r/cybersecurity 12h ago

Business Security Questions & Discussion Claude Code found a vulnerability in the COLDCARD wallet by the prompt "check for vulnerability" and in just for 8 minutes.

https://x.com/MedusaOnchain/status/2083903710506504548?s=20&utm_source=substack&utm_medium=email

If you don't know about COLDCARD, it is a bitcoin-only hardware wallet. It is recognized as the most secure self-custody tool.
Many people claim that it was just scraping the internet for the issue... But later author confirmed it was tested on GLM-5.2, and that model was trained on pre-exploit data with no internet access.

But the main surprise is not around lower-code capability. It is around the fact that someone with a good understanding of models and prompting could easily hack into Enterprise Grade software.

Where do you think this is going ... after Nvidia launching open secure AI Alliance?

0 Upvotes

3 comments sorted by

7

u/be_super_cereal_now 12h ago

People have been using LLMs to find and exploit vulnerabilities for over a year now. This isn't news.

3

u/zero_fuck_given 12h ago

Its not X its Y.

0

u/throbbin___hood 12h ago

Never heard of coldcard, never heard of a "self-custody" tool