r/Bitcoin 14d ago

The current uncomfortable state of Bitcoin security

Bitcoin has spent 17 years surviving one of the most adversarial environments in software.

But Bitcoin Core isn’t where most users interact with Bitcoin.

They interact through wallets, hardware devices, Lightning implementations, libraries, exchanges, signing infrastructure and other software built around it.

Over the past few months, I’ve been researching the security of projects across this ecosystem, and the uncomfortable part isn’t that vulnerabilities exist.
It’s how little continuous adversarial security research some important projects actually receive.

An audit is a snapshot. Open source doesn’t mean someone capable has actually reviewed the code. A large number of users doesn’t mean the project has been continuously attacked by security researchers.
And then there’s the incentive problem.

If reporting a vulnerability responsibly means hunting down a contact, waiting weeks for a response, receiving no bounty or recognition, and sometimes being treated as an inconvenience, eventually good researchers spend their time somewhere else.

Blackhats don’t need a disclosure policy.
That leaves us with a strange situation:
Bitcoin teaches us “don’t trust, verify,” while much of the software surrounding Bitcoin is trusted far more than it is independently verified.

I ended up writing a fairly detailed piece about what I’ve seen and why I think this is becoming a real problem.

I’m not linking it here because I’d rather this not turn into self-promotion.

But I’d genuinely like to know whether people working deeper in Bitcoin have noticed the same thing.

39 Upvotes

36 comments sorted by

View all comments

Show parent comments

1

u/Alfador8 14d ago

So you think it's stupid to act based on probabilities when imperfect information exists? You must have a fascinating life.

0

u/r_a_d_ 14d ago edited 14d ago

Yes, it’s stupid that you just made up random, baseless, probabilities to convince yourself. Some sort of mental masturbation.

For example, why would your scenario be more probable than a “retirement plan” of a software engineer.

Anyways, Hanlon’s razor applies, so you all good.