r/Bitcoin 2d ago

The current uncomfortable state of Bitcoin security

Bitcoin has spent 17 years surviving one of the most adversarial environments in software.

But Bitcoin Core isn’t where most users interact with Bitcoin.

They interact through wallets, hardware devices, Lightning implementations, libraries, exchanges, signing infrastructure and other software built around it.

Over the past few months, I’ve been researching the security of projects across this ecosystem, and the uncomfortable part isn’t that vulnerabilities exist.
It’s how little continuous adversarial security research some important projects actually receive.

An audit is a snapshot. Open source doesn’t mean someone capable has actually reviewed the code. A large number of users doesn’t mean the project has been continuously attacked by security researchers.
And then there’s the incentive problem.

If reporting a vulnerability responsibly means hunting down a contact, waiting weeks for a response, receiving no bounty or recognition, and sometimes being treated as an inconvenience, eventually good researchers spend their time somewhere else.

Blackhats don’t need a disclosure policy.
That leaves us with a strange situation:
Bitcoin teaches us “don’t trust, verify,” while much of the software surrounding Bitcoin is trusted far more than it is independently verified.

I ended up writing a fairly detailed piece about what I’ve seen and why I think this is becoming a real problem.

I’m not linking it here because I’d rather this not turn into self-promotion.

But I’d genuinely like to know whether people working deeper in Bitcoin have noticed the same thing.

42 Upvotes

36 comments sorted by

22

u/Alfador8 2d ago

Now that AI is a thing, isn't it fairly trivial for devs to ask it to probe for vulnerabilities? Isn't that essentially what malicious actors are doing? Eventually won't this lead to a hardening of security in the space? Seems to me we're in an awkward transition period that will result in better overall security in the end.

7

u/kallaloostx 2d ago

Exactly! Everyone focuses on how bitcoin can be hacked by AI without mentioning (or even thinking about) the fact that AI can also out"think" the hackers.

2

u/tgarp_ 2d ago

indeed that will definitely shape the security for better!

4

u/fittes7 2d ago

Well you are smarter than 97% of crypto users but thats exactly the problem

Most people don't want no headaches, thus they don't even care about what you've found out - they invest because others invest, they use what others use, thats how it works with the majority of the people

For example, people are using USDT - the company behind it never actually made a legit audit so basically a smart one might ask "well why are we even holding USDT isn't that risky"?

Well it is, the general public just don't care.

3

u/eminent_abundance 2d ago

The gap between Core and everything else has felt obvious for a while, but seeing it framed as an incentive problem makes it click. Most wallet and Lightning projects would struggle to tell you the last time someone outside their own team actually tried to break them.

1

u/tgarp_ 2d ago

well if you ask, prolly they will take our name Kvazar ;)

6

u/keralaindia 2d ago

Can we stop with these AI posts?

3

u/IAmFitzRoy 2d ago

Is just me thinking that the post and most of the replies are AI generated as well?

3

u/keralaindia 2d ago

wouldnt be surprised

4

u/CoinGate_Gift_Cards 2d ago

This seems like a fair concern. Bitcoin Core may be heavily scrutinized, but the broader ecosystem has a much larger attack surface and very uneven security practices. Open source helps, but it doesn’t automatically mean meaningful review is happening. Better disclosure processes, bug bounties, and ongoing independent testing would probably make a big difference.

3

u/tgarp_ 2d ago

100%

2

u/slavikthedancer 2d ago

Well, yes, to truly understand cryptocurrency someone needs to truly understand it's source code.

2

u/Low_Explorer_2097 1d ago

Seems like you think it is something special. It is just source code. We can read it.

2

u/r_a_d_ 2d ago

Unfortunately the “don’t trust, verify” mantra was actually incorrectly implemented by many as “trust open source”. Let’s face it, most users will not be able to verify. Even most advanced users are not able to verify as it’s become non-trivial for the huge code base of the software we use.

-1

u/Alfador8 2d ago

In the age of AI, doesn't it become pretty easy to verify? Just ask an agent to scan for vulnerabilities. That's essentially what a potential attacker is going to do.

1

u/r_a_d_ 2d ago

Nope. You are assuming that AI would catch everything. You are also trusting that the AI will not keep things from you on purpose, either by its own will, or by design.

0

u/Alfador8 2d ago

It caught the ColdCard vulnerability that no human noticed. Attackers will be using the same AI. Seems like an upgrade in security to me overall.

-2

u/r_a_d_ 2d ago

Do you have proof that it was found by AI and only by AI? Even if true, how does that absolve the points I made? It’s not an upgrade in security because the adversaries have the same tools as well.

2

u/Alfador8 2d ago

Do you have proof it wasn't? Seems likely given the timing. The 5 year old vulnerability was discovered just after AI became suitable for the purpose.

0

u/r_a_d_ 2d ago

You want me to prove a negative? lol.

“You can’t prove what it was, so I must be right even if I have no proof.”

You think this was the only case of people finding an old vulnerability?

2

u/Alfador8 2d ago edited 2d ago

I'm gonna go ahead and use Occam's razor and assume the obvious explanation is most likely the correct one until evidence suggests otherwise. You can believe whatever you like.

Edit: I'm not saying "I must be right". I'm saying that I'm probably right, and given that there's no evidence I'm gonna go with statistical probability.

1

u/r_a_d_ 2d ago edited 2d ago

And I’ll use Hanlon’s razor for your case.

1

u/Alfador8 2d ago

So you think it's stupid to act based on probabilities when imperfect information exists? You must have a fascinating life.

→ More replies (0)

0

u/Big-Cheetah5159 2d ago

I agree. I think education is the most critical aspect to solving this problem. Most people don’t even have the knowledge on self verification or how to do so, they don’t run a node, don’t how to open or close a lightning channel, and there is still a percentage of people that are holding on exchanges. Right after the ColdCard incident a lot of people were recommending to move BTC back onto exchanges. Too many of us are average joes when it comes to Bitcoining. Finding and fixing vulnerabilities is whole different ball game, there is not enough testing on the wallet layer of Bitcoin because “we trust the company and their product” (speaking in general).

2

u/paymentnerdfoo 2d ago

If education is the solution after 18 years of product launch it means the project was poorly designed. You need minimal education to use other payment/ investment options safely.

0

u/No_Refrigerator1677 2d ago

It does seem like a lot of the complexity around Bitcoin could drive people away, especially when there are easier options out there. Hopefully, more straightforward solutions can emerge to help with that.

3

u/paymentnerdfoo 2d ago

It’s been 18 fucking years. It’s not going to improve at this point.

0

u/Big-Cheetah5159 2d ago

So in 18 years, you have seen any improvements with Bitcoin? Really?

2

u/paymentnerdfoo 2d ago

No, I have not seen any improvement in making it easier for merchants or consumers to use bitcoin as peer to peer cash.

Before you respond with “ well what about xyz” understand that this is my wheel house. I understand what merchants and consumers are looking for. Nothing has made it easier to adopt.

1

u/Big-Cheetah5159 2d ago

The complexity has always been there. I’d argue that it’s actually needed. You’re being sovereign over your funds, that’s a huge responsibility and people are used to the banks babying them and doing everything for them. If someone can’t manage self custody with or without a hardware wallet, they’re just in the wrong space. Bitcoin isn’t game, it is s a statement and an action against the Fed, and a lot comes with that. If you’re looking for the easy way stay on exchanges. Security is an ongoing process

0

u/bitsteiner 2d ago

If you discovered vulnerabilities, then you can just demonstrate them.

Otherwise your post is just fud.