Want to give an update on AI scans b/c a few people have asked about it. Over the last week and a half we have received a *lot* of results from automated scans using Kimi K3 and similar tools from the bitcoin red team and from individuals.
@newtonick,
@KeithMukai and some of our other regular contributors have evaluated all of those submitted, with people like
@YTCryptoGuide providing great perspectives as well. Our sense right now is that none of the identified issues are considered critical, and that all of them require a compromised malicious coordinator to attempt the given exploit. To date, we haven't seen or heard about any instances of a malicious coordinator attempting to execute one of these kind of attacks. There are some mitigations our devs can put into place to solve for identified edge cases, and we are planning a near-term release with those fixes (targeting the end of this month). To serve their designated purpose, wallet coordinators have to connect to the bitcoin network and are in turn of course exposed to the wider internet. If you have concerns about your wallet coordinator, consider migrating to a fresh install on a separate machine that is not your daily driver where you browse the internet, open emails, etc. etc. Another option is to use a security-oriented Linux live USB like Tails, and then install Sparrow or another coordinator in that environment. There are also projects like DTails (
dtails.gitlab.io) that can pre-install Sparrow or other bitcoin tools in a bootable image. There were no SeedSigner-related vulnerabilities identified involving bitcoin at rest, so waiting until our next release before you make a transaction is reasonable too. These AI vulnerability scanning tools will likely continue to surface security issues in many bitcoin tools, and in the broader infosec landscape, for at least the next 12-18 months at least. This will likely continue to be a tumultuous time and is a good reminder for us all to think carefully about our own cold storage setups and what risks we may, and may not, be exposed to. Multi-vendor, multi-sig wallets continue to provide the strongest assurances in the current adversarial environment.