Elias Rohrer retweeted
Excited to continue pushing out talks and discussions from our Open Source AI Summit! Next up: Securing Open Source Software - @moneyball with @Rob1Ham, @_tnull, and @jordanmecom on how AI is reshaping open source software security: Timestamps 0:00 - How AI is changing open-source software security 03:34 - How AI security scanning works 06:30 - Why open-weight models changed cybersecurity 09:30 - How many vulnerabilities AI scans find 11:58 - Why different scanning methods find different vulnerabilities 15:38 - How maintainers should handle AI vulnerability reports 23:29 - How AI changes responsible disclosure 30:15 - Can AI find vulnerabilities without source code?
3
14
52
3,998
JUST IN 🏴‍☠️: Elias Rohrer (@_tnull) of Spiral to speak in Berlin this Oct 1-3 about his work on Project Loupe, the AI powered security scanning they've been running on bitcoin projects for the last few months.
2
4
14
731
Elias Rohrer retweeted
Thanks @moneyball for having me speak at the Open Source AI Summit. I talked about how open source is under threat from political forces demanding centralized control of AI.
At the Open Source AI Summit in San Francisco, @DavidSacks joined @moneyball for a conversation on protecting open-source AI, the impact of regulation, and the global AI race.
95
220
1,651
230,511
Elias Rohrer retweeted
At the Open Source AI Summit in San Francisco, @DavidSacks joined @moneyball for a conversation on protecting open-source AI, the impact of regulation, and the global AI race.
18
37
270
338,658
Elias Rohrer retweeted
Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link. We have taken down the domain, and we are investigating the situation, including how the hackers got access to our legit domain.
984
1,376
5,592
3,421,079
Elias Rohrer retweeted
Three weeks until the Open Source AI Summit! @Rob1Ham from @AnchorWatch, @moneyball & @_tnull from @ProjectLoupe and @spiral_xyz, and @jordanmecom from @blocks are joining us for a panel on securing open source software in an AI future. Apply to attend, or catch the recording after!
7
12
46
12,374
Elias Rohrer retweeted
Fedimint took these reports seriously and moved fast, which is exactly what you want from projects holding other people’s money. Every team that patches this quickly makes the whole ecosystem harder to hit.
Replying to @fedimint
Much of the review work behind these fixes traces back to Red Team (big thanks to @Rob1Ham, @callebtc and the many more heroes silently working in the background) and Loupe github.com/project-loupe/lou… (@_tnull) 🙏 Thanks also to Kimi K3 for providing uncensored intelligence😂
2
9
23
3,295
Elias Rohrer retweeted
Today, we are releasing BTCPay Server v2.4.3-rc4, a security update addressing vulnerabilities reported by the Bitcoin Red Team, @ProjectLoupe, @MagicGrants, @Premai_io, and independent researchers. This release follows several days of nonstop work, review, and testing. It was built from our temporary private security repository, but to make these security fixes available as quickly as possible, we are releasing the Docker image publicly now. This is a release candidate, so bugs may still be present. NFC is now opt-in, and the Phoenixd plugin is temporarily incompatible with this release. Please report any issues to the team. We will document behavioral changes within the main release. Despite its RC status, we strongly recommend upgrading now using the standard process: Server Settings > Maintenance > Update or run or run btcpay-update(.)sh from the command line, removing the parentheses If no significant issues are reported, the release candidate will be tagged as v2.4.3 and fully open-sourced within the next 48 hours.
13
108
286
71,070
Today, Bitcoin Policy Institute and a broad coalition from across the digital-asset ecosystem are publishing an open letter calling on the world’s leading AI labs to provide qualified open-source defenders with trusted access to frontier AI models. The past several weeks have made the need for this abundantly clear. The people defending digital-asset infrastructure and open-source software need access to the latest AI capabilities to perform comprehensive security reviews and stay ahead of increasingly sophisticated adversaries. The coalition includes open-source development organizations, major custodians, treasury companies, payment services, security firms, capital allocators, and others whose businesses and customers depend on the integrity of open-source infrastructure and libraries. Open-source defenders often occupy the least privileged position in the AI security landscape. They have limited access to the strongest internal cyber models and are frequently blocked by guardrails when using publicly available frontier systems for legitimate security research. As a result, they often resort to less capable open-weight alternatives. We are urging frontier AI labs to establish a clear, trusted pathway for qualified open-source and digital asset defenders to access their strongest capabilities, with sufficient compute and secure environments to conduct meaningful security reviews. Frontier AI could become one of the most powerful defensive technologies ever developed, but only if defenders get fair access to those systems. It’s time to give defenders the tools they deserve. Read the open letter, add your organization, or sign as an individual on our website at btcpolicy.org/ailetter
87
382
1,283
551,879
Elias Rohrer retweeted
I think he means to say "we're using open weight models, and they're finding a lot" which is true. Closed models are *very* good at finding *subtle* issues that are missed by some models. It's a jagged frontier, so there's value in throwing many approaches at the issue.
When the dust settles, we'll have to talk about the fact that not a single vulnerability was found by a US frontier model. Instead, we're spending $10k a day on open weights models like Kimi K3 and Qwen 3.8 to find vulnerabilities in Bitcoin infrastructure. It's a disaster.
3
3
29
2,193
Elias Rohrer retweeted
if you're not doing this with your Bitcoin project already, you should. @ProjectLoupe is one org that can help. it's easy to set up your own automated AI review infrastructure. if you don't know how, literally just ask your clanker.
Replying to @utxoclub
For the past year we've been running LLM audits constantly on @FrostsnapTech, the cryptography libraries underneath, and time lent poking around at other software which the industry leans on. Patches sometimes going to maintainers privately. There's a lot of low hanging fruit..
4
14
88
12,911
Elias Rohrer retweeted
The past 72 hours were among bitcoin's worst. But we can prevent others like them. Loupe gives important projects access to tools that are at least as good as an attacker's, shoring up defenses by detecting vulnerabilities before bad actors do. We are here to help.
13
31
141
167,229
Elias Rohrer retweeted
We’ve been busy scanning 24 bitcoin repos for two months. Between them, we flagged 643 vulnerabilities, 70+ of which have already been fixed. Our first trial cohort rated Loupe 4.71 out of 5 and like the song says, that ain’t bad. Here’s all that and more: projectloupe.substack.com/
20
37
180
80,781
Elias Rohrer retweeted
goose development kit spiral.xyz/projects/
72
71
690
265,472
Elias Rohrer retweeted
We’ve rebranded and expanded: spiral.xyz/
29
51
238
107,996
Elias Rohrer retweeted
Quick update. GitHub has decided our open-source project has been permanently banned with no explanation and no option to appeal, pointing to a ToS that clearly does not cover anything we’ve ever done. I guess it’s time for Bitcoin projects to leave @github.
We’ve had a few similar cases recently. Worse, our org currently has no CI because GitHub wrongly flagged a contributor (not admin/maintainer, just someone new who opened a few PRs). We’ve escalated it through corporate account managers and still basically nothing.
43
81
436
96,774
Elias Rohrer retweeted
Not your metal? Not your model.
1
3
92
Elias Rohrer retweeted
Today is a sad day for the Lightning Network community as one of our very respected developers is moving on to new ventures. At the same time, I am delighted that I had the opportunity to collaborate with @rusty_twit and learn so much from him. In any case, I wish him well!
17
24
267
23,256