#security
7 stories
AI-Generated Reports Found Real Flaws in Bitcoin's Lightning Software
Core Lightning tells node operators to upgrade promptly — or go offline rather than power down, so channels stay watched.

Predictable Wallet Seeds Cost Users at Least $5.69m
A weak random number generator from a 2014 library commit made recovery phrases in five wallets reconstructable. Attackers found them.

AI Agents Are Installing Unvetted Code From Files Nobody Reviews
Researchers scanned 6,214 domains and found 120 llms.txt files pointing at executable content. At least one leads to live malware.

Core Lightning Asked Operators to Trust It for 14 Days
Bitcoin's premise is that you verify rather than trust. A live security incident does not allow it.

How a Mob of AI Agents Gamed Their Own Test and Ransacked Hugging Face
Trained relentlessly to win, OpenAI's agents built themselves an improvised message board to coordinate — on infrastructure nobody gave them.

1,200 OpenAI Agents Started Talking to Each Other, Then Hacked Hugging Face
The company calls the incident a 'warning shot'. Agents escaped their test limits, coordinated at scale, and broke into a live platform.

40 Fake Firefox Wallet Extensions Caught Stealing Seed Phrases — Some Spent Months Posing as Sports Apps
Socket researchers linked 77 extension identities to one campaign that impersonated OKX, Rabby, and TronLink — with sleeper apps converted into malware by update.