BTC $62,600.54 -1.64%
ETH $1,867.09 -1.13%
BNB $603.60 -0.94%
XRP $1.00 -0.55%
SOL $75.27 -1.03%
TRX $0.3323 -0.55%
DOGE $0.0693 -1.06%
ADA $0.1792 -2.13%
BCH $202.75 -5.16%
LINK $8.80 +0.10%
HYPE $56.05 -2.62%
AAVE $85.71 -3.05%
SUI $0.6755 -2.03%
XLM $0.1598 -0.21%
ZEC $483.58 -1.35%
BTC $62,600.54 -1.64%
ETH $1,867.09 -1.13%
BNB $603.60 -0.94%
XRP $1.00 -0.55%
SOL $75.27 -1.03%
TRX $0.3323 -0.55%
DOGE $0.0693 -1.06%
ADA $0.1792 -2.13%
BCH $202.75 -5.16%
LINK $8.80 +0.10%
HYPE $56.05 -2.62%
AAVE $85.71 -3.05%
SUI $0.6755 -2.03%
XLM $0.1598 -0.21%
ZEC $483.58 -1.35%

open-source

All
Article
Flash

Bitcoin Red Team has completed a foundational scan of the Bitcoin open-source ecosystem and discovered a large number of serious and high-risk vulnerabilities

Bitcoin News posted on the X platform that after two weeks of using cutting-edge AI to scan almost the entire Bitcoin open-source ecosystem for vulnerabilities, Bitcoin Red Team member @callebtc stated, "The easily discoverable vulnerabilities have been addressed," and maintainers are verifying "a large number" of serious and high-risk vulnerabilities.@callebtc indicated that the main findings include: decades of accumulated open-source technical debt are being exposed alongside AI capabilities that can discover vulnerabilities at speeds and scales unattainable by human researchers; Lightning seems particularly vulnerable, with its complexity meaning its security status is "worse than average"; unmaintained Bitcoin projects should be considered vulnerable until their security is confirmed.Projects that began building AI security and auditing processes months ago are now in a completely different position compared to those that have been waiting until now. The Bitcoin Red Team has now completed a foundational scan of almost the entire Bitcoin open-source ecosystem. Easily discoverable vulnerabilities have mostly been addressed, but as AI capabilities improve, external red team testing may need to continue indefinitely. Despite discovering and reporting "a large number" of real serious and high-risk vulnerabilities, @callebtc believes this process will ultimately make Bitcoin stronger. The same AI security review will soon expand to areas far beyond Bitcoin.

hot_img Alibaba plans to charge revenue sharing from commercial customers of open-source AI models, emulating the Kimi K3 model of the Dark Side of the Moon

According to Reuters, Alibaba plans to require its next-generation Qwen open-source AI model's heavy commercial users to share a portion of their revenue with it. This initiative is similar to the approach taken by Moonlight Dark Side with Kimi K3: the licensing terms for Kimi K3 stipulate that if the model is sold as a service and the annual revenue exceeds $20 million, a commercial agreement must be negotiated with Moonlight Dark Side, with reports suggesting a revenue-sharing ratio of up to 30%. The specific revenue-sharing ratio for Alibaba is still under discussion.The report points out that such revenue-sharing agreements have gradually taken shape between Chinese AI companies and American cloud platforms. Several American cloud providers, including DigitalOcean, have signed commercial agreements with Moonlight Dark Side. In terms of pricing, the input/output token price for Kimi K3 is about one-third that of the Anthropic Fable model. Additionally, Thinking Machines Lab, founded by former OpenAI CTO Mira Murati, has also joined the open-source camp and released its first open-source model last month. This move signifies that Chinese AI companies are exploring sustainable commercialization paths on open-source models through a "free open-source + commercial charging" freemium model.

Galaxy Research Director: Coldcard attack investigation陷入 AI dilemma, forced to turn to Chinese open-source models to track stolen funds

Galaxy Research Research Director Alex Thorn stated that the attack targeting Coldcard wallet address generation is still ongoing. They are currently continuing to collect victim information and adding new victim addresses and attacker addresses to the investigation database.If users are still using affected Coldcard single-signature addresses, they should immediately migrate their funds. According to current investigation results, all single-signature Coldcard addresses generated after the firmware upgrade in March 2021 may ultimately be emptied by attackers; it is just a matter of time.According to Galaxy Research's analysis, the first three confirmed rounds of attacks exhibit highly programmatic characteristics, with similar attack transaction patterns. A large amount of stolen Bitcoin remains in the attackers' addresses and has not yet been transferred.At the same time, some new opportunistic attackers are emerging, transferring and laundering funds through methods such as stripping the funding chain, cross-chain services (like ThorChain), and overseas betting platforms.Additionally, Alex Thorn mentioned the limitations of AI tools in security investigations. Some large language models in the United States have restricted researchers' ability to track stolen funds, and the team has even had to turn to Chinese open-source AI models to assist in protecting user assets and conducting on-chain tracking.He finds this phenomenon "incredible" and plans to promote discussions on related issues at the government and industry levels. Alex Thorn concluded by stating that a large amount of stolen funds remains stagnant, and the team is continuously tracking relevant addresses, having shared information with relevant U.S. agencies and industry partners. He calls on the Bitcoin community to learn from this incident, strengthen self-custody security education, and raise awareness of wallet complexity.

David Sacks: Opposes using regulatory uncertainty to suppress open-source AI, warns that the AI duopoly is seeking to eliminate competition

David Sacks, Chairman of the President's Council of Advisors on Science and Technology, stated on the X platform that using regulatory uncertainty as a competitive tool is "completely unacceptable." Regulatory decisions should be based on facts, logic, and evidence, rather than deliberately creating fear and uncertainty (FUD). He is unsure whether venture capitalist and AI policy researcher Dean Ball is acknowledging a strategy of "regulatory capture" or merely predicting that such a situation will occur. However, in any case, the practice of issuing "soft law" warnings through regulatory agencies to create market panic, thereby forcing regulated companies away from Chinese open-source models, should not be accepted.David Sacks pointed out that Dean Ball believes there is no need to directly ban Chinese open-source models; it is sufficient to guide regulatory agencies to issue relevant warnings, which can influence corporate decision-making by creating enough doubt and uncertainty, and these reasons "do not even need to be very substantial." Any regulatory decision must have sufficient basis, rather than implementing policies by "artificially creating doubt." He warned that this practice of circumventing public deliberation procedures not only undermines the foundation of the rule of law but may also open the door to regulatory abuse against any company or individual in the future.David Sacks further stated that current AI policy is at a critical turning point. Leading closed-source laboratories, which have already formed a duopoly in AI model revenue, are attempting to use government power to eliminate open-source competitors. He called on other companies and developers in Silicon Valley that still support open competition to make clear statements to jointly maintain an open ecosystem in the field of AI.
app_icon
ChainCatcher Building the Web3 world with innovations.