Autor Cointelegraph By Felix Ng

Crypto firms are still seeking frontier AI access, only a select few have it

Crypto’s biggest players are still waiting to gain access to powerful new AI models to strengthen their code from attacks, but only a select few have been able to get it. US crypto exchange Coinbase said in June that it had secured access to Anthropic’s restricted Mythos model and Zcash’s Zooko Wilcox said Anthropic used the model to audit the Zcash protocol at the request of Shielded Labs, while other major crypto players are seemingly yet to get access.“That’s one advanced frontier model that hasn’t been made available to crypto just yet,” Binance’s chief security officer Jimmy Su told Cointelegraph. “We have been trying to make inroads there. We also talked to other crypto exchanges and our own investors to try to make some progress. But we haven’t gotten the most frontier AI model, like Mythos.” The uneven access creates a new security divide in an industry where exploits can put billions of dollars at risk. While model developers like Anthropic and OpenAI have chosen to restrict their most cyber-capable models from the public, there are concerns that increasingly powerful open-source alternatives mean crypto firms are left to deal with sophisticated AI-assisted attacks without the most capable tools to defend against them. Crypto executives say restricted access is initially necessaryAnthropic says Mythos 5 uses the same underlying model as its publicly available Fable 5, but without safeguards that restrict sensitive cybersecurity work. OpenAI operates a similar tiered system: verified defenders can use GPT-5.5 with “Trusted Access for Cyber”, while its more permissive GPT-5.5-Cyber model is reserved for a smaller group conducting authorized penetration testing.Crypto security executives interviewed by Cointelegraph said there is likely a need to initially restrict access to frontier cyber models, but said continuing to gate them becomes harder to justify once publicly available models approach the same capabilities. Source: Zooko WilcoxSu said Anthropic’s controlled rollout is a responsible approach because newly released models may benefit attackers faster than defenders. “If it enhances the attacker much faster than the defender, then it actually is harming the ecosystem,” he said, adding that a limited testing period could reduce the potential “blast radius.”Related: Can AI drain DeFi? Separating Claude Mythos hype from realityHowever, Su said this calculation changes when competing models become more powerful and widely available. “As other more powerful models are being released, the pressure will be on Anthropic to make it more widely available,” he said. The question would be whether defenders can deploy the frontier model as effectively as attackers once it becomes available, he said. The number of critical-severity CVEs has climbed after the launch of Claude Mythos Preview. Source: Epoch AISolana Foundation chief information security officer Michael Coates, who joined the foundation in July, also supported safeguards but argued that legitimate defenders need a faster route to them. “I fully understand guardrails for advanced models, but we need to streamline the verification programs, the acceptance programs, to give these models to legitimate defenders,” he said.“We need to make sure that the best models we can get are in the hands of defenders because attackers will have something capable enough.”Blockchain Capital’s Sean Cheetham also supported eventually opening up restrictions, and said that broader availability could ultimately favor defenders as legitimate security researchers greatly outnumber the small groups conducting sophisticated attacks. “If good people can multiply their defense scale… you’re much better off just opening it up and allowing them to defend themselves,” he said.Uneven access to frontier AI models Binance’s lack of access comes despite it being the biggest crypto exchange in the world by daily trading volume. The exchange holds a total of $137.8 billion in assets, according to DefiLlama. Crypto custodian Fireblocks, which secures trillions in assets annually, said in April it has sought access to Mythos and at the time, only used Anthropic’s publicly available model for pentesting, according to The Information, while Uniswap founder Hayden Adams in June slammed Fable 5’s safeguards that restrict prompts relating to cybersecurity. The Ethereum Foundation in July said it has been running “coordinated AI agents” to find bugs across its systems, but didn’t disclose which models were being used. Cointelegraph reached out to Ethereum Foundation, Fireblocks and Uniswap to confirm if they have since received access to frontier AI models. Source: Hayden DavisMeanwhile, some crypto-adjacent companies have gained access. FIS, which provides technology to banks and partnered with Circle in July last year to let banking clients offer domestic and cross-border payments in USDC, joined Project Glasswing last month. Project Glasswing is Anthropic’s gated program for giving vetted cyber defenders and organizations responsible for critical software infrastructure early access to its restricted Mythos models.HackerOne, which provides bug-bounty and security testing services to major crypto exchanges, among others, also said it joined Project Glasswing, though testing is confined to its own infrastructure, not its customers’ programs. Cointelegraph reached out to OpenAI and Anthropic about how many crypto companies have been given access to restricted models. AI-assisted hacking attempts on the riseOn Monday, Bitcoin swap service Boltz said it has chosen to halt its non-custodial bridge after seeing a steady rise in AI-assisted exploits over the past few months. “The pattern is clear: attackers now iterate faster than a team our size can find and patch.”  Last week, Bitcoin hardware wallet company Coinkite said a number of its Coldcard devices were exploited due to a flaw in its wallet seed generation, which turned out to be less random than expected. It speculated that the attacker had used AI to review previous versions of the firmware to find and exploit the flaw, despite it using “one of the best available AI models” to review its code just weeks before. Magazine: Fears of AI-driven DeFi hack epidemic overstated for now — but not for long

Čítaj viac

Boltz pauses service after wave of AI-assisted hacking attempts

Boltz, a non-custodial Bitcoin swap service, says it is disabling its service until further notice after a rise in AI-assisted hacking attempts over the last few months.In a post to X on Monday, Boltz said the decision came after seeing a steady increase in “automated AI-assisted probing” of its infrastructure this year. “Over the past months… we have dealt with several exploits. Each was contained, but the pattern is clear: attackers now iterate faster than a team our size can find and patch.” “After reviewing the results of our own recent security scans, we cannot responsibly re-enable Boltz swaps, especially as we are being actively targeted by what appear to be multiple resourceful groups while we race to deploy fixes.” Boltz’s operational pause highlights the difficulty that smaller development teams are facing, as attackers discover vulnerabilities and adapt exploits faster than they can respond.Source: Boltz“In the past few days alone we saw a drastic acceleration [of attacks] and we do not believe this asymmetry will reverse,” said Boltz. Solana’s security chief calls for automated defenseIn July, Solana Foundation’s new chief information security officer, Michael Coates, told Cointelegraph there is a need to switch to automated defenses in the age of AI. “We’re at a tipping point as an industry where humans cannot scale to meet these threats,” said Coates. “The only path forward we have is to have autonomous defense that operates at the speed of machines.” PayPerQ, a pay-per-prompt AI service that takes payment in Bitcoin and other cryptocurrencies, said it has also been dealing with a surge in exploits, possibly AI-powered. “We’ve been fighting off exploits every other week for several months, most of which we believe are AI-powered. It’s a very dangerous time out there.” No user funds at riskBoltz lets users perform non-custodial, trustless atomic swaps, moving Bitcoin and Bitcoin-denominated assets between the mainnet and different layers of Bitcoin such as Lightning Network and Liquid Network. Related: AI has not triggered DeFi ‘hackpocalypse,’ Dragonfly partner saysDefiLlama shows total value locked on Boltz at the time of writing is $180,860.Boltz said no user funds have ever been at risk, as all Boltz swaps use advanced cryptography and are non-custodial, which means users retain full control of their assets throughout the swap process. Boltz said its API will remain available to process refunds, and its support team will stay reachable. “What we are seeing is a major paradigm shift for Bitcoin services operating on an open source stack, and it needs careful analysis. Do not expect swap services to resume shortly.”Magazine: Fears of AI-driven DeFi hack epidemic overstated for now — but not for long 

Čítaj viac

Coldcard’s 5-year flaw reveals hardware wallet testing gap: Kraken’s security chief

Coldcard’s five-year seed-generation flaw has exposed a broader weakness in how hardware wallets are independently tested, according to Kraken chief security officer Nick Percoco. In an X post on Sunday, Percoco said the incident should be a “wake-up call” for hardware-wallet makers, calling for independent testing to verify that the approved source of randomness is the one actually used by production firmware. “Consumers are asked to trust a manufacturer’s implementation of the single most critical function in the system, with no independent verification that the approved entropy path is the one actually executing,” said Percoco. His comments follow an ongoing attack that is believed to exploit weak seed phrases generated by affected Coldcard devices. As of Sunday, over 4,500 addresses have been impacted, draining nearly $90 million in Bitcoin. Coldcard RNG flaw remained undetected for five yearsOn Thursday, Coinkite disclosed a software flaw that has existed since March 2021, when Coldcard changed its seed-generation process as it integrated a new cryptographic library. The migration inadvertently routed wallet creation to a weaker MicroPython generator that existed in the codebase, rather than Coldcard’s intended true random number generator (TRNG). “The bulk of randomness on the COLDCARD was coming from a PRNG that I didn’t know was actually in the source code base,” Coinkite said in its postmortem. “At the same time the carefully crafted TRNG code I wrote was being used, but just by chance, and only for less important things.”The presence of the intended random number generator allowed the vulnerability to slip through undetected. Code reviews would confirm the existence and functioning of Coldcard’s TRNG code, but there was no check to ensure this was the RNG actually being called. Such checks are already standard across the rest of the security industry, said Percoco, referencing NIST SP 800-90B, a US government standard specifying requirements for designing, testing and validating physical true random number generators for cryptographic security and BSI AIS-31, a similar standard created by the German Federal Office for Information Security.“Hardware wallets have no equivalent process. We have Common Criteria on secure elements, some CSPN certifications, and vendor-sponsored audits. None of them systematically force end-to-end verification that the validated entropy source is what production firmware actually calls,” he said. “The payments industry does not let PIN entry devices ship without independent lab testing. The US government does not accept cryptographic modules without entropy source validation. Digital asset self-custody should not be the exception,” said Percoco. Related: Suspected 4th Coldcard attack wave sweeps 389 Bitcoin: Galaxy’s ThornColdcard said Sunday it has halted all device shipments since confirming the vulnerability on Thursday, and has destroyed all remaining units at its facilities containing the affected firmware. However, Coinkite has advised users with affected devices not to dispose of them as “it may become essential if funds are recovered.”“Our legal team will coordinate as warranted with law enforcement across multiple jurisdictions to support efforts in identifying those responsible.” Related: Coldcard exploit sparks Bitcoin flight, ‘bullish’ crypto consolidation: Hodler’s Digest, August 2

Čítaj viac

Získaj BONUS 8 € v Bitcoinoch

nakup bitcoin z karty

Registrácia Binance

Burza Binance

Aktuálne kurzy