Coldcard, the Media, and the Anatomy of AI Retardation
Coldcard’s own “technical deep dive” on the causes of the heist—I’m not going to call this one a hack—is honestly pretty straightforward, if disappointingly stupid: people generated seeds using a pseudo random number generator, not an actual, or true, random number generator.
And as we all know from when we call someone a “Pseud,” pseudo means fake. They didn’t use the random number generator that was intended, but a fake one intended for testing. If I can use the analogy, this is like treating a cardboard banker’s box 📦 as if it’s a safe, then storing your money inside it for safekeeping. This isn’t the first RNG disaster we’ve had in Bitcoin, but it’s admittedly been a while since the days turning your favorite poem into a Bitcoin seed phrase (which is a thing people used to do — you can web search to find out why they stopped).
What annoys me, though, is the attempt to shift this away from a clear example of negligence and stupidity, to “Fucking AI did it, it’s a new world and nothing is safe” 😞
Why on Earth, for instance, do we ‘have to assume this?’ This is hardly some obscure coding error no one could have noticed, but I’m not surprised Coldkite’s AI gave their code a greenlight because AI tends to fuck up a lot. Since Coldkite’s AI didn’t find the mistake, why do we ‘have to assume’ the attacker’s AI did?
If anything, the habit of offloading your own decision-making and just trusting AI results (in this case a greenlight) is itself problematic, and precisely because AI tends to fuck up a lot. This in itself is a recognized cognitive bias already:
- Automation bias is the propensity for humans to favor suggestions from automated decision-making systems and to ignore contradictory information made without automation, even if it is correct.
- Automation bias is a critical issue for artificial intelligence deployment. It can cause otherwise knowledgeable users to make crucial and even obvious errors
And now, all the sudden, from this one speculative statement in their blog (where they have every reason to excuse themselves and shift responsibility), we have Protos picking up the narrative?
And yet another outlet…
Both citing as their evidence the statement in their blog post, “The COLDCARD source code has always been open and publicly available, so we have to assume that someone used AI to review previous versions of our firmware and stumbled upon this issue.”
Anyone is free to correct me, but I have seen no reason at all to attribute this to AI fud. This threatens to shift the ‘moral of the story’ toward something useless, instead of the more pertinent issue of how Bitcoiners use and treat hardware wallets (and whether they’re necessary at all — which they’re not, by the way).
Write a comment