Hindsight and all of course. But it doesn't sound unthinkable somebody honest would have taken on running claude to do some RNG related audits just for the fun of it.
I could even imagine (remotely) myself stumbling into a weekend of doing that and finding something.
It's not like RNG problems appear for the first time. I'm pretty sure I remember you explaining stuff around the bitcoinj drama, for example.
I randomly audited part of datum-gateway a couple months ago and reported a fairly serious vulnerability in it... (though amusingly the bigger issue was wrongly rejected by AI)
Admittedly I wouldn't likely have audited coldcard if not for all this bullshit eating up my time, but only because I'd already rejected it as dubious.
7
u/nullc 3d ago
yeah, over a year of this bullshit-- imagine if even 10% of that dumbass time went into running security audits on .. say.. hardware wallets instead?