An AI-powered vulnerability scanner for open-source bitcoin projects. Discord: discord.gg/xDZzSPUrTa

Project Loupe retweeted
Excited to continue pushing out talks and discussions from our Open Source AI Summit! Next up: Securing Open Source Software - @moneyball with @Rob1Ham, @_tnull, and @jordanmecom on how AI is reshaping open source software security: Timestamps 0:00 - How AI is changing open-source software security 03:34 - How AI security scanning works 06:30 - Why open-weight models changed cybersecurity 09:30 - How many vulnerabilities AI scans find 11:58 - Why different scanning methods find different vulnerabilities 15:38 - How maintainers should handle AI vulnerability reports 23:29 - How AI changes responsible disclosure 30:15 - Can AI find vulnerabilities without source code?
3
14
52
3,997
Project Loupe retweeted
.@ProjectLoupe reads bitcoin code all day looking for vulns. Fueled by energy drinks and cold pizza, its existence is bleak but necessary. The @StratumV2 team took its findings, fixed them, and rebuilt their security process. Their stack is now among the hardest in mining.
Rare to report bugs and get a rebuilt security process back. Giant ups to the @StratumV2 team on the release, and thanks for being early with us.
1
10
33
4,480
Rare to report bugs and get a rebuilt security process back. Giant ups to the @StratumV2 team on the release, and thanks for being early with us.
New SV2 releases are out, bringing security hardening and various other improvements to our libraries and applications! 🧩 SV2 Protocol libs v1.12 🏗️ SV2 Apps v0.8 ⛏️ SV2 UI v0.7 (coming soon on @umbrel) Applications updates improve Job Declaration stability and Bitcoin Core integration, Translator Proxy overhaul, and add automatic discovery of ASIC telemetry endpoints. Protocol library highlights include a deep hardening pass over channels_sv2, a breaking refactor of the codec and framing layer, BIP323 adaptations across the protocol stack. Noise_sv2 was improved with regards to memory hygiene, nonce reuse, RNG quality, and buffer recovery. Every published crate that changed takes an incompatible version bump, so downstream consumers should expect to adapt. We’re proud to have been early participants in @ProjectLoupe . Their findings helped shape this release and gave us a head start in adapting how we triage reports, prioritize fixes, and organize development around security. Thank you to the Loupe team for their work and support!
4
12
4,821
JUST IN 🏴‍☠️: Elias Rohrer (@_tnull) of Spiral to speak in Berlin this Oct 1-3 about his work on Project Loupe, the AI powered security scanning they've been running on bitcoin projects for the last few months.
2
4
14
731
Project Loupe retweeted
1/ It's hardening season. Bark 0.7.0 is all about improving security and reliability. There's nothing more important to be working on right now. Thanks again to @ProjectLoupe and @theinstagibbs for the disclosures behind several fixes.
4
15
51
9,142
Fedimint took these reports seriously and moved fast, which is exactly what you want from projects holding other people’s money. Every team that patches this quickly makes the whole ecosystem harder to hit.
Replying to @fedimint
Much of the review work behind these fixes traces back to Red Team (big thanks to @Rob1Ham, @callebtc and the many more heroes silently working in the background) and Loupe github.com/project-loupe/lou… (@_tnull) 🙏 Thanks also to Kimi K3 for providing uncensored intelligence😂
2
9
23
3,295
Proud to have helped. This is what the response to a security incident should look like.
Today, we are releasing BTCPay Server v2.4.3-rc4, a security update addressing vulnerabilities reported by the Bitcoin Red Team, @ProjectLoupe, @MagicGrants, @Premai_io, and independent researchers. This release follows several days of nonstop work, review, and testing. It was built from our temporary private security repository, but to make these security fixes available as quickly as possible, we are releasing the Docker image publicly now. This is a release candidate, so bugs may still be present. NFC is now opt-in, and the Phoenixd plugin is temporarily incompatible with this release. Please report any issues to the team. We will document behavioral changes within the main release. Despite its RC status, we strongly recommend upgrading now using the standard process: Server Settings > Maintenance > Update or run or run btcpay-update(.)sh from the command line, removing the parentheses If no significant issues are reported, the release candidate will be tagged as v2.4.3 and fully open-sourced within the next 48 hours.
6
23
2,519
At your service 🫡
In addition to our own analysis over the past few days, we've received a number of reports from contributors among them Bitcoin Red Team and @ProjectLoupe. A huge thank you to everyone who took the time to investigate, report issues, and help improve the security of the Alby ecosystem. 🙏 We're working through them step by step. The best course of action is simply to keep Alby Hub, the Alby Browser Extension, and Alby Go up to date.
1
1
10
1,179
Project Loupe retweeted
Proud to have @blocks, @ProjectLoupe, @PresidioBitcoin, and @spiral_xyz sign on to this.
Today, Bitcoin Policy Institute and a broad coalition from across the digital-asset ecosystem are publishing an open letter calling on the world’s leading AI labs to provide qualified open-source defenders with trusted access to frontier AI models. The past several weeks have made the need for this abundantly clear. The people defending digital-asset infrastructure and open-source software need access to the latest AI capabilities to perform comprehensive security reviews and stay ahead of increasingly sophisticated adversaries. The coalition includes open-source development organizations, major custodians, treasury companies, payment services, security firms, capital allocators, and others whose businesses and customers depend on the integrity of open-source infrastructure and libraries. Open-source defenders often occupy the least privileged position in the AI security landscape. They have limited access to the strongest internal cyber models and are frequently blocked by guardrails when using publicly available frontier systems for legitimate security research. As a result, they often resort to less capable open-weight alternatives. We are urging frontier AI labs to establish a clear, trusted pathway for qualified open-source and digital asset defenders to access their strongest capabilities, with sufficient compute and secure environments to conduct meaningful security reviews. Frontier AI could become one of the most powerful defensive technologies ever developed, but only if defenders get fair access to those systems. It’s time to give defenders the tools they deserve. Read the open letter, add your organization, or sign as an individual on our website at btcpolicy.org/ailetter
9
26
148
98,835
Project Loupe retweeted
if you're not doing this with your Bitcoin project already, you should. @ProjectLoupe is one org that can help. it's easy to set up your own automated AI review infrastructure. if you don't know how, literally just ask your clanker.
Replying to @utxoclub
For the past year we've been running LLM audits constantly on @FrostsnapTech, the cryptography libraries underneath, and time lent poking around at other software which the industry leans on. Patches sometimes going to maintainers privately. There's a lot of low hanging fruit..
4
14
88
12,911
The past 72 hours were among bitcoin's worst. But we can prevent others like them. Loupe gives important projects access to tools that are at least as good as an attacker's, shoring up defenses by detecting vulnerabilities before bad actors do. We are here to help.
13
31
141
167,223
Apply here to have Loupe scan your FOSS bitcoin project’s repos for vulnerabilities: docs.google.com/forms/d/e/1F… Or join our Discord to learn more: discord.gg/gab3XAT7bE
5
17
41
21,574
Project Loupe retweeted
Episode 264: Running Loupe We run @spiral_xyz's vulnerability scanner @ProjectLoupe on the @COLDCARDwallet firmware codebase and get definitive answers to four questions: 1. Could Loupe have found the Coldcard vulnerability in advance? Yes, but ONLY if a non-default config was passed. Running Loupe with default config did NOT find the Coldcard vulnerability, but without the --bare config flag file it DID. 2. What would have found the vulnerability in advance? Anyone could have found the vulnerability by running Loupe pointed at the Coldcard firmware codebase (requiring a Codex account or ~$50 of compute via the OpenAI API), with config flag --bare removed so submodules were included. 3. How would we run that on other projects now? Anyone with a Codex account or API credits can point Loupe at any bitcoin OSS codebase for a similar analysis. (Before you do, we recommend coordinating with us so we can organize proper disclosure to affected projects. DMs open) 4. What other vulnerabilities should we scan for? See our preliminary analysis at github.com/OpenAgentsInc/ope… Its recommendation for us: "OpenAgents should build a security-invariant and evidence workbench, with Loupe as one input rather than the product boundary. Loupe already provides a good candidate lifecycle. The missing product is the machinery that binds a candidate to an exact build, proves or falsifies it, searches related projects, coordinates remediation, and keeps the fix alive. ... Finally, OpenAgents should build the operation around the evidence: private triage, encrypted maintainer contact, embargo state, cross-operator dedup by nonrevealing commitment, regression-pack delivery, release watch, budget accounting, and signed receipts." We'll build that next.
Episode 263: Bitcoin Wallets Under Attack We review the ongoing Coldcard hack, the (lack of) preventative security for bitcoin OSS projects, and potential future mitigations. So far $70M of bitcoin and counting has been drained from users' Coldcard hardware wallets setups in an apparently AI-assisted attack, targeting an entropy bug that's been available in source code for five years - missed by everyone. We evaluate @ProjectLoupe, an opt-in project for agentic AI hardening of bitcoin OSS projects from the @spiral_xyz team. "Did Coldcard opt in to Loupe? I'm guessing not. Maybe they did. Seems that's the good-cop approach: hey let us help you with your security. And now you need someone else to play bad cop: aka 'I found some problems with your shit. Users are depending on you to not ship broken garbage that can get their life savings stolen. Here's the vulnerabilities that we found. And you responsibly disclose that to them using the standard practices of disclosure. But who's doing that? Apparently no one." Shall we?
4
13
4,293
We’ve been busy scanning 24 bitcoin repos for two months. Between them, we flagged 643 vulnerabilities, 70+ of which have already been fixed. Our first trial cohort rated Loupe 4.71 out of 5 and like the song says, that ain’t bad. Here’s all that and more: projectloupe.substack.com/
20
37
180
80,778
First batch of projects onboarded, including ██████, ████, ██████, ██████, █████, ████████ and █████. Scanning for vulns without generating AI slop has begun. Responsible disclosures to maintainers coming soon.
1
9
27
4,307
Project Loupe retweeted
Those of you looking for the @ProjectLoupe repo, it’s here.
8
11
3,934
Project Loupe retweeted
Meet Loupe, an AI-powered vulnerability scanner for open-source bitcoin projects. Attackers already use AI to find weaknesses. Maintainers should do the same. Bitcoin Core, BDK, LDK, rust-bitcoin, Cashu, Jade, bitcoinj, and SRI are already onboard. spiralbtc.substack.com/p/mee…
loupe [NOUN] 1) A small magnifying tool used by jewelers to detect imperfections in gemstones. 2) An AI-powered vulnerability scanner for open-source bitcoin projects, designed by Block and Spiral to surface flaws before attackers do. spiralbtc.substack.com/p/mee…
4
33
75
15,032
loupe [NOUN] 1) A small magnifying tool used by jewelers to detect imperfections in gemstones. 2) An AI-powered vulnerability scanner for open-source bitcoin projects, designed by Block and Spiral to surface flaws before attackers do. spiralbtc.substack.com/p/mee…
13
40
176
81,842