So they are using AI pala. I think that is good since the process can be automated and they can scan more projects faster.
My only concern is, will all those findings really be confirmed exploitable vulnerabilities, or will some of them just turn out to be false alarms? If people only see thousands of reported issues without knowing how many are actually confirmed, it could easily cause unnecessary panic.
For me, the important part is still the verification after the AI finds something.
Bitcoin news reports that security researcher Rob Hamilton of the Bitcoin Red Team had to switch to Chinese open-source AI models after losing access to OpenAI’s Trusted Access for Cyber tools. The team, which has already found nearly 5,000 potential security issues in 29.8 hours, relies on AI to prioritize code reviews. Hamilton claims the restrictions hurt defenders more than attackers. The Coldcard exploit in July, which stole 1,816 BTC, has made security a top priority. Altcoins to watch may also face similar risks if AI tools remain limited.
https://www.kucoin.com/news/flash/bitcoin-security-researchers-turn-to-chinese-ai-after-openai-restrictionsGumagamit na din sila ng Chinese AI para maghanap ng vulnerabilities. So ang AI talaga sa ngayon at double edge standard. Pwede mong gamitin sa masama katulad sa Coldcard o gamitin sa mabuti katulad ng ginagawa ng Bitcoin Red team.
Sa findings naman sa tingin ko ibibigay nila to sa mga projects na nakitaan nila ng vulnerabilities at sila na ang mag access at syempre kung hindi ito false positive ay dapat nila i-patch na agad.