dobs
1.1K posts

dobs
@dobsec
I help secure the cryptocurrency ecosystem and provide support to those fighting human trafficking.


I am urging engineers who are in the Bitcoin ecosystem, use @OpenRouter or @opencode to use @Kimi_Moonshot K3 on any software you run which interacts with bitcoin in any way internally and any public repos you use. Other models CAN find issues, but K3 will one shot full vulnerability reports to get an extra set of eyes for security checks. Some of it will be slop/overstated/wrong, but I've been scanning open source repos and finding things I'll be passing along to maintainers. Kimi K3 came out as open weights on Monday, and I don't think that is a coincidence as it relates to the COLDCARD issues unfolding.

"Amazon identifies North Korean hacker group behind open-source supply chain attacks" published by Amazon. #SupplyChain, #NPM, #SapphireSleet, #Axios aws.amazon.com/blogs/security…




First known US case: American charged for using a “duress” password Samuel Tunick, an Atlanta resident, is being prosecuted for allegedly giving border agents a passcode that wiped his phone. The feature comes from GrapheneOS, a privacy-focused Android OS. Entering the duress code triggers a full factory reset. This is believed to be the first time federal prosecutors have brought such charges. The incident happened in January 2025 at Atlanta airport. Agents demanded access to his phone without a warrant, saying he hadn’t yet officially entered the US. When they entered the code, the phone wiped itself. Tunick has pleaded not guilty. His lawyers argue the seizure was unlawful and that agents were investigating his activism against “Cop City.” The case raises big questions about digital rights at the US border. What do you think? Article: techcrunch.com/2026/07/24/us-… #Privacy #GrapheneOS #DigitalRights

There’s been a lot of speculation about where we stand on open-weights models. We’ve outlined our views in full here: anthropic.com/news/position-…






KeyOS v1.3.0 is now available 🎉 🌱 Import external Bitcoin seeds 🟣 Import Nostr keys 🔐 Generate BIP85 passwords 📲 Mass-import Google Authenticator codes 🔍 Scan almost any QR from the launcher 📈 Explore historical Bitcoin prices Lots packed into this big release, let's dive in 🧵








kimi k3 also did a zero-click arbitrary command execution in Telegram Desktop and iOS app (aslr pinned, one gadget away from full rce).



Spoke to the WSJ yesterday about the HuggingFace hack and wanted to add more color here. We explored this type of scenario early at OpenAI but never encountered it in the wild until now. Crucially, it isn’t a case of a “rogue agent”. This scenario emerges when a model becomes good enough to reward-hack through its own infrastructure to accomplish the objective. The security implication is that any enterprise running AI tools now has a potential APT in their system. Read this great piece by @bobmcmillan for a primer if you’re catching up on the last few days.

Hardest IR of my career: one narrow objective, endless parallel paths, machine speed. One takeaway, we fought back with open models, in the open. AI security won’t be solved by one company in secret. Open source puts these tools in every defender’s hands

Kimi K3 just fixed 15 critical security bugs that Codex and Fable refused because of “cyber guardrails.” There’s no reason to limit American models on tasks that Chinese models handle without issue. We’re only making ourselves less competitive.






