انضم إلى نوستر
2026-08-27 19:48:53 UTC

johnbwick on Nostr: "Hey I just met you. And this is crazy. But here's my crypto library that makes your ...

"Hey I just met you. And this is crazy. But here's my crypto library that makes your whole life's work insecure. So merge me maybe ;D"



My #Coldcard findings: based on public data, there is a high probability that the #Coinkite CTO intentionally planted an entropy vulnerability into the firmware, and there is good reason to believe that the CEO knew about it at the time the exploit was distributed to customers.
#Coinkite CTO, pretending to be an external contributor, switches out Coldcard's strong entropy implementation for false/pseudo entropy, thus allowing future wallets to be remotely swept.

Plebs: "It's an honest mistake. Python is hard! These things happen."

Peter Gray had an extensive debugging setup for the #Coldcard development process. He even left the USB REPL enabled only days before the vulnerability was shipped, meaning he had been inside the runtime inspecting the state of variables within #Coldcard during their big entropy changes.

Nobody makes the massive entropy changes they did without stepping into an interactive debugger (or automated testing) to see if things are in tact or broken. And guess what? Peter did.

He left the interactive debugger enabled at the time that he shipped the entropy vulnerability, meaning: he must have been inspecting the entropy implementation, and saw that Yasmarang was "defaulted" to as a result of the innocuous "bug" that had been introduced.

#Bitcoin