of the prompts, but they still need some understanding, because even to use a tool, you need some intelligence.
Most things can not be exploited unless they are done in very specific conditions that are not met in normal operating procedures, furthermore 99.99% of the internet users can't exploit even the simplest vulnerability so it is limited to those that are capable enough to use these kinds of things.

Am just fascinated by how AI has quickly become a concern to open source wallets when it is quantum computers that we should have been more scared off. If AI is already doing this, what chance would we stand against quantum computers?
Am sure every open source user should not just only upgrade their BTCpay if that's what they are using, but do so to other open source wallets services too, because we don't know how much AI knows at this time but we can anticipate this current threat and ensure counter measures to protect our funds.
Stop making shit up, quantum computers are not an issue at this time. You just spread more misinformation on top of other misinformation.


Pmalek (OP)
Legendary
*
Offline

Activity: 3584
Merit: 9435



View Profile
Today at 03:20:16 PM
 #31

What happens to the user who suffered devastating losses? Would the company compensate them or are their funds gone?
BTCPay Server isn't a company in the traditional sense. It's open-source software that has developers, contributors, and a community of users. BTCPay Server is free to use, so they don't earn any money from its community of users. They don't sell physical or digital products. Even if those who created the service wanted to, they couldn't compensate people unless they took money from their own pockets.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
Sandra_hakeem
Legendary
*
Offline

Activity: 1596
Merit: 1109


Leading Crypto Sports Betting & Casino Platform


View Profile WWW
Today at 04:34:41 PM
 #32

What happens to the user who suffered devastating losses? Would the company compensate them or are their funds gone?
BTCPay Server isn't a company in the traditional sense. It's open-source software that has developers, contributors, and a community of users. BTCPay Server is free to use, so they don't earn any money from its community of users. They don't sell physical or digital products. Even if those who created the service wanted to, they couldn't compensate people unless they took money from their own pockets.
The moment I saw the word "company" and "compensation", I just knew the user doesn't understand exactly what this is all about. A detailed explanation like you did might have done more harm than good. Keywords--- open-source, free to use.

His black-ass would have thought--- "Oh, the money is gone but no problems, that's on BTCPay sever". What's the interesting part about people like this? It's exactly how they get scared of investing a dime. [I don't understand? Well I don't care to]

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
uchegod-21
Hero Member
*****
Offline

Activity: 1764
Merit: 740


Are we ever seeing $126k again?


View Profile
Today at 06:04:37 PM
 #33

What happens to the user who suffered devastating losses? Would the company compensate them or are their funds gone?


It's an unfortunate incident none of them planned for. Yea it is a devastating loss, but compensations are coming from no one. BTCPay have done their part now in notifying the public about the vulnerability and what to do to protect their funds, BTCPay users need to act on this information urgently. You and I can help get this information to them just as the op of this thread has done already, by sharing this message in crypto communities we belong to, so affected persons will be aware. Information is power, anyone who owns bitcoins, including altcoins should not be too far away from crypto news and updates

█████████████████████████
████████
▀▀████▄▀█████████
███████
██████▐█░█████████
████████
███████▐█████████
████████
███████████████
███████
▀▀███▀▀▀▀▀▀▀██████
█████
███▄▄▄▄▄▄▄████████
█████████████████████████
█████████████████████████
█████████████████████████
██████████
█████████████
█████████
▄▄▄█████████
█████████████████████████
 
██
██
██
██
██
██
██
██
██
██
██
██
██
 
██
██
██
██
██
██
██
██
██
██
██
██
██
 
 
██
██
██
██
██
██
██
██
██
██
██
██
██
 
██
██
██
██
██
██
██
██
██
██
██
██
██
 
  PLAY NOW  
d5000
Legendary
*
Offline

Activity: 4732
Merit: 10975


Decentralization Maximalist


View Profile
Today at 07:24:09 PM
 #34

People who claim open-source wallet as safest probably generalize too much. I mostly agree with such statement only when such wallet is popular and have been around for some time. Even considering recent known vulnerability on open-source/source-code available wallet, IMO using closed source wallet isn't good alternative either, unless you deeply trust whoever create and maintain it.
I think all depends on the practices the open source dev team applies in their processes.

We might indeed see a larger wave of attacks in the coming weeks on crypto software, in particular also those who are a bit more "esoteric", and outdated versions. So it's best for everybody to update their wallets and tools to the latest version ASAP.

But I think in the long run open source developers will profit more from AI than hackers. Searching for vulnerabilities with AI should become standard procedure for every open source project, at least for those that either have to do something with "security" (e.g. SSL and similar libraries) or with finance, including "cryptocurrencies". And the advantage is that they can do it already before they submit a pull request publicly, from their own computer.

AI also makes creating automated test suites for software easier, a task that many developers hate, and that benefits the security of the tools. (For those that don't know: test suites are collections of small programs which simulate the most use cases of the program possible, in the case of Bitcoin software without moving real coins, not even on testnet. The bigger these suites are, the more bugs can be discovered early in the development process.)

Pages: « 1 [2]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!