Last Notes
NVK is stepping down from the OpenSats board, effective immediately. OpenSats will continue to operate with an 8 person board until a replacement is made.
Yes, things fucking suck right now. Something that should've never happened has happened, and is still happening as I'm typing these lines. The consequence? Innocent, hard-working people are getting rekt. Life savings gone. No recourse, no undo button, no number to call. Just an empty balance and utter disbelief. Hard to think of something that's more devastating.
The draining of funds won't stop any time soon either. Yes, it's not a full systemic failure and things could always be worse, but a LOT of people have used and are still using coldcards. People are on holidays right now, or in hospitals, or on a different continent, having no access to the key material that's potentially compromised. Unable to sleep, unable to do much other than pray, panic, or drive to the next airport. If they know about the current catastrophe at all, that is.
I was barely able to sleep the last 3 nights. Not because I'm personally affected by said catastrophe (which I might be, I don't know yet, stepping into airplane tomorrow), but because I could've done more. I wrote about entropy and this particular failure mode in the past. I tried my best to educate people on randomness, and what a private key is, and how to use bitcoin without getting rekt. But I stopped, and a lot of the newer people are unaware of these issues and I feel like I failed them. As a bitcoiner, as an educator, and also as a regular person. As someone who has some technical understanding of how the various moving parts fit together. I've always felt a strong duty to educate others and help them understand, and I failed to fulfill that duty. I decided to stop writing and educating. I deeply regret that decision.
It's hard to overstate the damage done. To me, bitcoin has always been about the separation of money and state, or more precisely: the separation of money creation and man. If humanity has a way to print money it will always find reasons to print money, period. Gold was seen as the tears of the Gods since men can't make more of it. Without a natural money like gold, society collapses. Always, like clockwork. Bitcoin has civilizational-level importance because of this. It represents a return to a natural money that lies outside of human influence, corruption, and fallibility. A lot of bitcoiners understand this, either implicitly or explicitly, and thus every time bitcoin fails in big ways or small, their soul hurts.
It fucking sucks.
My hope is that bitcoin will be stronger for it in the end. "What doesn't kill you makes you stronger," is something my dad used to say often. I'm not sure if it's true for people, but I'm pretty sure that it's true for bitcoin.
We should all be more humble going forward, or at least I hope that we will be. And more kind, that would be good too.
If you have any capacity to reach out to people and help them get through this mess please do. People are scared, and confused, and panicked, and don't know what to do. A helping hand and a calm voice will go a long way.
And regarding the civilizational-level importance I've mentioned above: bitcoin will only be able to fulfill its promise if people hold their own keys. If that's not the case, bitcoin will just be another tool in the money printer's toolbox. That's why it all sucks so fucking much. A gaping wound in bitcoin's very soul, and the bleeding hasn't stopped yet.
⚡️ 40 sats to each person who comments on this post, follows me, and reposts this post. ❤️
- Commenting with an emoji is allowed.
- Maximum 200 comments.
https://blossom.primal.net/231b6bedb66c74d90f403a29c055324a410a7761ce3224112fb0b81d57adcf52.png
Looking back over my own statements about coldcard over the years and here I am in one telling a fellow Bitcoiner that coldcard is good for single sig. the very thing being exploited. While I did push multi vendor multisig often the fact that I occasionally touted coldcard as “the best” despite having no ability to audit this claim is unacceptable to me. I fell for the social proof of technical and respected friends using it and recommending it. I assumed someone was looking. Apparently no one was. I am sorry.
https://blossom.primal.net/e83df1e37741c89aad6de1fece7284a16a11f4fa793f591eb7e3601a298d5548.png
Ok, so what is our preferred wallet today?
URGENT: I’ve seen some people saying that they are on vacation and won’t be able to check their coldcard for days until they get back.
If you have one of the affected coldcards and can’t get back in time please call a trusted person, have them go to where your device is stored and walk them through the procedure to transfer funds over FaceTime.
Normally this would be horrible advice but under these circumstances I think it has the potential to save someone’s coins.
Attacks are increasing not decreasing and attackers are starting to crack through the affected mk3’s with pass phrases. There are even credible reports of mk4’s with pass phrases being hit.
If you are in this specific situation, throw the regular rules out the window and do what you must in order to save your coins. DONT WAIT.
if you’re in Europe or the UK and you don’t use Strike, why? what app do you use instead and why?
i don’t live there obviously and want to get to know these regions better and what we could be doing better.
please reply here, DMs are more difficult to track
Update: Boltz will stay disabled until further notice.
Our API remains available to process refunds cooperatively. In any case, unilateral refunds will work, as they do not depend on our infrastructure.
Our support team stays reachable.
To be clear: this is not a response to a single incident. Over the past months we have seen a steady rise in automated, AI-assisted probing of our infrastructure, and we have dealt with several exploits. Each was contained, but the pattern is clear: attackers now iterate faster than a team our size can find and patch. In the past few days alone we saw a drastic acceleration, and we do not believe this asymmetry will reverse. After reviewing the results of our own recent security scans, we cannot responsibly re-enable Boltz swaps, especially as we are being actively targeted by what appear to be multiple resourceful groups while we race to deploy fixes.
What we are seeing is a major paradigm shift for Bitcoin services operating on an open source stack, and it needs careful analysis. Do not expect swap services to resume shortly.
To be explicit: no user funds were ever at risk. Boltz is non-custodial by design. And as a fully bootstrapped company, the losses were ours alone.
We don't know yet how things will continue from here, but we'll keep you posted as soon as we have had the time to catch our breath and make a decision 🙏
#nevent1q…m3s3
Alright I got fucking like 6 hours of driving to do today to go collect my fucking hardware wallets because the fattest asshole larp in bitcoin psyoped me into a retarded multisig setup
Goodbye
No doubt ColdCard screwed up massively. Hopefully they open source their software and hardware so multiple vendors can improve on their software and hardware. I don't see any other way the project survives.
I'm gonna lose followers over this, but it really needs to be said. I'm sorry for those I've misled.
If you're into Creed, Pivot to Limp Bizkit https://blossom.primal.net/c705499522fd0952bc8897d7858c1f33d98c9478eb7e91dbf4f6ee660ffe7d61.gif
would it be weird if I shared my mini muffin recipe right now?
the situation with Coinkite and Coldcard is heartbreaking and angering. It's being talked about it by everyone.
but also, these muffins have no added sugar and is egg free cuz one of the kiddos has allergies. I've made it a few times and I'm kinda proud of it.
Nostr vibe check: people are calling me a "whore" because, as far as I can tell, I bought a defective product? Or maybe because I get paid for my work? This place man. I am this close to just never logging on again.
#nevent1q…xusv
After almost 48 straight exhausting hours helping members of our community in Paraguay as well as users around the world affected by this ColdCard attack I have learned that both MK3 & MK4 (could be others) devices are bricking at high rates due to the below factors:
1. Devices using a 9V battery and connecting using ColdPower via usb cable / if the battery is low the device will brick if it’s not getting enough power, and become unusable - the battery doesn’t have to be dead, just providing less than sufficient power apparently. If using a 9V battery don’t assume it’s got enough juice if it’s old - use a fresh one
2. Devices that are plugged in with the charger connected via an international plug adapter unit are experiencing high levels of bricking due to inconsistent connection provided by the cheap adapter units
3. KNOWN and reported already is that the firmware updates are bricking devices as well
This should be information we get out to as many plebs as possible. Many only have a single device to work with and these issues are making an already stressful situation a lot worse
God bless everyone affected and I hope this information helps somebody to avoid these issues 🙏🏼🫡
FYI @nprofile…ww9r @nprofile…j774 @npub1rxy…hnp8 @nprofile…ep0q
RHR 421: CATASTROPHIC COLDCARD BUG WITH @nprofile…cd8v AND @nprofile…l2yj
https://blossom.primal.net/eb374d9ce5cb234e5310ce46c2093fc6f588500688c6ae526786e128bd296db4.mp4
GM https://haven.dergigi.com/9e4da19b80feac45838fd7ca56c5da919af58e831b36047e9ea1ca7de60d0e4e.jpg
Three questions to ask about any hardware wallet
Most comparisons argue about chips. Three duller questions tell you more:
Does an outside firm test it, and can you read the report? Anyone can claim their device is secure. Paying researchers to attack it and then publishing what they found, including the unflattering parts, costs money and stings.
Do they pay for bugs? A bounty gives someone who finds a flaw a reason to report it rather than sell it, and gives skilled researchers a reason to go looking at all.
Can those researchers see the code? Closed firmware still gets attacked. Fuzzing over USB or QR is routine, and reverse engineering has got cheaper as models have got better at reading disassembly. Source code does not make an audit possible, it makes it cheaper, so more people attempt more of it. Open source beats source available too, because code under a real licence gets reused, and the developers reusing it (sometimes) read it.
All three
Passport publishes firmware under GPL and hardware under CERN-OHL-S v2, complete enough to build one from the files. Outside audits are online with the fixes. The bounty covers the device, though the amount is decided case by case.
Keystone also has all three, with the best evidence that its bounty works: outside researchers found a real firmware flaw and got paid. Audits from two firms, reproducible builds, schematics and secure element firmware published. One catch is theirs alone: researchers are asked not to disclose without written approval, with no time limit.
Two of three
Trezor publishes firmware and hardware and runs the best funded bounty, up to $100,000. No commissioned audit report, but the secure element in its newest device was tested externally and the flaw disclosed publicly.
Ledger pays well and its in house team does serious offensive work, including on rivals. Firmware and OS are closed, so every finding costs more effort. The chips are lab certified, but you only see the certificate.
Open and nothing else
Jade and Bitkey publish firmware, Bitkey with reproducible builds. No audits or bounties, so the code waits for volunteers. Sometimes they turn up: Jade's serious 2025 flaw was found and reported for free.
SeedSigner is as open as anything here and built from off the shelf parts, but there is no company; an audit or bounty was never on offer.
This measures how a company behaves, not how the device is built. Still, between two similar devices, take the one that publishes its code and pays people to break it.
Mais uma conquista nacional: por meio do nosso herói NVK o Brasil conseguiu finalmente destruir o Bitcoin.
Five hours of seat weaving later, and this is the finished #shakerchair - I made this one as a gift for a close friend who has always wanted a rocking chair. You can just make stuff. #make #woodwork
https://blossom.primal.net/7d5eb78f80c5e18fb7e37391db74add4ce88cea81cd94d00b423bc0bb06bdbd7.jpg
https://blossom.primal.net/4347066af572b87061a642d3a0231c7473cd8e4a39de161cfd4fd8b5cfe186b9.jpg
GM nostr 🤙🏼💜
Back in the fiat mines I sold software.
Traded ~60 hours/week of my time & energy for €300k–500k/year and drove “fancy” cars.
I spent maybe 7 minutes a day with my family.
Today I deliver homemade sourdough bread on a used motorbike on an island for sats.
Now I get to spend every day with the people I chose & love.
Bitcoin humbled me & helped me prioritize my valuable time over stuff.
Gave me back my time and energy and helped me become a better human being.
Thank you satoshi.
Blessed & grateful.
Timestamp of freedom 960828
https://blossom.primal.net/ac617aec2f4a0e5036f22f1dd6b56d0aabf02ef825a11874d2ace6d8a9e0776d.jpg
mood https://haven.dergigi.com/b36fb3fa6bd04c6e9d7d1b8832919b7ff17fc6432f7b33f44058a3cfff80622e.jpg
GM💫
https://i.nostr.build/rrlYwqnBPEh4U1Rr.jpg
https://npub1lrnvvs6z78s9yjqxxr38uyqkmn34lsaxznnqgd877j4z2qej3j5s09qnw5.blossom.band/6d4a1250c68d1745559bd261ef4b4be01375e1b1345776416186ea144ed1b63f.jpg
Users are reporting that Coldcard's emergency firmware update is bricking some devices.
These reports are anecdotal and have not been confirmed by Coinkite, but if you're planning to update, move your funds off the device first.
I remember listening to a podcast where Odell had NVK and the CEO of ledger debating each other about wallet security. It got a little heated. It was a really long time ago so forgive me if the details aren’t completely accurate. I remember the ceo of ledger arguing that they’ve been around long enough that they deserve more trust for not having any issues. Of course NVK was being his normal arrogant self.
But the one thing I can’t stop thinking about is actually what Odell said. This is a paraphrase but he said something along the lines of, if the code isn’t open source then I can’t verify it. The irony of such a statement from someone who couldn’t even verify the code from his own company.
If coldcard code was closed source, AI probably wouldn’t have been able to find the bug and exploit it. Wouldn’t that mean if ledger has a vulnerability, it would be harder for someone to find it? Does anyone know if more exploits happen on Apple vs Android products?
I’m still all about open source but it’s not the end all for me like it used to be.
GM. Well... that escalated quickly.
Zap Zide #Nostr #bitcoin #GM #nostrich #zapzide
https://blossom.primal.net/6bccb28be5bee11e563c647d61a0cc3bcfb6108af6a559dc53f8bd45e4fbbb26.jpg
‼️ If someone felt threatened by Bitcoin dominance and self-custody, what would they attack?
Not Bitcoin’s code.
Your confidence in your ability to hold it.
They would amplify every failure.
Turn every hardware-wallet bug into an indictment of self-custody.
Make sovereignty feel reckless and dependence feel responsible.
The recent Coldcard situation is serious. Some people have lost funds because vulnerable wallets were created. That demands accountability, investigation, and better security, NOT a retreat into custodianship.
A defective tool does not invalidate the principle.
#Bitcoin has not failed.
Proper self-custody has not failed.
Blind trust in any single device or vendor has.
Verify your entropy. Test your recovery. Reduce single points of failure.
Fear will drive many back into the cage.
Let it drive you toward better self-custody instead.
The alternative is still dependence.
Choose carefully.
I'm not educated enough to make a statement but I will anyway.
I feel like this is some insider shit. Someone there knew and is part of this.
#nevent1q…6cjw
Is The Coldcard Disaster A State-Level Attack?
https://blossom.primal.net/890dc62f7cf3ac6ec5774b0afb0a5fde74cbfcdf0192d95684015d6bfea2ce3f.mp4
These last few days have been rough. Many of our brothers and sisters have been wounded emotionally and psychologically. Sadly, it wouldn't surprise me if some have considered drastic actions after watching what they believed was the value of their lives stolen from them. We've taken a major hit, and it's still sadly unfolding.
If you're reading this and you're on the edge, my DMs are open. I'm sorry for what you're going through, and we'll get through this together.
This bear market has been brutal. Adam Back is facing questions over his connection to Jeffrey Epstein. Jack Mallers got in bed with Howard Lutnick. Michael Saylor continues pushing fiat digital credit bullshit. NVK's hubris cost plebs thousands of coins. Core is gay and can't be trusted. BIP-110 proponents continuously spam everyone's comments. ETFs continue centralizing Bitcoin ownership. It's one thing after another, with attacks seemingly coming from every direction.
As angry as I am with the people who have caused so much grief in this community, I'm not a ruthless person. I never have been. What matters most to me, in this moment, is how they choose to act from this point forward, as it will reveal a lot about who they are.
I was deeply disappointed by Jack Mallers' interview with Danni on What Bitcoin Did. His unwillingness to clearly explain anything only increased my distrust. Adam Back, as far as I know, still hasn't publicly addressed the Epstein allegations in detail. Until then, ge cannot be trusted in any way. What NVK, Odell, and the rest of the OpenSats leadership do next will tell us far more about who they are underneath, than the events themselves.
We all make mistakes. Some are bigger than others. But what we do after those mistakes reveals our character far more than the mistakes themselves.
The money printer is powerful. So powerful that its gravity pulls on all of us. I know it pulls on me. I fight it constantly, and sometimes I slip. I've shitcoined into MSTR like many others, trying to play fiat games in the past.
I just hope that, in the end, my efforts are enough to help Bitcoin throw the money printer into Mordor's fires of Mount Doom.
NVK and the rest of the crew have a choice. They can be like Gollum, consumed by the thing they refuse to let go of, or like Boromir, flawed but ultimately willing to do the right thing when it mattered most.
The win condition was never a seat at the big fiat table.
The win condition is the death of the money printer.
#2sats
⚡️🤖 NEW - This is insane
Claude code found the COLDCARD wallet vulnerability with a single prompt, in just 8 minutes of thinking
we're not ready for what's coming
https://blossom.primal.net/1902088a193e3fd88537b193f1c7e08f352c02b92fa0965c2ef98e38643542eb.jpg
Coldcard only! This is for Coldcards only!
Simple passphrases on top of the shitty entropy now getting savaged.
https://blossom.ditto.pub/4570f5b58d1055dcea3cb78c05e47b486442e58af86b8b61bb620d70ce25b39d.png
There is a strange and unsettling irony in the fact that bitcoiners want ordinary, hardworking people to “roll the dice” to secure their wealth.
Money has to be dead simple to store and use, allowing people to get on with the parts of their lives that their money is supposed to enable. Coldcard users rested in the assurance that their wallets did just that. It wasn’t a dice roll. It was a solid and secure solution to the problem of holding their money so they could go about day to day life. We all know now it was a false assurance.
The result of this catastrophe is that ordinary, hardworking people who had started to hear about and see firsthand the benefits of bitcoin and self-custody will now be so unsure about who to believe that many will give up on self-custody, if not bitcoin entirely. This won’t be just Coldcard users, but users of any self-custody solution. If you can’t trust the people who are supposed to know these things, then why believe anyone? People just want to get on with their lives, and right now bitcoin isn’t allowing them to do that the way it was promised by those “in the know.”
FFS
https://blossom.primal.net/948c12ecba19f5cbe02500e32aa6cdb61a160de33a1528ea76c3ef0e7be9e370.jpg
Clowns on X Spaces: Bitcoin Self Custody has failed.
Me: no, one company failed and a lot of fuck ups happened, but that doesn't change the mission.
Self custody is hard.
If it wasn't hard, we wouldn't have invented banks.
And we know the problem with banks...
We spent the last year panicking about quantum computers with 100,000 qubits breaking SHA-256 in 2035… only to get wiped out in 2026 by a C macro that forgot to roll the fucking dice.
Nostr is terrible as a transport mechanism.
Nostr is amazing as an identity system.
gm
i had a older friend that i recommended a coldcard to in 2021 he bought a mk3 and i helped him set it up (he was not technical at all) and sent his coins off coinbase then we didn’t talk about bitcoin much at all until the beginning on this year he told me he bought a bitkey. he wanted me to help him moves his coins over from the mk3 we didn’t get around to do it until last month. we moved everything off the coldcard and into the bitkey its crazy how things happen.
he has no idea this is going on
shoutout to @nprofile…dt9r it was extremely easy to help him understand how to use it
he was basically in a forced hodl with the mk3 without me helping looking back i shouldn’t even told him to take self custody
lessons learned
his bitcoin would have been 100% gone if he didn’t see a bitkey ad somewhere
If you’re a true Bitcoin maximalist, spend $100 of your stash to study Bitcoin’s competition
Buy some Zcash, try shielded pools & spend it via NEAR Intents
Buy some Monero, mine sone with your CPU, learn how the subaddress system works & buy something on XMR Bazaar
Buy some Ethereum, try Uniswap & create your first contract
Buy some Litecoin, try MWEB and then spend it at a merchant
Buy some Decred, see why their implementation of Lightning is more stable
Buy some Bitcoin Cash, play with CashFusion, CashTokens & see what you can do with the covenants
If you’re a true maximalist, you must think in terms of maximizing: bringing all the popular use cases to the network in which you are emotionally and financially most invested
Learn from other projects, then try to figure out how it can work on Bitcoin
You don’t need to buy more than $10 of each coin, consider this your education budget
Once you learn more, you will become a more valuable community member in Bitcoin. Not a cheerleader, but someone who can compare and think for himself.
Good morning nostr, today will be a busy one, with lots of outdoor chores. I still have some things to straighten up on my btc setup stuff too. But i'm happy to be on nostr, since i'm just a non-techy trying to muddle thru the chaos. But my coffee is good and i'll be listening to some Vivaldi on my walk this morning. Yall have a great monday, enjoy your coffee, and do your work with a happy heart. #coffeechain https://npub13kwjkaunpmj5aslyd7hhwnwaqswmknj25dddglqztzz29pkavhaq25wg2a.blossom.band/e3f1b00c8d676b611a757125ea450edf9a26c05c3e7928f19341f8c43b9bfcd9.jpg
Apart from Coldcard and SeedSigner, what airgapped Bitcoin signing devices that use PSBT and BIP-39 do not require a phone home setup?
Ledger - closed source not available, phone home
Passport Prime - open source mostly available phone home
BitKey - phone home, non standard
Trezor ??
BitBox ??
GM
https://blossom.primal.net/8e055f26815920b92a940adf0f2a412fc8cc94572998e3cd4b93731b0b980f04.jpg
GM☕
When you make fun of BIP-110, remember you are making fun of the Bitcoin you used to support.
https://blossom.primal.net/91218285ece53c5cd43c7a7f4d3e40ac2846c8df4bcfb08506c9a3503a531d3b.png
GM #nostr
The only #hardware wallet never trusted to generate its own entropy.
#frostsnap @npub1fr0…l2sa
AVAILABLE at @nprofile…04l8
KYC free
#einundzwanzig #bitcoin
https://blossom.primal.net/3da8372bfea35aa49ad923735f1bf4374c7fc934e1e5581fcdb13723a0cf7bda.jpg
Is amethyst junk or nostr abandonware?
https://i.nostr.build/v7OBfYKLLkpv9y7C.jpg
wave 4 attack happening right now reported by galaxy research. dashboard updated. https://coldcard-hack-tracker.vercel.app/
https://blossom.primal.net/116ba2e453be0b4eb9d2bfecd0f6e71d383ebec7ebd8ba0bcc05e147ab90d702.png
⚡️💬 END OF DAY - Do you think the Coldcard hacker is on Nostr?
https://blossom.primal.net/66396966b5576bb02d5c85078bcc71ab1d4c572f5a07b17568c2f44036e24555.mp4