Non nobis, Domine, non nobis, sed nomini tuo da gloriam.
Public Key
npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Profile Code
nprofile1qqs0eac2gh86s9l24qfmnw52xawhz0f3d862yleaetpafygjmanaxlspz4mhxue69uhhyetvv9ujumt0wd68ytnsw43qz8rhwden5te0dehhxarj9e3xjarrda5kuetj9eek7cmfv9kq3gp5ze
Show more details
Published at
2026-04-18T13:13:37Z Event JSON
{
"id": "a509c361792adbc55eb1c197fb2f0934c0dd362809d054840c62f7a5d634448f" ,
"pubkey": "fcf70a45cfa817eaa813b9ba8a375d713d3169f4a27f3dcac3d49112df67d37e" ,
"created_at": 1776518017 ,
"kind": 0 ,
"tags": [],
"content": "{\"display_name\":\"\",\"name\":\"Cyph3rp9nk\",\"nip05\":\"[email protected] \",\"lud06\":\"\",\"banner\":\"https:\\/\\/m.primal.net\\/LDXY.jpg\",\"lud16\":\"[email protected] \",\"picture\":\"https:\\/\\/m.primal.net\\/HINp.jpg\",\"about\":\"Non nobis, Domine, non nobis, sed nomini tuo da gloriam.\",\"website\":\"\"}" ,
"sig": "66ba907077de44ab166b7a90ba0bc51eb80254602225accd2dca53731f8ffb0a41ab02f87afb54d9204ba8d290549caae8b60de5fe1262f5b8f266787c183a22"
}
Last Notes npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk Any device designed for Bitcoin users has strong incentives to operate maliciously—whether it’s a watch, a hardware wallet, a software wallet, or a dildo. In this regard, Greg Maxwell is right: use general-purpose hardware and software that has been reviewed by thousands of pairs of eyes, such as Bitcoin Core. But this means you’d have to use at least a 2-of-3 scheme with four computers—three of them offline—and digital backups. Plus, the computers should be from different manufacturers and run different operating systems. 99.99% of the people in this space wouldn’t even know where to start, and I could start teaching courses and make a fortune 😂. npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk https://blossom.primal.net/32565b04c278f6865df253ea555d2a443896bb517dfbfcea0c78b7ef0e6fd35f.jpg npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk Look at this virus maximalist who doesn't understand basic math 😂 npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk Knots, an ultra-religious nutcase who got every vaccine and wore a mask to protect himself from a virus that never existed, and who believes the law must be obeyed. Core, a bunch of transgender people working for the CIA. npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk What is an influencer? Someone who gives their opinion on things without having enough technical knowledge about them. npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk hahahahhahahhahahaha https://blossom.primal.net/36ed4510f54f4116b1243f41c631c5b68d5478d562a02199d849b8cb904c7fe7.jpg #nevent1q…vmya npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk A lot of people say toxic maximalism is dead, but damn it, I think we actually need more toxic maximalism. From what I’ve seen, most of you are retarded. npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk Well, it turns out that a chain split is possible after all, even though all this time, whenever I pointed it out, you guys were insulting me. Hahaha, you fucking idiots at bip-110. https://blossom.primal.net/4f700b6bee599918cc038259f3a5b1bf9c24393a9c223b76565c5d90157a9c6e.jpg npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk This is the ranking of hardware wallets by Lunaticoin, one of Spain’s leading influencers. Back then, I warned him that he was completely wrong. I’m still waiting for him to come forward and apologize to everyone. This is the result of you and your accomplices trying to give your opinion on cardiac surgery without being cardiac surgeons. https://blossom.primal.net/e26e0fd7674af87b4b99dbb0a7cf900517236364fa2134cc722a5b8940fb14b9.jpg npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk Capitalists favor closed, restricted AI models. Communists favor open-source, unrestricted AI models. Crazy. npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk nvk's behavior during the hack leaves me with only two options: - He's a sociopath/psychopath - He's a government agent, which doesn't rule out the possibility that he's a sociopath/psychopath #nevent1q…p84y npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk Is Nvk a government agent? npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk In the age of mass surveillance, only living like the Unabomber—isolated in the middle of the woods—can protect you. npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk https://blossom.primal.net/969440bc63d4098931fea2e4b6d7cba5a2dfff988d0deb3e3aab4c80618a1eda.jpg npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk https://gist.github.com/dsbaars/33ace96982773b5dc79d46551f64d467 #nevent1q…xfxv npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk https://blossom.primal.net/abf7632eca87c86e6185455387eac98fc036827f73304c5bea929ccbffb883cf.jpg #nevent1q…7tj2 npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk https://blossom.primal.net/6d65e59c0276c0d8d0251e49cd786d42673a684cced59e58588b76b67210f00c.jpg #nevent1q…s289 npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk https://blossom.primal.net/bf4510b941b2078ef68f7c255785aa06523bd62b771dfa27e8b0d2e7772f08a8.jpg npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk https://blossom.primal.net/a409ee3e406b97f2b7814409a247196f33c0beb90f37118efce1765ef538208f.jpg npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk He's referring to Samourai npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk Good morning! https://blossom.primal.net/27b6587ed3ee3b29a408de35b8fa069ef806b18d93fc647b0e2107f161feb84e.jpg npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk https://blossom.primal.net/55b8c27824e4db2895c6e5cd5ebaef21041e6158b187ab9559f9220ddea3062f.jpg npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk Damn, between Scamourai, the Coldcard fanatics, and the Bip-110 folks—what a bunch of idiots. npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk Te voy a contestar en español que se me da mejor insultar.
Tú lo que eres es un hijo de la gran puta que te calzas un retraso más grande que la profundidad de la fosa de las marianas.
Si quieres chuparle la polla a Scamourai es tu problema no el mío, no vengas aquí a hacerme responsable de cualquier mal en el mundo cuando yo estoy harto de defender los coordinadores descentralizados, pero que vas a saber tu si tienes las neuronas justas para no cagarte encima todas las mañanas cuando te despiertas.
Por mi la subnormales como tú os podéis morir todos, el desprecio que siento hacia gente como tú que sois NPCs del influencer de turno o de la TV de turno no es más que el respeto que le puedo mostrar a puta cucaracha cochambrosa recién salida de la alcantarilla.
Te lo voy a decir con SONORIDAD, ERES UN HIJO DE LA GRAN PUTA!
Dicho esto, bloqueado.
#nevent1q…xxa6 npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk It's unbelievable how many idiots there are in the world. I've run out of patience; I'm going to insult you and belittle you if you come and piss me off. npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk Since when are those my favorite developers? You're an idiot, aren't you? Have I ever scammed anyone? Die, you son of a bitch. npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk #nevent1q…4tg3 npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk Bingo https://blossom.primal.net/2153938d204e0c955f051ff123d74278bf342226ef8afdb5783a9e603532ba8e.jpg npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk https://blossom.primal.net/00958c1ff87b98ecbe9072e638c5a2883d51309496d5dda8d3878beda077a3bc.jpg #nevent1q…7nk8 npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk https://blossom.primal.net/b966252f0d16623234f3c6f42175ebc29027a8efe79b47f19902e1543c94b80e.jpg npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk Es que es muy difícil posicionarse en A o B, todo tiene cosas buenas y cosas malas, y en temas de seguridad informática la cosa se complica más. La realidad aunque duela es que en Bitcoin de momento no tenemos un sistema universal y sólido de auto custodia, todo tiene pros y contras. Yo mismo siempre he sido defensor de passphrase, pero visto el desarrollo de la IA y todo lo que está pasando ya nunca más puedo confiar en un solo fabricante. Si yo que me decido a esto no puedo saberlo? Como ciertos “influencers” pueden lanzar afirmaciones tan taxativas de eso es malo y bueno? Los que te decían que Coldcard era bueno te decían que Jade malo cuando siempre he dicho que Jade está hecho por gente que entiende de criptografía. Y mira que Adam Back y mucha gente de su equipo me caen como el culo, pero a mí no me paga nadie, solo soy un libre pensador 😂. npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk What I mean is: - We light the fire with a lighter - The lighter manufacturer screws up and the lighter doesn't work - We all go back to lighting the fire by striking stones together. Entropy in a computer is fine; the problem is that Coldcard didn't use it. The problem wasn’t the lighter; it’s that the lighter manufacturer didn’t put any gas in it. npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk No, that's why the only option if you decide to use these devices is multi-signature. My point was that I've harshly criticized SE for being black boxes, and Jade uses an elegant solution to this problem—which is nothing more than a multi-signature setup between your device and its server. This way, everything remains open source and there's no black box; you can even set up your own Oracle server. npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk I'm against rolling dice simply because we shouldn't have to resort to that. Computer entropy is fine; it's just that Coldcard doesn't use this entropy or that of its chip. npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk El tema no es que la seed o la passphrase no sean seguras, el tema es que ese hardware wallet este comprometido de alguna forma y entonces tú seed y passphrase se vean comprometidas. Los hww wallets son mucho más propensos a ataques de cadena de suministro que el hardware convencional. Llegado el punto de paranoia máxima, frente a eso solo te protege la multifirma con diferentes proveedores de hww o tipos de dispositivos como ordenadores offline o teléfonos offline. npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk Es segura, pero estás confiando solo en un fabricante, y si el fabricante del hardware wallet compromete de alguna forma esa passphrase? npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk You're making the same mistake again; I don't have time to argue. npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk Just so you know, I really can't stand Gentoo. You know why? The worst disasters I've ever seen have been with Gentoo in professional environments, caused by computer geeks who wanted to use that crap. That crap is fine for your home, but not for professional environments. When you’re managing thousands of machines, as I have been, I don’t have time for that kind of nonsense—I need secure and stable environments. npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk Okay, recommend Gentoo to a beginner, and let them enjoy the security. npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk From a security standpoint, Arch Linux is terrible, for example. Any distribution worth its salt must include the following by default: - Secure Boot - SELinux or AppArmor - Firewall This rules out most “geeky” distributions that have neither Secure Boot nor SELinux or AppArmor. npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk I've been analyzing this whole situation since Saturday, and I think that given the circumstances and what I foresee for the near future, only multi-signature can mitigate this. I've never liked recommending it because it's not feasible for beginners, but that's just the way it is. And please, stop with the dice nonsense. Use, for example, a 2-of-3 multi-signature setup; mix hardware wallets, an offline computer, even an offline cell phone; use different platforms and different entropies. That’s just the way it is—we’re facing a new paradigm with AI. npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk I hope you’ve learned your lesson. Stop listening to podcasters and influencers—you’ll have to figure everything out on your own. This whole space is already corrupt; they’re all snake oil salesmen. And just as you’d look for a surgeon with years of experience if you were having heart surgery, do the same if you need outside help with Bitcoin or computer-related issues. Notice that most of them recommended ColdCard—what basis did they have for recommending such crap? I explained to you the reasons why I only trusted Jade (not Secure Element), and everyone made fun of me. Notice that most of them recommended Samurai for privacy—did these idiots even review the code? These same people were selling you crappy privacy courses taught by parasites like Dr. Riviera from *The Simpsons*. They recommend bad Linux distributions without having a basic understanding of cybersecurity; they recommend shitty KYC exchanges disguised as NO-KYC, and so on—thousands and thousands of mistakes—simply because they’re not professionals in this field. The damage they’ve done is irreparable. Do you know why they do it? Because they aren’t IT professionals and don’t make money from it—they make money by acting like charlatans. npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk Good morning! https://blossom.primal.net/cab7c91776d79415e6f889f4cf32c33c8461ba50245ae3e15541ed20fe877778.jpg npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk I use 5 different blosson servers npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk 😂 https://blossom.primal.net/8c9f1af1bd0c37d6aeff4c46193150f08ad3ec3e13b60490a1232ae8f5da1c9c.jpg npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk 5 dias para que los pesados de bip-110 se bifurquen 😂 npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk 2021 https://blossom.primal.net/b65ae4658040818e428611f207706a91a391573128ea7688d24d93d0b5372143.jpg npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk The guy who thinks everything revolves around BIP-110 and still hasn't realized he doesn't have any options. https://blossom.primal.net/b3e0cd84e0459e85810a3eb34a1f493b17af442df834107f2121e7a5d0760cfb.jpg npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk Bitcoin has become full of idiots... here I'm going to give several examples... The guy who keeps claiming that Saylor is buying when Saylor is now only selling. https://blossom.primal.net/8c696fd2fd5b070b0192946d8c63c5c90cbd2a6f94135172f0d8e66456638ebb.jpg npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk Michael Saylor's Strategy has sold 1,637 BTC https://blossom.primal.net/445c27907ae2c48013e865391dc1e90596fede877c492f16d1804243b2be3439.jpg npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk You should know that I have donated most of what I have received to privacy projects, and also much more. Now I've seen the kind of person you are—you’re an asshole. By the way, BIP-110 is going to fail, idiot. npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk This is pretty despicable—you could simply donate the funds you've raised, but you'd rather mine hashes for your own cause while hiding behind a charitable cause. https://blossom.primal.net/242d2fa26383c389af453da57785ad65cc758de6e189a4f8f3dfcdc1184d4c2d.jpg npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk https://blossom.primal.net/629a09110556a7a93824bb2d4e2a84a6002f89b90b51a5ab461422633e633083.jpg npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk If the three words were not chosen at random, there is hardly any entropy. npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk We have to stay alert.... https://blossom.primal.net/70c7a186c8ae11a716769e6dce21ab286bf86c6d91b9a9f798e95c4fbbb418e9.jpg npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk It’s completely valid what you’re saying, but it’s also more practical for people to remember words than a password like this. npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk 3-word passphrase hacked... https://blossom.primal.net/74921825166063a30c0c9f936472f4c2d62358f108d32223f533cb317b3e09ee.jpg npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk Coldcard npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk They gained access to the seeds generated by Coldcard because they had an entropy of just 40 bits. That was the attack in the first wave, but now they’re targeting those seeds and also performing brute-force attacks on passphrases. If you have a seed generated by Coldcard—regardless of the model or year (let’s keep things simple and forget about exceptions)—migrate your data to a new seed with sufficient entropy, which can be generated on a Trezor, Jade, or an offline computer (freshly formatted with Linux) using Sparrow or Electrum. After creating the seed, generate a passphrase with KeepassXC that has at least 90 bits of entropy. Ideally, it would be 128, but certain hardware wallets won’t accept passphrases of that length based on the number of words, so let’s not overcomplicate things—90 bits of entropy can’t be hacked. Store the passphrase and the seed separately. Let’s also not overcomplicate things with multisignature—not everyone is ready for that. The current passphrase acts as a 2-of-2 multisignature. npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk Edited due to errors made in the rush, so that there are no misunderstandings. "It seems they are already stealing funds from seeds protected with a passphrase; specifically, it involved a passphrase consisting of two simple words." npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk Urgent: It seems they are already stealing funds from seed phrases protected with a passphrase; specifically, it involved a seed phrase consisting of two simple words. To make things easier, here are some simple instructions for creating a secure passphrase. Download KeePassXC, open the password generator, and generate a passphrase. By default, it uses 7 words and 90 bits of entropy, making it practically impossible to crack by brute force. Write it down just as you would the seed phrase, and never store the seed phrase and the passphrase together. Stay safe. https://blossom.primal.net/d808bc603d6dddc2f74325f6fb1a6a06b23cbc40578073aaf030e150628e7a12.jpg npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk The Samourai developers might as well commit seppuku for handing over all the xpub keys to the NSA, and for being able to track coinjoin inputs and outputs through faulty Tor circuits. https://blossom.primal.net/b0c49a96452645383a94431c97945b48e6bbc633cee498769661c32b9e73a874.jpg npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk How much damage professional encroachment is doing to Bitcoin. npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk A Trezor T with Secure SD is better than a Trezor 7 from the point of view of cryptography. Refer to Kerckhoffs' principle of cryptography. #nevent1q…9mye npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk Here we have one of the influencers who has never worked professionally in IT, one of those who recommended Scamourai's flawed solution and a crappy wallet like Coldcard, talking nonsense once again. That "vulnerability" of the Trezor One or T was actually its greatest strength. It forced you to use a passphrase or Secure SD in the case of the Trezor T, meaning all the security relied on the algorithm and the strength of the password, which is exactly how it should be in a perfect cryptographic system, rather than on black-box solutions like Secure Elements. https://blossom.primal.net/492e94dbd2abc38d9377660a6dccb1f431fa8c37f9212fb73587558a68d04ee6.jpg npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk More… https://blossom.primal.net/92bd452d0b24542322ad2be68e148cfb11dc7d3865bbfa430ba912a30e710758.jpg #nevent1q…n5e5 npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk It's possible that this bug had already been exploited more discreetly, or that one user simply generated the same seed as another. https://blossom.primal.net/17ee5c841f91998f0cead0d4698dac3d4b3a6a5df6d1135b153d22faee325166.jpg npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk #nevent1q…7ecq npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk Just to clarify, the hack had nothing to do with secure elements; the issue of secure elements is a personal crusade of mine. The hack was a rookie mistake—they failed at the most basic level: the seed entropy. npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk https://blossom.primal.net/cca82cb4f319a11c61722b13e238a771a56229ce718605f87317cc5b0019bd12.jpg npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk Guys, you need to be prepared for all this crap. Remember, if you use a passphrase, make sure it has at least 128 bits of entropy. Otherwise, use multi-signature. I'm afraid more vulnerabilities will come to light over the next few months. npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk https://blossom.primal.net/155465fdc3e926498be11c8371df812c0f269e06971c52a90f7b4345950522e6.jpg npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk WOW https://blossom.primal.net/9eb41b01c6182384e96b11665d9fd18203376d8b7ee60aa8ae00bd3576bc3c85.jpg npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk Today I'll only say one more thing. Satoshi's coins have not been hacked, even though hardware wallets and multisignature didn't exist back then. Think. npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk They're a black box that I don't know what it does, and it violates Kerckhoffs' cryptography principle. npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk Just to clarify, I wouldn't use the Trezor 1 for many reasons. The main one is that you can't enter the passphrase on the device, and it doesn't have MicroSD card encryption for the PIN either. #nevent1q…yvxf npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk It has a secure element npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk Yes, I've always said that. npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk A nivel técnico? Bueno tu solo eres un indocumentado y chupapollas más. Recuerda usar coldcard, samourai y HODLHODL. Mas imbecil y no naces. npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk As long as they are completely open source and have no secure elements, they fully meet the requirements. But I don't know about this specific case. npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk This is the level https://blossom.primal.net/51ae157fd87eb77ee165c20a3c30cc7da6dec5b427ee1df2c153f77439de9daf.jpg npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk Applying this principle, right from the start you should only use wallets that have no secure hardware component and are fully open-source—and the only ones that meet these criteria are: - Trezor 1 and Trezor T - Jade - SeedSigner Add a passphrase with more than 128 bits of entropy, and as of today, these are the most secure options. Failing that, you can use them for multi-signature transactions. Anyone who doesn’t understand why I’m saying this knows nothing about cryptography and is just an uninformed idiot. And an old, offline PC running Linux encrypted via LUKS is also perfectly valid as a signing device, as long as you use a passphrase and avoid using TPM to encrypt the disk. #nevent1q…8t2t npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk Always use a passphrase with more than 128 bits of entropy or, failing that, multi-signature. Be aware that secure elements are useless and pose a future risk. Cryptography is not a matter of trusting a third party; a secure element implies trust in a third party. Offline, encrypted computers are just as valid—if not more so—than a hardware wallet. Cybersecurity is an active discipline, not a passive one. npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk Why am I usually right? Because I've spent a lifetime practicing my profession: millions of lines of code, thousands of security incidents, managing large data centers. Cybersecurity is the same everywhere; it doesn't matter whether it's a hardware wallet or a web server—the methodology is the same for finding vulnerabilities, fixing them, and preventing them. My opinion is backed by thousands of hours of active, not theoretical, experience. The opinion of most Bitcoin podcasters is highly biased and lacks real-world experience. Many times, it's not even an opinion they've formed themselves, but one copied from someone else. It's hard for me because when I listen to them, all I hear is nonsense. I share my opinion, and they treat me like I'm crazy, but time puts everyone in their proper place. Anyway, it's sad. By the way, I'm against university degrees—they're useless, even though I have them myself. What really matters is experience. But the people you listen to don't know the trade of being an IT professional, nor do they practice it; they're just YouTubers, if you can even call that a profession. #nevent1q…xeyx npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk The main Bitcoin program/podcast in Spanish has only been recommending failed solutions from the very beginning. They ignored my recommendation not to promote secure-element hardware wallets (HWW), especially ColdCard, which I have been very critical of. They ignored my recommendation not to promote Samourai because it was a flawed solution. They ignored my recommendation not to promote HODLHODL as a non-KYC service. The problem is that the host is an industrial engineer, and his main assistant, who gives opinions on privacy, is not a computer scientist either. They are simply outsiders to a profession they do not practice, and this is the result: they have done a great deal of harm to the community by teaching things incorrectly. npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk @npub1az9…m8y8 You have zero dignity. How dare you repost this? https://blossom.primal.net/21fb5cfb514546bd40ded21603d4a6b6c6e0927d99dccd2a2284a77ac96a92c0.jpg npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk 💀 https://blossom.primal.net/6ff7d6fc91cedb22af1863abcdfd533fbfe621ea853cf8ca961a86ea76d17c0d.jpg npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk https://blossom.primal.net/2366d85605298b4823b251692d7b3e1a920d7183e289bbae6a28b2338c44f328.jpg npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk ☠️ https://blossom.primal.net/2eab9d685c31c48bcebaa221fe138b8244e7c963e8b8ffafd163c24842fcf7f7.jpg npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk 💯 "From a different angle: Let's finally retire the myth about air-gap. Air-gap doesn’t necessarily imply stronger security. With air-gapped wallets you miss this entropy from the host. If the randomness is not sufficient and keys are predictable, the attacker never needs to touch your hardware." npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk 😢 https://blossom.primal.net/e0829f0a06f4ec5914d16ff97c03bed7537adb956eccc6c29189a6a5822e2fe5.png npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk I'm so tired of always being right... 😴 #nevent1q…fasu npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk I never said at any point that it has anything to do with the secure element... I said that I've already had problems with NVK regarding secure elements... He's a fool, and I'm not surprised this is happening to him... npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk Las garrapatas siempre queriendo hacer negocio. Todo este grupito de tontos indocumentados pertenecian al club scamourai y coldcard. https://blossom.primal.net/72e5df3da68a46cd861cf416899afdc349ad4f1fc89d2a99468e51609d6b58e9.png npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk I fear that China's strategy will be to use AI as a weapon against the West. It will promote models like Kimi K3 that enable malicious activity. This is good from the perspective of freedom, but bad from the perspective of how cybersecurity has been built up over the years. Bad for Bitcoin wallets. npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk 😂 https://blossom.primal.net/a77e02d88a4e957e654f9215316803ba4aba86c4154a20233ace5164a6c9ce5a.png npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk https://blossom.primal.net/0f59613c11715533b2ffc84a1c3944ab6d3ac963413c9728b139a6c300adee7d.png npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk his post has really aged poorly. My crusade against “secure” elements ran up against this man's ignorance and arrogance back then. Oh well. https://blossom.primal.net/f351d0995000af802b009e30f70d3ec4f63255a95f255b1967dbfcfae7433b27.png npub1lnms53w04qt742qnhxag5d6awy7nz6055flnmjkr6jg39hm86dlq7arrnt Cyph3rp9nk Coldcard Mk3 Security Advisory https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/