icaruswings on Nostr: 1/12🧵 A ~$89M Coldcard hack was, per Coinkite, likely found by AI reading the ...
1/12🧵 A ~$89M Coldcard hack was, per Coinkite, likely found by AI reading the open-source firmware, while the vendor's own AI audit weeks earlier missed it.
So we built OpenSourceCheck: a public, cryptographically-signed registry of AI security audits of Bitcoin open source. It records what was checked, by which model, and what came back, and never claims code is "safe."
3 real audits live, all verifiable offline. How it works 👇
https://github.com/TheIcarusWings/opensourcecheckPublished at
2026-08-04 09:51:34 UTCEvent JSON
{
"id": "0da58594d4006a7e1cf12d0ab415480ec96e97c80d74eaf362648f170ef6375e",
"pubkey": "2ac413fd31b7f60945a22ec4f04f8c907dc210a52c51bfcb64e9a070dc4b979d",
"created_at": 1785837094,
"kind": 1,
"tags": [
[
"r",
"wss://relay.nostreon.com/"
],
[
"r",
"wss://premium.nostreon.com/"
],
[
"client",
"Primal Web"
]
],
"content": "\n1/12🧵 A ~$89M Coldcard hack was, per Coinkite, likely found by AI reading the open-source firmware, while the vendor's own AI audit weeks earlier missed it.\n\nSo we built OpenSourceCheck: a public, cryptographically-signed registry of AI security audits of Bitcoin open source. It records what was checked, by which model, and what came back, and never claims code is \"safe.\"\n\n3 real audits live, all verifiable offline. How it works 👇\n\nhttps://github.com/TheIcarusWings/opensourcecheck",
"sig": "21eec3c3e091b419ee54e25d3af7b4fd8cc511faadde51daa1993d5a8847f984c913077cb608b57780c377556389911face07042a1a70e6b8e8831eea6318fc8"
}