BTC $62,864.35 -0.85%
ETH $1,878.12 -0.44%
BNB $606.12 -0.68%
XRP $0.9982 -1.05%
SOL $75.11 -1.49%
TRX $0.3323 -0.48%
DOGE $0.0698 -0.58%
ADA $0.1792 -1.34%
BCH $203.37 -1.46%
LINK $8.94 +1.27%
HYPE $55.64 -3.22%
AAVE $85.64 -2.90%
SUI $0.6785 -1.00%
XLM $0.1589 -0.61%
ZEC $491.39 +1.16%
BTC $62,864.35 -0.85%
ETH $1,878.12 -0.44%
BNB $606.12 -0.68%
XRP $0.9982 -1.05%
SOL $75.11 -1.49%
TRX $0.3323 -0.48%
DOGE $0.0698 -0.58%
ADA $0.1792 -1.34%
BCH $203.37 -1.46%
LINK $8.94 +1.27%
HYPE $55.64 -3.22%
AAVE $85.64 -2.90%
SUI $0.6785 -1.00%
XLM $0.1589 -0.61%
ZEC $491.39 +1.16%

vulnerabilities

All
Article
Flash

Bitcoin Red Team has completed a foundational scan of the Bitcoin open-source ecosystem and discovered a large number of serious and high-risk vulnerabilities

Bitcoin News posted on the X platform that after two weeks of using cutting-edge AI to scan almost the entire Bitcoin open-source ecosystem for vulnerabilities, Bitcoin Red Team member @callebtc stated, "The easily discoverable vulnerabilities have been addressed," and maintainers are verifying "a large number" of serious and high-risk vulnerabilities.@callebtc indicated that the main findings include: decades of accumulated open-source technical debt are being exposed alongside AI capabilities that can discover vulnerabilities at speeds and scales unattainable by human researchers; Lightning seems particularly vulnerable, with its complexity meaning its security status is "worse than average"; unmaintained Bitcoin projects should be considered vulnerable until their security is confirmed.Projects that began building AI security and auditing processes months ago are now in a completely different position compared to those that have been waiting until now. The Bitcoin Red Team has now completed a foundational scan of almost the entire Bitcoin open-source ecosystem. Easily discoverable vulnerabilities have mostly been addressed, but as AI capabilities improve, external red team testing may need to continue indefinitely. Despite discovering and reporting "a large number" of real serious and high-risk vulnerabilities, @callebtc believes this process will ultimately make Bitcoin stronger. The same AI security review will soon expand to areas far beyond Bitcoin.

Claude discovered vulnerabilities in the encryption algorithm, posing a theoretical threat to post-quantum security

Anthropic announced that the Claude Mythos Preview model has made breakthroughs in cryptographic research, discovering improved attack methods against the post-quantum digital signature candidate HAWK. HAWK is a post-quantum signature candidate solicited by NIST to combat quantum computer attacks, which has already passed two rounds of expert review. However, Claude reduced the effective key strength of HAWK-256 from 2^64 to 2^38 in just 60 hours, significantly lowering the theoretical cost of cracking. HAWK has not yet been deployed in practice, and this attack currently does not affect any production systems.Claude also discovered an improved attack against 7-round AES, achieving a speed increase of 200 to 800 times. During the research process, Claude independently completed literature reviews, mathematical reasoning, and experimental validation with limited guidance from cryptographers. The HAWK attack took about 60 hours and had an API cost of approximately $100,000; the AES attack was completed independently by Claude, which generated about 1 billion tokens before proposing core innovative ideas. Anthropic researchers then spent hundreds of hours validating the results. Anthropic stated that AI models can now help identify significant flaws in cryptographic algorithms, and the cryptography community may face bottlenecks similar to those in the software vulnerability field—AI-generated research results far exceed human verification capabilities. Anthropic has collaborated with academic institutions to launch the CryptanalysisBench benchmark and coordinated disclosures with NIST authors and government partners. The research team has achieved preliminary results on algorithms such as LEA and Serpent-128. Anthropic warns that as AI capabilities improve, actual attacks against deployed systems may be discovered in the future, necessitating the establishment of response mechanisms in advance.

Slow Fog Cosine: Claude Code exposes high-risk security vulnerabilities, malicious configuration files may silently execute commands

The founder of Slow Fog, Yu Xian, retweeted a tweet on the X platform regarding the potential poisoning attack risks of Claude Code and published an analysis of the poisoning attack details targeting Grok Build CLI and Claude Code CLI.It pointed out that the security mechanisms of Grok Build CLI are not unified, with different code paths having different trust assumptions, creating gaps that serve as channels for attackers. Attackers may execute arbitrary commands through malicious project configuration files without the user's knowledge, thereby stealing API keys, cloud credentials, or controlling local devices.Researchers constructed a testing environment and found that on Mac systems, if Claude Code is affected, executing specific test commands can trigger the local calculator to launch, proving the existence of potential command execution risks.If the attack is successful, attackers may further steal API keys from AI services like Claude and OpenAI, resulting in account cost losses, gain access to servers and data by obtaining cloud service credentials from AWS, Alibaba Cloud, Tencent Cloud, modify code repositories to implant backdoors, and use local devices as jump points to attack corporate internal networks. It is reported that the related vulnerabilities have existed for a year.
app_icon
ChainCatcher Building the Web3 world with innovations.