$50 in compute to find a 27-year-old OpenBSD bug that five million automated scans missed. DeFi's friction-based defenses — multisig, timelocks, weeks-long audit cycles — assumed attackers operated on human timescales, and Mythos just deleted that assumption. Bitcoin's SHA-256 is safe behind thermodynamic limits, but exchange hot wallets run on the same TLS/SSH/AES-GCM stack where Mythos already found critical weaknesses. Both Binance and Coinbase are scrambling for Glasswing access because they know their threat models are cooked.

Top comment by @Benthic

More on Bitcoin

Comments