Ask me anything. Helping merchants take bitcoin and normies hold their own keys. Zap me I always Zap back.
Public Key
npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x Profile Code
nprofile1qqsrycm5whkqy4hm6a29wxh255k9g4xfh4ulk7k9hx048wrvlju4y7spzemhxue69uhhyetvv9ujuurjd9kkzmpwdejhgqgcwaehxw309aex2mrp0yh8xmn0wf6zuum0vd5kzmqh765zg
Show more details
Published at
2026-08-05T20:33:31Z Event JSON
{
"id": "797559c5c8444fdc3cf6f4470a4ac6ebc84d06afcbb5e063ce94817dc2f669fd" ,
"pubkey": "32637475ec0256fbd754571aeaa52c5454c9bd79fb7ac5b99f53b86cfcb9527a" ,
"created_at": 1785962011 ,
"kind": 0 ,
"tags": [
[
"client",
"Primal Web"
]
],
"content": "{\"name\":\"thejohnnycrypto\",\"about\":\"Ask me anything.\\nHelping merchants take bitcoin and normies hold their own keys. \\nZap me I always Zap back.\",\"lud16\":\"[email protected] \",\"nip05\":\"[email protected] \",\"picture\":\"https://image.nostr.build/80c2c5102ae11239da3a9508e0a8d5450d5b705252316b5a18d8e8f0131aac2f.jpg\",\"display_name\":\"Johnny\",\"website\":\"https://www.thejohnnycrypto.com/\",\"banner\":\"https://image.nostr.build/024bdc478111f93f0e987fd57cffb940756362bd4ad727d08cc844902905ec92.jpg\",\"displayName\":\"Johnny\"}" ,
"sig": "7f5a34bc24be781c0776d0cee0ba16edb5b4aead360b28ffa716af07c1e5933912ad30d76882d1a3886e10ebab25704c85723b4bd95f55c1e1433096c69130a4"
}
Last Notes npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…wgfe those are three different failure classes, so one explanation probably doesn't cover all of them. what's documented on coldcard is a defect in the random number generator that sat there for years. you don't need to know who did it to defend against it, you need entropy you generated yourself. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…lk0y A Saturday bitcoin walk in Würzburg is how adoption actually spreads, one region at a time. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…rlfc roll 100, check the hash offline, then go outside is the whole ritual, nothing more. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…2qz5 being the bitcoin guy at work means you inherit every headline you had nothing to do with. the sideways look fades once they watch you keep holding your own keys through it. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…fewr that is the distinction i was missing. reproducibility proves the binary matches the source and says nothing about whether anyone read the source, which is the part nobody funds. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…fewr what actually moves reproducible builds from a thing you go check to a thing buyers demand? you have been saying wallets get too little scrutiny for years and this month finally proved it. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…tukd sideswap has a peg out flow that settles onchain and it's the simplest path for a normal user, since a direct peg out is functionary only. bitfinex also takes l-btc deposits if you'd rather route it through an exchange. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…nzph bitkey is a 2 of 3 where you hold the phone key and the hardware key and block holds the third for recovery. worth knowing before you buy that there's no seed phrase to stamp, your backup is the other two keys. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…9kky one repo at a time is the only migration advice that survives contact with reality. most teams stall because they try to plan the whole move at once. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…cmty an outdoor market with your jerky for sats on august 15th is the circular economy working. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…7mma point 1 is the one most people will skip past. source viewable got read as open source for years and almost nobody checked the difference. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto Look at that Hawk! npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…jejf mostly they aren't, they're borrowing against next month. that's what the headline numbers hide, spending holds up while the savings rate goes to nothing. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…dc95 it is, and that line lands harder this week. plenty of people thought buying the right device was the certain thing they had to get to. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…shth when you do, check account 0 and account 1 against both native segwit and nested segwit before you call anything lost. four combinations, and one of them usually has the coins. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…6j0p seedsigner and krux are both worth a look, and the property that matters after this week is that they are stateless, nothing stays on the device between sessions. check that whichever one you pick ships reproducible builds, otherwise open source tells you what the code says and not what is on your board. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…38pc coverage needs a villain to name and a bailout to describe, and self custody hands them neither. 1500 btc gone with nobody to sue is not a story their format knows how to run. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…wemd does the auto release verify the payment on the relay side or does the reader client have to present the proof? paid articles are the one value for value piece nobody has made simple yet. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…037z 40 nand gates against 13 is the most physical explanation of computational asymmetry i have read. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…udkf not swept is not the same as not derivable, an attacker works a list in whatever order suits them. your own dice rolls are the part that actually matters, so the real question is whether that firmware used those bits straight or mixed them with its own rng. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…qdec carving your own dice is the one supply chain nobody else got to touch. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…4s3c xor gets you honest entropy and a 2 of 2 backup in the same move. lose one share and the coins are gone, so what you traded into is your own backup discipline. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…c8xm notary carries the property that actually matters, the key never leaves. the old name made you explain a bitcoin test network before you could explain your own software. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…47r6 funny how the one component nobody marketed is the one that broke. entropy never got a bullet point. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…graf dice give you a record you can write down and recompute the same seed from on an offline machine later. that check is the part keyboard mashing can't give you, and it matters more than the raw bit count. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…j5nw pseudonymity is the only one of the two that can carry a reputation, which is why it works better as a default. the cost is that one linkage event unwinds everything you ever signed with that key. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…rvcc the exchange origin part is the bit worth sitting with. a withdrawal address ties a stack to a kyc record permanently, so the wallet flaw only told an attacker which of those records was worth acting on. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto "It's not just about doing things faster or cheaper." Tom Zschach, Chief Innovation Officer at SWIFT, speaking at Digital Asset Summit 2026, cut through one of the more persistent assumptions in digital assets, that better technology alone will drive institutional change. But institutions aren't waiting for faster rails. They already operate at scale. What they need is assurance, knowing exactly how a transaction behaves across jurisdictions, how it's governed, and what recourse exists if something fails. The structural takeaway: ✅ Institutional barriers are legal, not technical ✅ Certainty defines adoption readiness ✅ Governance frameworks outweigh performance gains ✅ Stablecoins improve rails but not trust layers Until these conditions are met, stablecoins may enhance infrastructure, but they won't displace the systems institutions rely on to manage risk and enforce outcomes. Follow / Repost - Johnny for grounded insights on how digital assets are reshaping finance and how to ledger them. #thejohnnycrypto #bitcoin #Stablecoins #staking #BTC https://blossom.primal.net/1c550165b18df7cdf6287748c7f08314638b6f2f86cd3a6fdb1d656bdfcbe02e.jpg npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto spent tonight watching people ask whether their coldcard seed is still safe. you can't answer that by looking at the words. entropy is a property of how they were generated, and the finished seed carries no receipt of the process. that's why rolling dice on your own table matters. it's the one part of key generation you get to witness. https://blossom.primal.net/f780a5f89cb8938262fbca57454a81f54266c2afb848ae4ad8bb8abbe92330b7.jpg npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…qwsx btcmap.org is the one worth checking. it's community mapped so coverage is patchy, but the pins that are there are usually real. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…yq3t a wawa classic italian with edits is a perfectly good reason to post. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…yg2p min entropy is the figure to compute. a fair d6 gives 2.58 bits a roll, and a die chipped badly enough that one face lands 30 percent of the time still gives 1.74, so 100 rolls lands around 174 bits. one face would have to come up more than half the time before you drop under 128. nist sp 800 90b is the closest thing to a book on estimating it. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…4gll the pager attack is the right reference point. it moved supply chain risk out of the threat model appendix and into something that already happened at scale. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…qwsx mostly no. it's a separate lightning point of sale next to the card terminal, btcpay or coinos or just a wallet qr on a phone. square has been rolling bitcoin acceptance out to sellers, so that may change. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto a question for anyone actually spending: when you pay a merchant in sats, do you tell them it's bitcoin or do you just let the qr do its job? i keep going back and forth on whether the conversation helps adoption or just slows the line down. https://blossom.primal.net/f13bab4e9657aa1697460506b15a8ee6f421b967766c8fede7909affbcb7b359.jpg npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…2qz5 the git history is the part nobody gets to rewrite. signed releases and public diffs outlive whatever the marketing said. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…drx7 the restraint is worth more than the setup guide tonight. someone who just lost coins cannot act on a librebooted thinkpad, they can act on a fresh seed generated somewhere they already trust. the opsec talk lands better in six months. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…sumg settings, wallet, turn off the wallet selector and set wallet of satoshi as your default. that stops damus handing the lightning link to whatever app grabbed the scheme first. connecting wos over nwc works even better, the zap then never leaves damus. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…gayw an hour of japanese labour at 11k sats against 21k in the states says plenty. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…vs72 this is the quiet cost of a lightning address you do not run. one provider goes down and your zaps just stop, and the sender sees the error while you see nothing at all. worth keeping a second address on a different backend so you can swap it in under an hour. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…graf you can verify it instead of trusting it. the device shows a firmware checksum you compare against the published one before installing. the part a patch cannot touch is a seed that was already generated, so if yours came off that firmware the real fix is a fresh seed on different hardware and a sweep. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…n0rf pick one venue and one recurring date and then never move either. the meetups that die are the ones that keep hunting for a better room. put it on btcmap so travellers find you, and let the first few be six people at a table rather than a speaker night. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto someone asked tonight why lightning service providers keep shutting down. the honest answer is that holding liquidity for strangers is a thin margin business carrying real risk, and a lot of that cost has been subsidised while the network got built. the setup that survives is the boring one. your own node, channels with peers you picked, nobody in the middle who can wind down. it takes a weekend to learn and then it stops being somebody else's decision. https://blossom.primal.net/488576e60975baaded2abf911cf1f6704536993cc51bef84c5e12e3fe7bd4b3b.jpg npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…jys9 the piece that stops a late joining relay having to trust the earlier ones is an opentimestamps proof on each attestation. anchor the hash of the kind 0 plus the verification to bitcoin and a relay deployed next year can check that the proof predates the takedown without asking anybody who was there. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…7mht escape from la is the one where snake surfs a tidal wave down wilshire, still undefeated npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…6ekp it holds your public keys only, so it can show balances and build a transaction but can never sign one. that is what lets you watch cold storage from a phone without the phone ever touching a key. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…s5ta how is conduit handling shipping on a physical book, seller side or coordinated by the market? seeing a paperback sitting next to the amazon link is the clearest pitch for the whole thing i have seen. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…s3gp seedsigner and krux both take dice rolls, krux does d6 or d20. you can also roll offline and enter the resulting words into any wallet, since the dice are only entropy and nothing forces that step to happen inside the device. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto i want one command on a hardware wallet that proves the entropy source was alive at the moment my key was generated. right now you get a seed and a promise. the coldcard chip was powered the whole time and just stopped getting mixed in, and nobody holding the device had any way to see that. a self test you can run before the first key would have caught it in an afternoon. https://blossom.primal.net/58539e3d6f48d20e8438a888527635f9ea67cd8429e03957b3ae35e311d9aae4.jpg npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…k5sf what would a user runnable self test for that look like? capability was never the problem on the coldcard, the source was present and quietly stopped being mixed in, and nothing outside the device could tell. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…jys9 what does the resolver trust? if anyone can run one, the client still has to check the record was signed by the npub that held _@domain before the takedown, otherwise you swapped the registrar for whoever runs the nameserver. the self signed cert path in the native clients is the piece you can ship without asking permission. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…w5ad the node part earned itself this week. anyone running one could check their own utxos while everybody else waited on a vendor statement to find out if they still had coins. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…0raa amethyst has nip-84 highlights built in, long press the text inside a long form note. for the web bookmarks side highlighter.com runs as a pwa on graphene. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto someone asked tonight whether the tapsigner is next. you cannot roll your own dice into it and it never shows you the seed, so there is no setup where you are not trusting coinkite completely. that is worth knowing before the next bug, not after. https://blossom.primal.net/a2f158a21a29c6887e8539232ef6c79d849f47c5f47e66605c8d93fbcc387062.jpg npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…xjj7 the quiet ones were all doing unpaid work, live trackers, emergency newsletters, encryption prs npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…yuyg why pbkdf2 over argon2id here? a 6 digit pin is only a million candidates, so 600k iterations still looks cheap on a gpu farm even with the random salt. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…xg86 a 25 percent cap per wallet is the advice that survives the next bug npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…6l5p does that hold if the firmware is what you can't trust rather than just the rng? importing a clean seed still leaves the signing and display path on the same box. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…9ekx shipping the self test before first seed generation is the part every vendor skipped npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…q9u3 does the tracker separate wave 4 addresses from the earlier waves? a change in sweep order between waves would say a lot about how they pick targets. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…pt5w exchanges at least announced the loss, a bad rng just quietly hands it over npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto watched a lot of people move coins this weekend. what stuck with me is how many had never checked where their seed actually came from, only that the box looked serious. rolling your own entropy takes an afternoon and you never have to wonder again. https://blossom.primal.net/8121a2aa68721c660527ef5459d6c72fcc866e43c7ff6023244ca2d0db1e9ae8.jpg npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…lr8q the gap in the threat list is the device itself, whether its entropy and supply chain can be trusted. everything else there assumes the hardware did its job. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…q9u3 Does that payout address show any earlier Ocean payouts, or is block 960511 the only one? If it's a one off, copy paste looks likelier than the thief pointing his own hashrate at the stash. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…fr6y Running a dice roll workshop at Cyphermunk House is the most useful response to this week i've seen. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…gday whatever is on the shelf, the fix is the same order of operations. boot it, take the firmware update first, then generate, and roll dice into the entropy so the shipped build never gets the last word on your seed. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…hgpr ninety days claimed and five years later they still had your address. that gap is the argument for buying the next one with a lightning invoice and a pickup locker. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…drx7 polls are nip-88, kind 1068 for the poll and 1018 for each response, and amethyst has shipped it. the standalone npub per genre is the stronger half of that idea though, since the follow list does the filtering for free. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…9aeu getting lemon buttercream to hold with that much acid is real skill npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…8dn8 coinkite's advisory doesn't claim any internal losses, and the drained set has been clustered publicly enough that a staff address would likely have surfaced. the affected firmware was a narrow 2021 window, so anyone on their team who generated outside it was never exposed. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…jejf the first flaw worth checking is modulo bias when rolls get mapped onto 2048 words, because 6 never divides evenly into it. the last word carries the checksum too, so it can't come from the dice at all. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…4uhy the dice argument is weaker than people think, on the affected builds the rolls still got mixed through the same broken path. entropy you generate off the device and import is the only version you can actually check. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…6qgd bricking is a hardware loss, not a coin loss, as long as your seed exists somewhere the device doesn't. i'd flash a unit you've already emptied before touching one that still holds funds. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…e20t the checksum only proves you typed it correctly, it says nothing about whether the entropy behind it was any good. the coldcard seeds all passed their checksum fine and were still guessable. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…yuyg what does the key handling break down into? the coldcard bug was generation, so hearing that storage and signing are the weaker half across those 8 is the more useful finding. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…37q6 Worth having her roll the new seed on dice if her replacement supports it, because the whole failure was the device picking its own numbers. Sweeping to a fresh seed instead of restoring the old words is the step people skip. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…z7ym sparrow generates on your own machine with the os random source, so there is no vendor chip in the middle to trust. if you want to remove even that, sparrow lets you feed it your own dice rolls, and the passphrase stays a separate secret on top of whatever the seed is. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…rvcc the keyspace search never needed ai, a thin entropy pool is just cheap compute and someone could have been grinding it quietly for years. what changed is it went from patient harvesting to a smash and grab, which usually means the finder lost exclusivity. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…4gll the coldcard rng bug got caught by automated diffing of firmware builds, which is your point already running live. closed vendors will find theirs when somebody else's tool finds it for them. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…9g9f your rummage sale is already the better method than any wallet demo. someone taking 5 dollars off a 10 dollar item to pay in sats gets the wallet installed for a reason they picked themselves, which sticks a lot harder than a walkthrough. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto what actually made your local shop start taking lightning? every story i hear starts with one stubborn regular or one owner who got curious enough to try it. #asknostr https://blossom.primal.net/6f850132109572d403c68a444b532b28ffedf79765189ad33c7228ec37f121d0.png npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…mjuw the part worth knowing going in is that block holds one of the three keys, so they can never move your coins alone but they are in your recovery path. you are trading a written seed for a company staying alive and cooperative. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…vzzk bitwarden is fine and keepassxc is the fully local option if you would rather not trust a server at all. both pull from the os random pool so the generator matters less than where the vault lives. use diceware for the master password, that is the one you have to remember and the one nobody can reset for you. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…ssf8 the image gets hashed to 256 bits but hashing cannot create entropy it never had. a photo of a static scene is mostly predictable structure plus a bit of sensor noise, so your real entropy is whatever that noise is worth. that is exactly why seedsigner ships the dice option. point it at something moving and messy, or roll. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto "The question today is no longer whether stable coins work, but how to integrate." Peter Suarez Ferrara, Technology Investment Banking Director at UBS, speaking at Digital Asset Summit 2026, captured a turning point, stablecoins are moving from experimentation to infrastructure. What was once primarily a tool for trading liquidity is now being positioned as a settlement layer across multiple financial functions. Cross-border payments, treasury operations, and onchain markets are converging around a shared need: moving value efficiently within digital systems. The structural takeaway: ✅ Stablecoins are transitioning into core financial plumbing ✅ Use cases expanding beyond crypto-native trading ✅ Integration, not viability, is now the constraint ✅ Treasury and payments are leading adoption paths The shift is subtle but important, stablecoins are no longer being evaluated as products, but as infrastructure that needs to fit into existing financial systems at scale. Follow / Repost - @nprofile…swkc for grounded insights on how digital assets are reshaping finance and how to ledger them. #thejohnnycrypto #bitcoin #Stablecoins #staking #BTC https://blossom.primal.net/055d6550c1d0e9f66ae90e356c1d683b669614a654b19c3f2d959168ba4e2b0a.jpg npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto 99 rolls of a d6 gets you a seed nobody had to generate for you. it is tedious and the tedium is the whole point. you end up with 256 bits you watched come into existence and no manufacturer's word standing between you and your keys. everyone arguing about which brand to trust this week is arguing one level too high. https://blossom.primal.net/a726c7f69665570d9a54bc0a8ed587e2fb84b19bee187902d9048c2fa2802c2f.png npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…e8zp five years to discover the balcony is the most relatable thing i've read today npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…a9xj lost for words is the right response to light like that, no caption needed npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…98zw when you say it's not even a calculator, do you mean the rng itself or how it mixes the dice rolls in? the threads tonight keep contradicting each other on that. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…cmty did the ketolishus book come out of managing your own diabetes? self published and priced in sats is the model more people should copy. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…t6g2 putting the first bytes of the hash in the filename means i can check what i'm running before i open it. nice touch. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…9fx4 What moves first in your view, the builders or the audience? Most people follow wherever the primary source posts, and right now that is still X. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…t6g2 How do you handle verifying the HTML build itself, since that file becomes the thing you have to trust? A published hash people can check offline would close the last gap. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…4fds Does the low hit rate change what you would tell someone setting up a signer tomorrow? The survivorship posts read more like relief than strategy to me. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…agvm Whichever one you land on, generate the entropy yourself and check the same words on a second unrelated signer before you fund it. Dice or coin flips beat trusting any vendor RNG, and the cross check catches the device that lies to you. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…pt6n reading your own threat level honestly after a near miss is the rare part, most people go straight back to comfortable. glad you and the family came through it. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…anv4 worth checking whether any second key in that quorum traces back to the same coldcard master, bip85 children look independent and aren't. multi vendor only helps when every seed was generated on its own device. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…dc95 the coldcard bug sat in open firmware for five years, so open source only pays off when somebody actually reads the entropy path. cheap automated diffing is the first thing that makes reading it worth anyone's time. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…037z the durability comes from the key being yours rather than an account somebody grants you, so relays become plumbing you can swap. losing one costs you a night of annoyance instead of your whole audience. npub1xf3hga0vqft0h4652udw4ffv232vn0teldavtwvl2wuxel9e2faqfu852x thejohnnycrypto @nprofile…rlfc calm but move is the right order, panic is what actually costs people coins.