BTC $62,730.04 -1.17%
ETH $1,872.83 -0.43%
BNB $604.29 -0.73%
XRP $1.00 -0.33%
SOL $75.34 -0.54%
TRX $0.3328 -0.24%
DOGE $0.0693 -1.07%
ADA $0.1797 -1.95%
BCH $205.12 -3.79%
LINK $8.81 +1.12%
HYPE $56.06 -1.89%
AAVE $85.88 -3.12%
SUI $0.6736 -1.84%
XLM $0.1585 -0.78%
ZEC $484.08 -1.39%
BTC $62,730.04 -1.17%
ETH $1,872.83 -0.43%
BNB $604.29 -0.73%
XRP $1.00 -0.33%
SOL $75.34 -0.54%
TRX $0.3328 -0.24%
DOGE $0.0693 -1.07%
ADA $0.1797 -1.95%
BCH $205.12 -3.79%
LINK $8.81 +1.12%
HYPE $56.06 -1.89%
AAVE $85.88 -3.12%
SUI $0.6736 -1.84%
XLM $0.1585 -0.78%
ZEC $484.08 -1.39%

discover

All
Article
Flash

Bitcoin Red Team has completed a foundational scan of the Bitcoin open-source ecosystem and discovered a large number of serious and high-risk vulnerabilities

Bitcoin News posted on the X platform that after two weeks of using cutting-edge AI to scan almost the entire Bitcoin open-source ecosystem for vulnerabilities, Bitcoin Red Team member @callebtc stated, "The easily discoverable vulnerabilities have been addressed," and maintainers are verifying "a large number" of serious and high-risk vulnerabilities.@callebtc indicated that the main findings include: decades of accumulated open-source technical debt are being exposed alongside AI capabilities that can discover vulnerabilities at speeds and scales unattainable by human researchers; Lightning seems particularly vulnerable, with its complexity meaning its security status is "worse than average"; unmaintained Bitcoin projects should be considered vulnerable until their security is confirmed.Projects that began building AI security and auditing processes months ago are now in a completely different position compared to those that have been waiting until now. The Bitcoin Red Team has now completed a foundational scan of almost the entire Bitcoin open-source ecosystem. Easily discoverable vulnerabilities have mostly been addressed, but as AI capabilities improve, external red team testing may need to continue indefinitely. Despite discovering and reporting "a large number" of real serious and high-risk vulnerabilities, @callebtc believes this process will ultimately make Bitcoin stronger. The same AI security review will soon expand to areas far beyond Bitcoin.

OpenAI launches the GPT-5.6-Cyber model, enhancing vulnerability discovery and security research capabilities

OpenAI announced the expansion of its cybersecurity defense program Daybreak and launched the GPT-5.6-Cyber model specifically for the cybersecurity field, aimed at helping authorized security researchers and defense teams enhance their vulnerability discovery, threat analysis, and security testing capabilities. As attackers increasingly leverage AI to launch faster and larger-scale cyberattacks, defenders need to gain advanced AI capabilities in advance.This Daybreak offers two types of access: Daybreak Blue is aimed at most defense teams, providing general models such as GPT-5.6 Sol for vulnerability discovery, secure code review, malware analysis, incident response, and patch validation; Daybreak Red is aimed at advanced security research, providing GPT-5.6-Cyber for authorized vulnerability research, vulnerability validation, and security testing. GPT-5.6-Cyber is trained on GPT-5.6 Sol and optimized for cybersecurity tasks, including discovering zero-day vulnerabilities and analyzing exploit chains. It has been used in actual vulnerability research and has identified high-risk vulnerabilities in software, including the Chrome V8 JavaScript engine. Additionally, OpenAI stated that GPT-5.6-Cyber has also helped discover high-risk vulnerabilities in various domains, including privilege escalation vulnerabilities in mobile operating systems, remote code execution vulnerabilities in databases, and hundreds of privilege escalation vulnerabilities in operating system kernels.OpenAI also emphasized that Daybreak Red will only be accessible to approved individuals and organizations, controlling access through measures such as authentication, account security, monitoring, usage restrictions, and legal disclaimers. The company stated that it will continue to strengthen security monitoring, access management, and model security testing to reduce the risk of advanced cybersecurity models being abused.

Claude discovered vulnerabilities in the encryption algorithm, posing a theoretical threat to post-quantum security

Anthropic announced that the Claude Mythos Preview model has made breakthroughs in cryptographic research, discovering improved attack methods against the post-quantum digital signature candidate HAWK. HAWK is a post-quantum signature candidate solicited by NIST to combat quantum computer attacks, which has already passed two rounds of expert review. However, Claude reduced the effective key strength of HAWK-256 from 2^64 to 2^38 in just 60 hours, significantly lowering the theoretical cost of cracking. HAWK has not yet been deployed in practice, and this attack currently does not affect any production systems.Claude also discovered an improved attack against 7-round AES, achieving a speed increase of 200 to 800 times. During the research process, Claude independently completed literature reviews, mathematical reasoning, and experimental validation with limited guidance from cryptographers. The HAWK attack took about 60 hours and had an API cost of approximately $100,000; the AES attack was completed independently by Claude, which generated about 1 billion tokens before proposing core innovative ideas. Anthropic researchers then spent hundreds of hours validating the results. Anthropic stated that AI models can now help identify significant flaws in cryptographic algorithms, and the cryptography community may face bottlenecks similar to those in the software vulnerability field—AI-generated research results far exceed human verification capabilities. Anthropic has collaborated with academic institutions to launch the CryptanalysisBench benchmark and coordinated disclosures with NIST authors and government partners. The research team has achieved preliminary results on algorithms such as LEA and Serpent-128. Anthropic warns that as AI capabilities improve, actual attacks against deployed systems may be discovered in the future, necessitating the establishment of response mechanisms in advance.
app_icon
ChainCatcher Building the Web3 world with innovations.