Last Notes
Most normal people prefer to outsource security anyway. That's why banks exist. Self custody is for control-freak weirdos only. Always will be.
I'm zooming in on the 40MB RAW file, I can see their hairs have split ends.
They need good shampoo 😂
This whole thing completely sank the self-custody ship.
#nevent1q…tqvt
Normal people aren’t going to roll a dice. They’re just going to store their bitcoin on exchange from this point forward.
No one can be sure it will not happen..
Posted a note about this more than a year ago.. ii was already smelling this kind of FUD
https://media1.tenor.com/m/_90ngLQufGIAAAAC/sheeeeiiittt.gif
Over 1K now
https://npub1lrnvvs6z78s9yjqxxr38uyqkmn34lsaxznnqgd877j4z2qej3j5s09qnw5.blossom.band/e98967c09af4a65e1831b0f7ecf0012d5ff68eb0297fee380cce8fbfabce2239.jpg
I call this one:
"3 bees on a sunflower":
https://i.nostr.build/aB7fM5VM4sNxwFiE.jpg
https://media1.tenor.com/m/G9lyfGiunzIAAAAC/tea-spill-the-tea.gif
https://media1.tenor.com/m/LLu6EdwJk3sAAAAC/big-oof-size.gif
Nah, I think it is the opposite to all of our shortcuts and attempts to put security second to convenience.
Cryptography is sound and the source entropy was always its achilles heel. Cyprography always advertised that it is only ever as good as the entropy you give it.
High concentration gives you a similar risk level, regardless of the asset. It's unreasonable to expect normal users to become cryptographers. Better to expect them to diversify wallets. Best to diversify wallets _and_ assets.
And invest in the people around you. Surround yourself with people who would continue to care about you, even if you were broke. They remain your best insurance against all risk and **we have no idea what man-made horrors are fast approaching us**. This was just the warning shot.
A very late GM
If I'm boring you with bee shots, do let me know 😂
#Photography
https://i.nostr.build/iu4Zwc7PcEH5pygr.jpg
https://npub1832epq8kgur55cuwnnrdf3y85p4l4wqsgq42hxn8jna5ngznz5lq2law2l.blossom.band/5926a0d01d0a7a7e3049874046e70a79af8d69ba1b4a2659d23b50f2d4cff4ce.mp4
#nevent1q…nmce
Over 1K BTC now
https://npub1lrnvvs6z78s9yjqxxr38uyqkmn34lsaxznnqgd877j4z2qej3j5s09qnw5.blossom.band/e98967c09af4a65e1831b0f7ecf0012d5ff68eb0297fee380cce8fbfabce2239.jpg
On a positive note: you don't have to charter a yacht for that boating accident to be plausible now.
I was satisfied with the way their docs bragged about using hardware tRNG and two separate secure element chips but it turns out the hardware tRNG wasn't even being utilized. This is very bad and the only reason I'm not a victim of this attack is pure luck that it didn't happen before I moved my funds end of 2024. This RNG fallback flaw is something that should have been caught in review and never made it to production. The fact that they didn't even know that their devices were doing this is a deathblow to this company's reputation.
always love some good news, especially on days when all the news seems bad!
congrats!
I saw some of your stack was swept. Sorry to hear it brother.
Yes the shilled 'gold standard' of single sig self custody being exploited really is a devestating hit for self custody.
July 31st
YOUR CAREER IS NOT A LIFE SENTENCE
“How disgraceful is the lawyer whose dying breath passes while at court, at an advanced age, pleading for unknown litigants and still seeking the approval of ignorant spectators.”
—SENECA, ON THE BREVITY OF LIFE, 20.2
#DailyStoic
Nah, Blocktron is way cooler.
What about OpenDimes…are they safe?
Nah, they know what it will be worth.
Hard not to roll your eyes at all the pictures like this that have been posted over the years. They didn’t need to break into homes, take people hostage, threaten anyone with violence. They did it much more efficiently and quietly, right out from under everyone’s noses. There was absolutely no defense against that. https://onlydans.blossom.band/f93fabfc061020fa8d3d56eb295f66f8e0c3ea651e870ef1c1e11673d70b622a.png
I was taken in by the Coldcard sales pitch. Operated on the assumption that my funds were as secure as they could be by remote signing with my CC and broadcasting with Sparrow on my own node. The only reason why I'm not a victim of this attack is pure luck that it didn't happen sooner. When Bitcoin hit 100k, I decided to start cashing out a whole coin and moved my CC funds to a hot wallet and started selling a million sats per day.
NVK said cold card was super duper secure!
That’s the worst part about this I think.
https://npub1lrnvvs6z78s9yjqxxr38uyqkmn34lsaxznnqgd877j4z2qej3j5s09qnw5.blossom.band/90dbc4e72a12cfd863e75229b13eec291aaa38d9d1878950e8a4eed49419ca13.jpg
i have more trust in the opinion if you don't shill your reference code for the product you are referencing.
is it just me?
Likely to see a lot of this for the next while
Normies that “did their research” just got rekt.
GM
I heard Ashy Larry was not using a coldcard 😂
Psycho way is the best way.. maybe the only one.
Yeah I completely agree with you.
To not create heroes is better and wiser than to slay them along the way..
This is true until robots turn autonomous and start rug-pulling us with code they generated.
If you’re in need of a #SeedSigner, @npub10px…mwhg has enclosures, self-assembly kits, and complete builds.
#note1w8r…5lq8
Learning the hard way was always the way to learn more and deeply.. sad but true.
Yeap.. when I started my journey I understood that was a point where or you "trust" or you study and learn as much to verify and or secure yourself.
My heart goes out to everyone affected by the Coldcard hack. 🧡🙏
I will be taking some time in the coming days to review my setup. Here are some links I’ve come across in the last 21 hours that I think might be helpful. Please leave a comment if you have any others.
https://seedsigner.com/seedsigner-independent-custody-guide
https://github.com/bitcoin/bips/blob/master/bip-0039/bip-0039-wordlists.md
https://darth-coin.github.io/wallets/tails-hodl-cold-wallet-en.html
https://bitbox.swiss/bitbox02/BitBox_Diceware_HowTo.pdf
Savaged by the same bitcoiners who told people coldcard was the safest hardware wallet? Lol
Check with @npub10px…mwhg 🧡🙏
https://www.takemysats.com/zalgebar-media
If AI breached this, then the court will ask why they weren't using AI to audit this, themselves. Every software or firmware maker, going forward, will be expected to conduct regular 3rd-party human and AI audits.
Just publishing code doesn't mean the code has been properly and regularly audited. Most open source code is unaudited. They just vomit it up onto GitHub and call it a day. That is actually _less secure_ than keeping the code closed source, as it makes it easier to find potential exploits or to distribute fake clones that phish for keys.
didnt realize each deck had individual art on the backside. super fire!