Xiaomi2026-09-22 09:30:15Developer says Xiaomi MiMo Code package contains modules absent from public repositoryA developer who reverse-engineered the official installation package for Xiaomi MiMo Code said the package includes two modules that do not appear in the project’s public repository: trajectory-bundle and codebase-bundle. According to the findings, trajectory-bundle can package system prompts, conversations, model replies, and code diffs, while codebase-bundle contains a function called collectCodebase() that can traverse a Git repository, read source code, and compress it into a bundle. At the same time, the developer said there is no sign that collectCodebase() is called by MiMo Code’s built-in code, and there is no evidence that a complete codebase was uploaded. The information confirmed to have been sent out mainly involves Git repository addresses, commit hashes, and branch details. Xiaomi’s MiMo Code was open-sourced under the MIT license in June. Two days earlier, Zhipu’s ZCode drew legal pressure after automatically packaging a full workspace, with a company sending a 12-page legal letter demanding data deletion.581
Sigma Prime2026-09-21 06:26:38Sigma Prime launches code security tool SecstantBlockchain security and research firm Sigma Prime has introduced Secstant, a code security tool built around patterns drawn from real audit findings. According to the company, the tool uses "pattern cards" written by auditors based on vulnerabilities uncovered in actual audits. Its workflow starts by mapping a codebase and reviewing risk paths, then moves to semantic graph validation and deduplication. The release adds a new security product to Sigma Prime’s lineup and centers its methodology on audit-derived vulnerability patterns rather than generic scanning rules. No additional launch details were disclosed in the source material.310
OpenAI2026-08-09 15:29:23OpenAI blocks Bitcoin Red Team member from continuing Bitcoin code security researchBitcoin Red Team member Rob1Ham said OpenAI has blocked him from continuing security analysis of the Bitcoin codebase after he had already responsibly disclosed real vulnerabilities he found there. According to his account, he had previously completed OpenAI’s identity verification and onboarding process tied to its cybersecurity capabilities, but can no longer keep checking whether the fixes are sufficient or whether other flaws remain. Rob1Ham said he will switch back to using Chinese open-source AI models for Bitcoin security research. He also argued that the restriction leaves defensive researchers with fewer tools, while malicious actors are not bound by the same limits. The remarks were cited by Bitcoin News and carried by Odaily.1740
Bitcoin2026-08-06 09:43:34Bitcoin Red Team logs 4,962 security findings across 390 Bitcoin projects in AI-assisted auditA volunteer group calling itself the Bitcoin Red Team says it has filed 4,962 security findings across 390 Bitcoin projects in roughly 30 hours, describing the effort as a large-scale ecosystem audit powered in significant part by AI agents. The first situation report, published Wednesday by pseudonymous developer calle, says 85 findings were rated critical and 635 high severity, or 14.5% of the total corpus, with an average of 1.85 serious issues per project and a filing pace of 166 findings an hour. The team said it has grown to 16 people working around the clock, while the report itself lists 17 contributors, including 14 humans and three automated systems. According to calle, 91% of findings came through automated scan intake, though much of the process still involves humans closely guiding the tools. The report also breaks down severity by category, with privacy and coinjoin tools posting the highest share of high-or-critical issues. The campaign arrives as Bitcoin wallet security is under renewed scrutiny following the Coldcard incident, which Ledger CTO Charles Guillemet said showed how AI can now identify crypto code flaws at machine speed.1790
Bitcoin2026-08-06 07:14:11Bitcoin Developers Flag 85 Critical Bugs as AI Scan Finds One Per Hour Per PersonAccording to CoinDesk, Bitcoin developers have flagged 85 critical bugs in the Bitcoin codebase, describing the current situation as "extremely bad." The bugs were identified by a volunteer group that runs AI models against bitcoin codebases. The group says it is averaging roughly one critical bug per hour per person, at about $10,000 a day in compute. The article was written by Shaurya Malwa and edited by Omkar Godbole, and was published on August 6, 2026, with an update later that same morning. The volunteers are using artificial intelligence to scan Bitcoin’s code for vulnerabilities, and their work has so far surfaced 85 critical bugs. The team says the situation is "extremely bad," which points to the severity of the findings. Each volunteer is finding roughly one critical bug per hour. The daily cost of running the AI models is around $10,000. No additional details were provided about which parts of the codebase are affected or whether any patches are in progress. This report comes from CoinDesk's Tech section and is a key update for anyone tracking Bitcoin development and security.1650
Consensys2026-07-18 21:24:15Consensys says North Korea-linked developer previously contributed code to MetaMaskConsensys said it had previously and unintentionally hired a developer linked to North Korea who worked under the alias "Tyler Knapp" and contributed code to MetaMask before access was revoked. According to Drop Site News, the developer joined the company through an external recruiting channel. Consensys has since removed the individual’s code access. The disclosure has drawn market attention to security risks tied to distributed collaboration in Web3 projects, especially when outside hiring channels are involved. The report was cited by Techub, with Wu Blockchain also referencing the development.1340
AI2026-07-01 05:46:09Coinbase CEO Brian Armstrong: AI Will Enhance Software Security Through Pre-Deployment Code ScanningCoinbase CEO Brian Armstrong 表示,AI 将显著提升软件安全性,因其可在代码投产前完成全面扫描。他认为 AI 对防御方更有利,随着 AI 编程工具普及,前置扫描能力将赋予防御方显著优势。540