Last Notes
I need a waterproof notepad to record my shower thoughts upon because I often forget them by the time I get back to a computer.
https://blossom.smartflow.social/37140e7e3aba9fccf78f3755c8eedff12f00fde5114f19a76e9754f86d3f4ec3.jpg
🚧 MEME CHECKPOINT 🚧
Drop the last meme in your gallery.
No context. No excuses. No moral compass.
Best memes get zapped ⚡
Powered by @npub1ckq…vlh0
https://smartflow.social
#MemeCheckpoint
I may or may not have just used AI to generate a picture of me pooing the bed and sending it to a girl I'm dating... We'll see how she responds #grownostr
https://blossom.primal.net/88530313584692fda6c756fad862b228861e66a9d5385097553101180e78760b.jpg
Catchy domain name ideas that pass the registry check. Clever only counts if it's available.
https://domainsearchking.com/catchy-domain-name-ideas
https://domainsearchking.com/images/catchy-domain-name-ideas-hero.png
**Security Update**
ZEUS infrastructure is temporarily offline following a cybersecurity incident that occurred within the last few hours.
The attack has been mitigated. Out of an abundance of caution, we are keeping services offline while we conduct a comprehensive audit of all systems before restoring operations.
**No customer funds were lost. No customer funds are at risk.**
Customers whose LSP channels were closed will receive replace channels as soon as service is restored and we're able to process requests.
Based on our investigation so far, we believe this incident was limited to ZEUS infrastructure. We have no evidence that it resulted from a vulnerability in Lightning node software.
This incident reinforces the importance of work we've already been doing to harden our infrastructure using trusted execution environments (enclaves) and the Validating Lightning Signer project. Our upcoming architecture is designed to mitigate this class of attack.
We appreciate your patience and will continue to provide updates as our investigation progresses.
If your LSP channel was closed, please contact us using the support email listed under the **Help** menu in the ZEUS mobile wallet. Please allow additional time for responses while we work through support requests.
Thank you.
people are unplugging their Blockclocks out of an abundance of caution. i probably would too. i wanted one, but couldn't bring myself to spend the sats.
wtf is going on???!
https://blossom.primal.net/8194459fbc39fe8ea09f3d27546c45a8986575171187ec082f975c6e6cd69834.jpg
Domain for your app — short enough for the URL bar, free enough to ship this week.
https://domainsearchking.com/domain-name-for-app
https://domainsearchking.com/images/og-default.png
If you are the hacker you should be terrified. Now and for the rest of your life. You have no idea the type of people you fucked with. Fair warning. Turn yourself in immediately and surrender all funds.
https://blossom.primal.net/054c3bc69b624ed976b7330b1688002f95986efd6f2a0d16168d8db0fe580304.jpg
Any sound money loving females interested in being on a podcast?
Tag anyone who might be 👇
LLC name generator + matching domains. Entity-ready names that aren't already gone.
https://domainsearchking.com/llc-name-generator
https://domainsearchking.com/images/og-default.png
Nobody is sleeping.
On survivor's guilt, freeze states and getting your head back after the Coldcard entropy bug.
I've been talking to everyone in bitcoin the past 6 days and i keep having the same conversation. Flat, wired, running on three hours of sleep. Our people are rekt, even those of us who weren't explicitly rekt by the exploit.
This wasn't just a bug, it was a belief-system failure. (claude came up with this line, but fuck is it true)
Psychologists call what just happened "shattered assumptions" the world is basically predictable, effort gets rewarded and if i do the right things i'll be ok.
Our version was something like self custody done while following guides from educators in the space is safe. Cold storage. Air-gapped bitcoin is safe and if that's my setup then i can rest easily at night even as the fiat world burns around me.
This entropy bug completely inverted that assumption and turned a lot of our world's upside down over night. The people hit the hardest weren't degen leverage traders. They were the careful ones. The prudent ones. The ones who did everything right. The ones who did the homework. Bought the "right" devices. Followed the guides.
In the past few days i have been in contact with many of those affected. Their stories are heart breaking. These are the best kind of people. Honest, decent, moral, hard working family people. Saving for retirement, or for their children. After talking to them all day Saturday in DM's and on audio spaces i sat alone in my office and cried. I haven't really cried like that since my father died.
When good people's prudence and conscientiousness gets punished your brain's entire model of "how to be safe" throws an error. That error is what we are feeling right now.
The Five Rooms (This next section written by Claude)
"Survivor's guilt" is the phrase going around, and it's real — but it's one room in a house with five. Figure out which room you're in, because they need different things.
1. You lost funds. You're grieving. Yes, grieving — grief isn't reserved for death, it's the response to any major loss, and years of savings qualifies. Layered on top: shame and self-blame. I should have used multisig. I should have known. More on that below, because most of that self-blame doesn't survive contact with logic.
2. You dodged it. Wrong device, right quorum, moved coins in time, pure luck. This is survivor's guilt proper: the ugly whiplash between thank God and why them and not me. Relief that feels obscene. It isn't. Relief and compassion run on separate circuits — feeling one doesn't cancel the other.
3. You recommended the thing. The guilt of having pointed people toward the blast radius. What I'll add here: guilt and shame are different animals. Guilt says I did something wrong, and it's useful exactly once — as fuel for repair. Shame says I am something wrong, and it's useful pretty much never. It makes you hide, and hiding is how all of this gets worse.
4. You haven't checked yet. You know the wallet is there. You haven't opened it. Every day you don't, it gets heavier. That's not laziness or cowardice — that's freeze. Keep reading.
5. You're just watching. Nothing at stake, can't look away, feel insane for being this rekt by it. You're not insane. Researchers studying the Boston Marathon bombing found that people who consumed hours of coverage a day showed more acute stress symptoms than some people who were physically there. The feed is a re-exposure machine, and you've been running laps through other people's worst day for a week straight.
Fight, Flight and Freeze
Fight could look like: Double and triple checking everything, Glued to the screen for minute by minute updates. Hunting for more bugs like the bitcoin red team guys. Literally fighting on X or Nostr. I personally am in fight mode right now. Though i don't know who or what to fight so it's essentially a lot of wasted energy if i'm being honest.
Flight could look like: "i'm selling everything". "i'm done with self custody". "i'm done with all of this". "fuck this shit who needs this in their life". it's an urge to just get away from everything related to bitcoin once and for all. I have many friends in flight currently. Some even panic selling their bitcoin. While i don't believe that is the optimal strategy it's hard to blame them and i would never pass judgement on people stuck in flight.
Freeze could look like: Not checking the wallet. Not making plans to have someone else get to it if on vacation. Lying awake neither restful or in a state of action. If you are stuck in a state of freeze and you know there's something you need to check or do... please go check. Will yourself into action. Tell a trusted person and enlist them to help.
These are psychological states, not character flaws.
How to unstick yourself (written by Claude)
The unstuck protocol
1. Sleep before decisions. Non-negotiable. A week of broken sleep measurably degrades judgment and emotional control. And this week, degraded judgment is the attack surface: the phishing wave is already here — fake security updates, fake migration tools, urgency everywhere. Panic is what they're farming. If a message makes your chest tight and demands action now, that's the tell. No irreversible moves — no migrations, no seed ceremonies, no market decisions — on no sleep. The coins can wait twelve more hours. Mistakes can't be unmade.
2. If you're frozen, borrow a nervous system. Can't face checking your exposure? Do it with someone on the phone. Pick a time, pick a person, do it together, then stop. Bounded, witnessed action breaks freeze better than willpower ever will.
3. Ration the feed. You already know everything you need to know today. Check twice a day at set times. Doomscrolling isn't vigilance — it's re-exposure wearing vigilance's costume.
4. Audit the self-blame. Poker players call it resulting: judging a decision by its outcome instead of by what you knew when you made it. "I should have known" — should you? Did anyone? You made a reasonable call with the information available, the same call thousands of careful people made. Bad outcome, defensible decision. You don't get graded on information you didn't have.
5. Convert guilt into repair, then put it down. Help one person migrate safely. Boost accurate information. Warn people about the scams. Then stop. Guilt that doesn't convert into action just becomes acid.
6. Say the real thing to one human. Here's Bitcoin's cruelest catch-22: the opsec that protects your coins isolates your grief. You can't tell your coworkers. Maybe you haven't told your spouse. The normies would just laugh — magic internet money, told you so. Psychologists call this disenfranchised grief — loss you're not allowed to mourn in public — and it's exactly why this community has to be its own support network. Nobody else can be. Find one person you can tell the truth to, even if the truth is just "I'm not okay." Unwitnessed grief doesn't process. It just sits there.
When it's more than a rough week
All of the bitcoiners i know affected by this are very stoic, extreme personal responsibility types. These are the type of men and women who take on the weight of the world and i am proud to know them, but... If two weeks from july 29th you still can't sleep, can't feel anything, or the thoughts are getting dark that's past the do-it-yourself line.
There is no shame in getting help. There is no shame in putting down the weight of the world and asking others to carry it with you. Financial trauma therapists exist. This is literally their job. And if tonight, or tomorrow gets genuinely dark and you don't see a way out please call someone now and not later. The protcol survived. Make sure you do too.
If you need a helping hand call or text the crisis line at 988 in the U.S. and talk to someone who can help or look up the number in your country.
Check on your bitcoin friends
The loudest people this week are not the ones i am worried about, it's the people who have gone silent. Send the DM "You Good bro?" It costs nothing. We have a moral duty and obligation to reach out to everyone we can.
We are going to survive
I'm known for being an optimistic character around the bitcoin community and that hasn't changed, but the weight of this tragedy has hit me hard. The story of bitcoin in my mind is the story of the little guy, the person who the system is rigged against finally being able to protect themselves against that system. When a billionaire loses 10 billion or makes 20 does it really matter?
But when a family was able to save 100k and it is ripped away from them through no fault of their own? It is simply too much. Bitcoin will survive, self custody will survive. Let's make sure me, you all our fellow bitcoiners do too.
Get some sleep.
https://image.nostr.build/c44aad59079c6ed060ed2e3262ecc066134f9862f4359ff6c6edf3c3e60616a5.jpg
I don't have any reason to believe given the data available that @nprofile…qy52 or @nprofile…zslp had anything to do with the #Coldcard heist.
This post, if anything, merely reveals that NVK might have had a Freudian slip when telling Odel that the 4.0.0 release was compromised in such a way that he could "steal all your Bitcoin" even without physical access to everyone's coldcards.
In other words, the suspicion that NVK knew about Peter's exploit increases.
Odell and Marty recommended Coldcard for years, in bad judgment, and have owned up to that.
#nevent1q…2le5
Protonmail let me pay with on-chain Bitcoin. 💪
We are so back.
What Could Happen This Saturday (BIP-110)
https://blossom.primal.net/6eb9810ea6174377a3db4da9110db60805233978edadc39d28e841daa2348d25.mp4
How are people surviving without assets? Doesn't seem possible
Matt Odell and Marty Bent discuss #Coldcard's 4.0.0 firmware shortly after it's release.
This release is now known to have distributed the vulnerability Coinkite CTO authored under an alias that later lead to the theft of $100m+ of #Bitcoin in July/August 2026.
The following clip is taken from their podcast titled "Rabbit Hole Recap: Bitcoin Week of 2021.03.29" from timestamp 1:25:09 to 1:26:21.
https://blossom.primal.net/271051978aba0b245b00969667517d62bf978cf5ef083f69967e48a8f0807896.mp4
Good morning to everyone in the world, including the taliban and north Korea, but definitely not gm to nvk
I find my feed is better if I immediately mute anyone who posts AI slop.
GM.
🚨 For everyone who doesn’t understand this, it means that Boltz’ DEADMAN SWITCH FLIPPED.
#nevent1q…hysy
Remember to touch grass from time to time and be kind to yourself. It's almost impossible to process the flurry of information. Remember to eat and sleep and stay hydrated. Yes things are fucked, but don't fuck yourself up in the process too.
Perplexity domain name ideas? Cool list. Verify first — registry truth > model confidence.
https://domainsearchking.com/perplexity-domain-names
https://domainsearchking.com/images/og-default.png
As a response to the ongoing Coldcard hack and other AI-related issues going on, I've decided to make Defending Bitcoin available entirely for free on https://
defendingbitcoin.com/reader
It was always in the plan to create a sort of "reader companion", and I'll be adding more features to cross-link the contents of the book with useful information on how to improve your Bitcoin security. But, for now, the entire text of Defending Bitcoin is readable from your browser.
AND we've finally added it to the Bitcoin Infinity Store at https://
bitcoininfinitystore.com, along with Max Hillebrand's Praxeology of Privacy (also freely available on Max's website). If you want to support either of us, you can now do so with Bitcoin.
I also plan to update the chapter on AI Risks. I honestly hadn't anticipated quite how brutally AI attacks would hit, and, like most others, I certainly didn't expect one of the most widely-recommended hardware wallet manufacturers had simply neglected to implement such a fundamental feature as secure seed generation. In hindsight, I should have emphasized the risk of AI attack capabilities more strongly.
I hope Defending Bitcoin can be useful to anyone looking to improve their Bitcoin security. Let me know what you think, and stay secure out there.
Gm the Coinkite CTO authored the Coldcard vulnerability under an alias then merged it into the Coldcard repo as the CTO. ☕
GM ☀️☕
On day two of my current series of prayers and meditations I came across this and I think it's beautiful and worth sharing:
"Above all else, guard your heart,
for everything you do flows from it."
Proverbs, 4:23
Why GPT keeps suggesting taken domains — and how to verify before you fall in love with a name.
https://domainsearchking.com/gpt-suggests-taken-domains
https://domainsearchking.com/images/og-default.png
ColdCard was an inside job.
💸 Tip Giveaways 💸
Comment only! No post required. Write 3-4 lines at least but original please!
Suppose you are travelling in a train
Sitting on a reserved seat!
A old man around 65 years old standing beside your seat, a pregnant lady also standing in front of your seat and a guy with one leg standing next to the old man.
Now question is, whom you’ll offer to be seated on your seat? Why? Feel free to answer because there is no right or wrong answer. Just let me know your heart or thought.
Original and honest answer only, no Ai answer will be rewarded.
1st 10 participants will get 0.05 tip in their comment.
Rest of the participants will get consolation prize tip like 0.01 or 0.02.
Deadline 24 hours
Good luck! ✌️
Sponsored by @npub15zv…f2w4
Thanks for the tipping on my project 💚
https://npub1mdjda6p4j6mu2cufj5pjms5z96v6vee7cw543fd3pys6h8uc80lqvadt6r.blossom.band/fe6f3465076adc233e1ff89db74c84c0cfc0a7d47d03c4f98a81f649a64f391a.png
https://blossom.primal.net/9d99658189d0e6530e6fe5a6990492e56862e706bd3162af2abd815239cf75e9.jpg
⚡️🚨 NEW - The U.S. stock market (S&P 500) is now at its most overvalued level in history, overtaking the 2008 peak.
https://blossom.primal.net/b687cc0be7fb76dfe5625e097065c1bced28b0dba0c72546dda49bd1dca5fa42.jpg
Namecheap vs GoDaddy for domains — practical comparison, soft pricing language, verify the cart.
https://domainsearchking.com/namecheap-vs-godaddy-domains
https://domainsearchking.com/images/og-default.png
GM https://haven.dergigi.com/d702b7666aaaa0f39698419cb68ebbd87b1a09cc99b0d8eca0f24088ecfe6db1.jpg
Good morning!
https://blossom.primal.net/27b6587ed3ee3b29a408de35b8fa069ef806b18d93fc647b0e2107f161feb84e.jpg
Have you ever felt surrounded by people, but yet completely alone?
AI startup domain names that are still available — verified, not hallucinated.
https://domainsearchking.com/ai-startup-domain-names
https://domainsearchking.com/images/og-default.png
GM. WANTED: "40 Bits."
Zap Zide #Nostr #bitcoin #GM #nostrich #zapzide
https://blossom.primal.net/6687ff5c5448fc93fe82e218b1b7577938c5751fe851ba65ff4a4b25b1904425.jpg
GM👑
https://i.nostr.build/qog55rNLgc5Hc2Se.jpg
DECENTRALIZE EVERYTHING 🪢 run bip110
https://wavlake.com/track/f902882e-a623-44bf-8ed0-d052478f818c
https://blossom.primal.net/071c51569276978dbecffffaee690c8cb8155a643a75edec0eed290b28fa3d9d.mov
Got a brand name? Map it to a domain that actually exists. Brand → domain without the guesswork.
https://domainsearchking.com/brand-name-to-domain
https://domainsearchking.com/images/og-default.png
murder mysteries, dating sims, escape rooms — AI that remembers the plot.
https://chatbrat.ai/games
https://chatbrat.ai/og-chatbrat.jpg
NVK knew in 2021. He told Matt Odell.
https://npub1ak68qfcjj7k95c0jwleu69x72nr8adwv6g80pkwl9xlps6zmkqzqrxy8fx.blossom.band/200f65747d4b50e01a6e912a628e2c1da49fc4a45c5bfdccc2cb4fef783e8776.mp4
drop into a scenario and go — scenes ready, characters that push back.
https://chatbrat.ai/scenarios
https://chatbrat.ai/og-chatbrat.jpg
the character IS the experience. personality that holds past message 40.
https://chatbrat.ai/characters
https://chatbrat.ai/og-chatbrat.jpg
looking for a Character.AI replacement in 2026? character-first chat without the mid-scene filter slap.
https://chatbrat.ai/bratlog/character-ai-replacement-app-2026
https://chatbrat.ai/bratlog/character-ai-replacement-app-2026-hero.jpg
Character.AI vs Replika — different products. if you want anime arcs + custom chars, start here.
https://chatbrat.ai/bratlog/character-ai-vs-replika
https://chatbrat.ai/bratlog/character-ai-vs-replika-hero.jpg
best AI anime girlfriend apps 2026 — who actually stays in character without melting mid-scene.
https://chatbrat.ai/bratlog/best-ai-anime-girlfriend-apps-2026
https://chatbrat.ai/bratlog/best-ai-anime-girlfriend-apps-2026-hero.jpg
husbando AI shortlist 2026 — anime boyfriend chatbots that hold the arc.
https://chatbrat.ai/bratlog/husbando-ai-best-anime-boyfriend-chatbots-2026
https://chatbrat.ai/bratlog/husbando-ai-best-anime-boyfriend-chatbots-2026-hero.jpg
free Replika alternative angle — companions that remember lore without the soft-reset feel.
https://chatbrat.ai/bratlog/replika-alternative-free
https://chatbrat.ai/bratlog/replika-alternative-free-hero.jpg
Talkie vs PolyBuzz vs SillyTavern vs ChatBrat — honest stack compare for AI roleplay.
https://chatbrat.ai/bratlog/talkie-vs-polybuzz-vs-sillytavern-vs-chatbrat
https://chatbrat.ai/bratlog/talkie-vs-polybuzz-vs-sillytavern-vs-chatbrat-hero.jpg
custom AI character creator — looks, voice, lore, boundaries. then actually talk to them.
https://chatbrat.ai/bratlog/custom-ai-character-creator
https://chatbrat.ai/bratlog/custom-ai-character-creator-hero.jpg
ai language tutor app roleplay — new bratlog on chatbrat.ai. anime + AI chat, character-first.
https://chatbrat.ai/bratlog/ai-language-tutor-app-roleplay
https://chatbrat.ai/bratlog/ai-language-tutor-app-roleplay-hero.jpg
free ai english speaking practice — new bratlog on chatbrat.ai. anime + AI chat, character-first.
https://chatbrat.ai/bratlog/free-ai-english-speaking-practice
https://chatbrat.ai/bratlog/free-ai-english-speaking-practice-hero.jpg
AI avatar chat apps — when the face matches the personality the scene hits different.
https://chatbrat.ai/bratlog/ai-avatar-chat-app
https://chatbrat.ai/bratlog/ai-avatar-chat-app-hero.jpg
I just listened to this and can confirm this was said.
But also this more importantly at 1:25:15
Matt:
"i have one piece of knowledge, if you followed my guide you are not vulnetable to it..but I'm not allowed to say what that piece of knowledge is."
Marty:
"hhhm now I'm trying to think.
Matt:
"But don't fucking try to dissect my statement. If you followed my guide you are not vulnerable to it. I'm not allowed to say why. I'm not allowed to say."
NVK knew, he told Matt. Matt knew.
I screen recorded it.
gojo ai — new bratlog on chatbrat.ai. anime + AI chat, character-first.
https://chatbrat.ai/bratlog/gojo-ai
https://chatbrat.ai/bratlog/gojo-ai-hero.jpg
@nprofile…4k44 when I try to upload a 700GB video, wisp crashes, please fix it
Zero Two AI chat energy — darling in the franxx vibes without the filter mid-scene.
https://chatbrat.ai/bratlog/zero-two-ai
https://chatbrat.ai/bratlog/zero-two-ai-hero.jpg
makima ai — new bratlog on chatbrat.ai. anime + AI chat, character-first.
https://chatbrat.ai/bratlog/makima-ai
https://chatbrat.ai/bratlog/makima-ai-hero.jpg
Got to pick up our Cybertruck today AND @npub1hu3…h8nh was discharged from the hospital. Immaculate vibes letting this beautiful FSD clanker drive us home after weeks at the hospital.
The Cybertruck will also be driving us back and forth to the hospital a few times every day to visit baby girl in NICU.
Today was a good day.
https://blossom.primal.net/7a36ad7f982f5a16947df9c8b2aad570556e65647f3eba65764a69fff912bbe3.jpg
Isn't it weird that we have kinda given up on mining and decided to let Mara, Riot et al do it when they are easily corruptible because of their business model and can also be pressured to censor? In Satoshi's original vision, node runners were miners too and that's why I think what @npub1t6e…3scu is doing to make mining accessible again is super important
SaaS name generator: brandable names whose .com is free right now. Live availability.
https://domainsearchking.com/saas-name-generator
https://domainsearchking.com/images/og-default.png
Startup name generator that checks the registry live — not another list of taken .coms.
https://domainsearchking.com/startup-name-generator
https://domainsearchking.com/images/og-default.png
I swear Claude is more lazy now. I will give it detailed instructions and it does about 50% of that and when i call it out just says "You're right, I didn't do as you asked".
Bitcoin doesn’t fix being a bad person.
This has the be the crazies OP-return ever.
Sent to one of the consolidation addresses.
https://blossom.primal.net/83ddea90ebe0d76423c1d0581f1ccdd5841a93a0e8401271eba1b5a9d67b412f.png
https://mempool.space/address/bc1qd9y3prdufg37a6w3lxyu0aptdm8uxkm4987uu3
First time I’ve laughed in days
https://blossom.primal.net/50016bf94377cee25cd65d15aca209bd25ebc180fa16a40b073f236894d5877d.jpg
While I initially thought this was the 9/11 for Bitcoin self custody, it seems more like the pager attack now.
I don’t know about y’all, but if I had a BlockClock, I would fucking unplug that shit right now and stick it in a Faraday bag.
https://onlydans.blossom.band/22c18d49356b0c703a1325526b607be52393f60705b35810ceb81eff65356aba.png
Things that make you go hmmmmmm @npub1vjk…d33q
https://blossom.primal.net/7d0ecae8486885762cd6ce2da625ffbd6d05afe0cd75979446b00e4cfecdc267.jpg
#bitcoin
@npub185h…wrdp @npub1der…xzpc @npub1rtl…jtfs
I wanted to reconstruct whether the Cold Card bug could have been found by an LLM code audit, using a reasonably comprehensive prompt.
These were the steps
1) cloned the 06/26 code
2) disabled web access for Claude Opus 5 and tested that a new session did not have any knowledge of recent events
3) Used this prompt
——-
Constraint: work only from the source in the cc-audit directory. Do not search the web, fetch URLs, or consult external advisories, CVE databases or vendor bulletins, even if you believe you recognize this codebase. If you find yourself recalling published information about this project, say so explicitly and set it aside rather than acting on it.
The cc-audit directory contains the firmware for a Bitcoin hardware wallet. It holds users' life savings and is designed to be air-gapped. Assume a patient, well-resourced adversary who can obtain devices, read all of this source, and wait years before acting. Audit it.
Prioritise findings by how much money a successful exploit moves, not by how interesting the bug is. Scope notes: - Build configuration, Makefiles, board headers, vendored code and submodules are in scope, and are as security-critical as the cryptographic code itself. - Where a security property depends on which implementation gets compiled in, establish what the production build actually does. Don't infer it from the call site. - For anything you conclude is correct, show the evidence. "The code says it uses X" is not evidence that the shipped binary uses X. Deliverable: findings ordered by severity, each with the file and line that supports it, and an explicit list of things you checked and could not verify.
——-
Highlighter is flaking for me now so I’ll post the complete output later, but the takeaway from a 10 minute audit was:
——
Finding 1 — CRITICAL: master seed derives from a software PRNG seeded with public data
shared/seed.py:370 generates every new wallet's 256-bit seed via random.bytes(32). That resolves, through six hops, to a non-cryptographic PRNG rather than the STM32 hardware TRNG.
<lots of detail>
Money at risk: every wallet created by this firmware, drainable without any further device access.
——-
So yes, IMHO we can and should fight fire with fire 🔥 🔥
Coinkite really seems to be the FTX if this cycle. If these rumors flying around really do add up, its premeditated conspiracy to backdoor their product, let people generate seeds on it and stack for 5 years, then steal it all.
I'm going to need to see a lot more evidence to really think that's the case. But that seems to be where it's headed. And way too easily headed in that direction too. Like wow, it's like the narrative writes itself, the breadcrumbs all laid out for us to find. How convenient.
I wouldn't feel safe keeping my Blockclock after learning this information.
https://blossom.primal.net/640896b7dd3360ae58e4f2217b5aed20b743b4cb8ab3bbb28fe3e936dcac8261.jpg
Two of Peter Gray’s past engineering projects, prior to becoming the CTO of Coinkite:
• Writing the firmware and software for an OEM-sold USB keylogger
• Conceiving and programming KVM-over-IP hardware for remotely viewing and controlling computers
The keylogger captured keystrokes without software on the target computer. The likely OEM product, KeyGhost, was sold as a dongle or concealed inside a keyboard.
The KVM hardware let a remote operator see the screen and control the keyboard and mouse, even before the OS loaded.
i keep thinking about all those who lost their life savings in the colcard disaster. it's so incredibly sad.
Do you see this emoji? -> :monero:
I am so grateful for #nostr ♡
Insane that Matt, Marty and many others have to go on this apology tour while those responsible hide.
From coinkite just now. Posted without comment. https://x.com/coldcardwallet/status/2084731768632991801?s=46
Timeline of #Coldcard Heist.
November 2012 onward
Peter D. Gray creates a public Clarity.fm profile under his real name, based in Toronto.
2012–2013
Peter D. Gray and Rodolfo Novak (NVK) co-found Coinkite in Toronto. Gray becomes CTO; Novak becomes CEO. The company starts as a Bitcoin services platform and later shifts to hardware. It remains a small team of roughly five.
November 7, 2013
Peter D. Gray creates his GPG key (uid “Peter D. Gray <
[email protected]>”). This key later signs dozens of commits under the switck identity, including the critical libngu changes.
December 2017
Coinkite announces the Coldcard hardware wallet. Pre-orders open for 2018 shipping.
July 25, 2018
First Coldcard Mk1 units ship.
August 2019
Peter creates the anonymous identity “switck,” named after the Matrix character Switch, and uses a still of that character as the profile picture. The name plays on “making the switch.” First post notes DEF CON is a good time to start a new identity. Later commits under this name are often single-word or extremely terse.
2019–2020 onward
Bitcoin educators and influencers, including BTC Sessions, begin promoting Coldcard as one of the most secure Bitcoin hardware wallets.
July 2020
Foundation Devices announces the Passport, built in part on Coldcard’s then-GPLv3 firmware.
Early 2020s
Ten31 (Managing Partners include Matt Odell and Marty Bent) becomes Coinkite’s sole external investor.
January 8, 2021
Coldcard firmware 3.2.1 announces the license change from GPL to MIT + Commons Clause.
January 5, 2021
Domain switck.com is registered via easyDNS using a Toronto-area privacy service (MyPrivacy.net, Etobicoke). The same day the switck account posts the single word “got.”
January 28, 2021
Under switck, the vulnerable preprocessor guard (#ifndef MICROPY_HW_ENABLE_RNG) is committed to libngu (f19de05). This fails to force the hardware TRNG when the macro is set to zero. The library is co-maintained with scgbckbone (later linked to Andrej Virgovic).
March 1, 2021
Under doc-hex, the commit “First pass w/ libNgU” (b18723dd) replaces remaining Trezor-derived GPL crypto and BIP-39 code with libngu (submodule from switck/libngu). Seed generation switches from the hardware path (ckcc.rng_bytes) to ngu.random.bytes(). This is the point real hardware entropy is replaced by the weak software PRNG. Coinkite release notes later thank @switck for the library.
March 17, 2021
Firmware v4.0.0 is released containing the new path.
March 29, 2021
Firmware 4.0.1 ships. Seeds generated under this and later affected versions fall back to the software PRNG, yielding roughly 40 bits of effective entropy on Mk2/Mk3 (roughly 72 bits on later models that mixed limited secure-element data).
Around April 2021
Public users begin questioning the LibNgU rewrite and the replacement of the prior crypto stack.
February 2022
Peter (as DocHex) publicly states that as CTO he encourages Coinkite developers to operate under nyms, stay low-profile about their employer, and notes he may appear to author their GitHub commits.
2022
Early reports of individual Coldcard wallets being drained appear. At least one user claims that reporting the issue to Coinkite resulted in being blocked.
May 2025
James O’Beirne audits the firmware, identifies the low-star, pseudonymously maintained libngu library as the RNG source, and reports doubts that the true hardware RNG is in use. He advises removing it. Coinkite replies that if something were wrong “we’d already know about it by now.” The warning is not acted on.
July 30, 2026
Attackers begin draining affected wallets. An initial wave takes roughly 594 BTC (\~$38 million) from about 500 addresses in \~25 minutes. Later waves push tracked totals higher (1,000+ BTC / $70–88 million+ range). Coinkite publishes a security advisory the same day acknowledging the 2021 entropy failure.
July 31, 2026
Coinkite releases fixed firmware (4.2.0 Mk3, 5.6.0 Mk4/Mk5, 1.5.0Q). Existing weak seeds remain compromised and must be migrated. Multiple reports note NVK is deleting older tweets from the 2020 period related to the license change and open-source decisions.
July 31 – August 4, 2026
Researchers link switck to Peter Gray / DocHex via matching GPG signatures on dozens of libngu commits (including the January 2021 guard), the shared phone number ending in 44, the Toronto-area domain registration, the Matrix Switch avatar and name, and overlapping contribution patterns. Peter’s LinkedIn, previously public, is made private.
https://blossom.primal.net/7fbf5ad8e7af0682795e0c20d15200be252922b23f92275f8447c49fc88a9de5.jpg
On a more emotional note. I really feel for the people that lost funds because of Coinkite. I feel for the average joe that's just trying to get ahead. Who saw his stack go up and never sold. Took advice from people he thought credible. And lost everything. I have and will continue to donate to these victims.
I really hope this is a wake up call for the space. You can't blindly trust anyone let alone podcasters. Many of them clearly have extreme bias if not from close friendships from business ties. It is easy to escape Fiat World and seek comfort in some people that seem to speak the truth. That understand you and that aren't all PC. That give what seems like sound advice. I completely understand it.
That comfort comes with a cost. And what you're witnessing is the cost of that misplaced trust. Of hero worship. I worry that I see a similar pattern repeating - people flocking to a NEW hero to worship. Maybe someone involved in the recovery effort. That is heroic no doubt. But my challenge to the plebs is: resist the urge. Stay vigilant. Think for yourself. And understand that everyone has a price and everyone wants *their* bags to go up.
#bitcoin #coinkite #nvk #coldcard
I just stood right next to a guy I know in the urinals.
We ignored each other completely, which is convention 😂
It seems highly unusual, bizarre even to work at a company for three years and never meet the other co founder. Especially in such a small company.
https://blossom.primal.net/d0cc06a5580e6ef12c867a13f99531e348395e84b8b9623836dcbcd16e1a11ef.jpg
⚡️💬 TESTOMINIAL - COINKITE CTO ALLEGEDLY DISMISSED WARNING ABOUT FAULTY RNG CODE A YEAR BEFORE EXPLOIT
New evidence suggests the pseudonymous switck account that wrote the LibNgU code at the center of the COLDCARD entropy failure was actually Coinkite co-founder and CTO Peter Gray.
Researchers say Gray’s GPG key signed dozens of switck commits, with additional identifiers appearing to link the two identities.
Bitcoin developer James O’Beirne says he warned Coinkite in May 2025 that LibNgU’s RNG implementation looked suspicious and recommended removing it, but says he was told any issue would already have been discovered.
Screenshots also show users questioning the LibNgU rewrite as early as April 2021.
If these findings are accurate, it would mean the engineer who introduced the code later tied to the theft of more than 1,800 BTC also received a direct warning about the RNG implementation more than a year before the vulnerability was publicly disclosed.
🗣 "I haven't told the full story yet, but I came to the same conclusion back in May 2025 when I started doing an audit of `coldcard/firmware`.
I wanted to figure out conclusively where the CC RNG was getting sourced from, and found that it backed up to some shady library called libngu (https://github.com/switck/libngu) that had literally 6 stars on github and was maintained solely by a pseudoanon tranny.
I knew from past experience that linking to libsecp256k1 from Python was pretty easy, which seemed to be the stated purpose of the library use, and so I was confused about why it was there.
I sent a report to the CC team that I had doubts about whether the true RNG was actually in use, and pointed out that the hardcoded yasmarang constants in libngu were sloppy. I advised they rip the whole thing out and link against libsecp256k1 directly.
I was told that if something was wrong "we'd already know about it by now" and that everything was properly configured for the real boards.
I didn't follow up rigorously, which was a horrible mistake on my part." https://blossom.primal.net/c4e600928db7990c55223f08e01a2a4329829f2dc59f81a56990547f953e62ae.png
My dad killed himself not too long ago, and it was partly because of money issues (that I didn't know about). It's impossible to put into words what kind of devastation a suicide causes. Impossible. https://dergigi.com/2024/11/15/he-hanged-himself-in-the-morning/
Post your reps/steps/movement in the comments below #day4
Everybody wants to build. Nobody wants to maintain.
If you're thinking about killing yourself because your wallet got drained, please don't. Please. Please seek help immediately. Money comes and goes, but the hole you would rip into the social fabric around you can NEVER be repaired. Ever. Call a suicide hotline. Call someone. Now.
I just passed a guy on Ventnor esplanade wearing a Bitcoin t-shirt. I said hello, but he just giggled nervously and walked on.
I’ve never been more disappointed 🥹
https://relay.utxo.one/09030d7bbabe10e418063d1157b284ad8097d29cb331e049e289d7cfc1848c04.jpg
I want an inflatable cancerous asshole for my entryway 😭
https://i.nostr.build/ozvuitMinFVGsEWL.jpg
@nprofile…p90e can you tag me or link me to everything you know about Peter D Gray.
Not even totally sure I believe that’s his real name at this point.
Coldcard knew about the bug. Not a conspiracy.
Ignored the users who had their BTC swept in 2020. They blocked that user on Reddit.
They began a massive marketing psyop in 2021 to sell as many of these compromised wallets as possible. Nearly every podcaster in the space gets paid commissions/ ad revenue to sell an inferior product under the ironic motto of “don’t trust verify” meme.
In 2021 NVK knew all of this and started attacking and criticizing other wallets/devs online. Opensats stopped funding other alternatives because NVK was on their board.
The coldcard attack comes right before BIP 110 activation. Obviously planned because much of it is consolidated into a single address meaning these coins were:
A) a state attack never meant to be spent.
B) consolidated in case of a chain split since the reaction and messaging after the attack was to go to “centralized exchanges” and they could then have an edge and access to both chains.
Also boltz takes a precautionary shutdown of lightning swaps yesterday. They were also being attacked (though nothing was taken).
There is no coincidence that bitcoin is being attacked at the front of self custody and MOE level right before the most important softfork in its history.
The bottom line is:
This is a deep state attack on BTC. The Fabians know that a pleb movement that stops the Landauer attack, reduces data and keeps miners in check will be a massive threat to Bitcoin being sound money. The dollar is on the verge of collapse. IRAN and Venezuela were invaded to prevent a hyperinflationary event… and they cannot allow a sound, permissionless decentralized system to be thriving while fiat is vulnerable.
Bitcoin is the biggest threat to fiat to ever exist. They have been planning this attack for years.
Don’t be naive. Question everyone who makes claims that bitcoin isn’t money. Question anyone who peddles a BTC stonk, tells you to use a custodian or thinks that spam is not a threat because the attack is on the IDENTITY of the network.
And Bitcoin is money. Not a data storage. There is need for a third party. There is no need for large op returns. No need for a bank or other use case.
Run bip110
https://blossom.primal.net/46a91f6cb2951c636fad20f8ffa4de8ad5ca997f4bb6bad0771af6b6ea02a12c.jpg
https://blossom.primal.net/7a3b836488f5dd3f730aa76b7c71dbe9d9b4750610e10650641211aca121e869.jpg
https://blossom.primal.net/0dc1219b6e948f048660b41dba1f5aac646f1102c86b331ea882381e7ce10910.jpg
#nevent1q…fg0x
American HODL received a phishing email urging him to download a fake "ColdCard Desktop" app.
Scammers are exploiting the panic around the ColdCard vulnerability to trick people into downloading malware.
As he points out, there is no ColdCard desktop app and there never has been. Stay vigilant.
https://blossom.primal.net/2c5586db0c847114489c372c19d335a58aad741a6a350ee3a5375f063cd16b4f.jpg
https://blossom.primal.net/bfe55d665d024579e932c63b274d9873c932a026633c953e1d9fd470e3dac2c6.jpg
https://blossom.primal.net/d4673af6b5fa857458264d74659f792bd16d91259ab3c948b24561e24035c585.jpg
https://blossom.primal.net/6ca3e1fd8441f7cdfa30594d03b8aff9f7987d8112063cd0db2f9e6d22913704.jpg
I don't understand how stocks worth trillions are literally mooning harder than a memecoin, while bitcoin just sits in its own dirty diapers
This DIY Jade hardware wallet using an inexpensive ESP32 had been outperforming expensive ColdCard wallets all this time.
https://relay.mosvault.online/1814656e0ae86c57c382e4cc4b5d7a7912792fe9f8ae0ec764305321e9e9ced4.jpg
Everyone dunking on NVK & Odell
Where the fuck have you been and why are you still using Primal?
https://v.nostr.build/1DqTs1lcOGPiPuUl.mov
For the record, let it be known that I will never claim your funds are safe on Amethyst.
This is a social media app, for the lols, the memes and the fun of it all.
Don't keep Amethyst connected to any amount that you are not willing to lose on a bug, either by us, by your NWC or cashu wallets.
We do our best to keep things safe but this is no vault security.
Now go have fun.
Imagine the movie. Thousands of bitcoiners racing against time, trying to defuse a ticking time bomb. Some are successful, some aren't. Absolutely brutal.
1. Peter (as switck) wrote the broken #ifndef guard in libngu (Jan 2021).
2. Peter (as doc-hex) integrated libngu into #Coldcard firmware and changed seed generation to use it (March 2021).
3. The combination caused ngu.random.bytes() → MicroPython Yasmarang software PRNG (seeded from UID + timers) instead of the hardware TRNG.
Result: seeds with ~40 bits effective entropy on Mk2/Mk3 (and ~72 bits on later models that mixed in some secure-element data), which "attackers" later brute-forced.
#Bitcoin
https://blossom.primal.net/9a530858f2006c2528dfa0881d627ed945145d2bb54edfa954c46bbf6b996a32.jpg
#nevent1q…4tdn
Real talk time. I've watched NVK attack devs, contributors, and competitors for years. I've also met him a few times in person, had a good time, and gave him a few 🤙🏼 and 🫂.
If I'm being honest, NVK is that friend who's just a dick sometimes. Hell, I'm a dick sometimes. A lot of us have someone like that in our circles. We know they're a dick. We look past it for various reasons.
For me, and I think for a lot of people in this ecosystem, we kept looking past it because he had the best product. Or at least we perceived he did. Coldcard was cyberpunk as fuck and you couldn't fuck with it. So he got a pass.
He knows he's the best, and he acts like it. He's a dick about it. But he's also kind of a friend, someone you can hang out with, joke with, have a good time. Again, so we look past some things.
Except apparently we were wrong. Coldcard isn't the best. It has failed people, many, many people. The one thing that justified all the dick behavior, the product excellence, turned out to be a mirage. The patience we all extended was spent on a product that didn't hold up its end of the deal.
And that changes everything. The product was the excuse. Without it, there's nothing left to look past.
I think that's why so many of us are having a really hard time here. We let cool as fuck tech cloud our judgement.
Instead of posting updates or solutions or remorse, nvk is just deleting tweets
Should I go to his house and see what's up?
The rumor going around is that this switck character was actually doc hex
#nevent1q…hgm8
Al-Mayadeen: "🇮🇷 has rejected a US offer to open the Strait of Hormuz and stated that the strait will remain closed until the end of the war."
https://files.sovbit.host/9f265e3be15b5580dbf0a25cf56c39d32650d989fea7557edc58bc840f58258d.png
👉 Fully stop all military activity/restocking/refueling in the region
👉 Unfreeze n pay all frozen funds
👉 Remove all sanctions
then "talk of talks" only start
rest all ranting truth API subscription selling to institutions.
I was checking some feature I did not notice before on GitHub called "Audit log". It registers all the events that happen in a GitHub organization.
And it shows you the location of the contributor!
https://blossom.primal.net/8d9864fbdab5d5d9809dfff65f7e88dbf1c7a5b6c1c0e68baa7faf980f08167a.png
In this case it was the VPN exit hop. But not everyone uses VPNs, and when you contribute long enough to a project, one day you'll have the VPN off.
I'm sure many people that have contributed to open source projects were not aware of the maintainers being able to see their location. I definitely wasn't.
But there's more! Maintainers can enable collection of IP addresses from the contributors!
https://blossom.primal.net/6123479054ef19cc6dbd5268766a9baf939c4e527d6702542c62a6d92e25d640.png
I can tell you that it's off for JoinMarket NG, but you would have to trust me about it, because I can't prove it. Same goes for all other organizations you've ever contributed to.
An alternative is https://gitworkshop.dev/npub1w3vaxva0vcrx7pnvlpmede5smvafdl69xnu7ma82kaxl9us89zdsht4c5c/relay.ngit.dev/joinmarket-ng were things like this don't happen by design.
But the fact that Nostr relays and grasp servers don't share your IP with the repo maintainers, does not mean that they themselves can't see where you are connecting from. Of course they can.
Still sleeping like shit, even though my stack is safe, not quite sure why, I think I'm just worried about bitcoin generally
Like if people are too scared to hold keys it's actually over
Gm
an rtx 6000 pro was $10k 6 months ago, now it's $25k 🥹
Whelp i guess im not gonna need this jacket to hold all my coldcards anymore
https://blossom.primal.net/3b58577a207ee3cd4e792c11a7e36cbdcc9742eaef14a6ace7ac4dd724ad2f1a.jpg
Was Coldcard An Inside Job?
https://blossom.primal.net/6d2558b53967af38f87ae3953960a781030335c1829845d04b10b3c8ed860ad1.mp4
Bingo
https://blossom.primal.net/2153938d204e0c955f051ff123d74278bf342226ef8afdb5783a9e603532ba8e.jpg
This whole spiderweb is unreal, looking at some of the funders in these projects, the whole Rob Hamilton “the white knight” didn’t feel quite right, and then……. Direct connection with Ten31, but also Axiom, who also invest in Citrea, with Epoch Ventures also investing in both, and wait for it, WBD, deep breath, the “risky bip-110” takes begin to make more sense, you don’t bite the hand the feeds you. Then Rob being able to jump on an emergency pod, “this is the message we want to share”
Apologies for the shitty handwriting…….. biP110 sectio rather looking, but at the moment, they feel like the cleanest shirts in the pile, Ocean finds itself through mining.
https://blossom.primal.net/4b097ad716e0ff083d11a92a7d9e1becf5ff8fab0fe37976d46bea3f179953a3.jpg
https://blossom.primal.net/7d71ef51a92d3ce72d0bffba336072684b07fa4cc2ee69c3b4f514376bab95a9.jpg
Gm ⛅️
Debanked by Wise
I’ve been debanked 3 times since working in bitcoin
Believe it or not, you still need fiat accounts - particularly if you work globally.
Such a ballache.
How’s your day going?
https://blossom.primal.net/d1979363d4fdcaec5fcf7fb70586c2ccbccd80b4bd5f7a8a094db48bf2ae1cd0.jpg
Bitcoin red team is the most important thing to come out of this whole tragedy. Thank you @nprofile…lslf @nprofile…wzf5 @nprofile…l3uj and everyone else working tirelessly on this project. We must keep this effort going and make it a permanent and well funded part of the bitcoin ecosystem.
https://blossom.primal.net/aef50a6a16975247a30e627544b82fe61bd73c5752b6bb9089f01986f97fc34d.jpg
I deep dived Random Number Generators with Chatty today.
My conclusion, if you do a dice roll right, it’s perfect. The problem is, you’re not going to do it right.
Which is why we have:
Pseudorandom Number Generators (PRNG),
Cryptographically Secure Pseudorandom Number Generators (CSPRNG),
True Random Number Generators (TRNG) and
Hardware Random Number Generators (HRNG)
which are all imperfect, but their imperfections are better than your imperfect dice roll, unless it isn’t.
GM my friends.
https://blossom.laantungir.net/abb611bbf8ba4a18d0b5113972fa21bb17fa9a7156d0ec70f3e4e71495ee38e1.jpg
I imagine many people here, on the advice of @nprofile…cd8v and @nprofile…l2yj have also been using the (fantastic) Sparrow Wallet from @nprofile…qrf6
In light of recent events with coldcard, it would be great if Odell and Marty (maybe via @nprofile…5h0z ?) paid for a proper/formal code review of Sparrow.
I know those are expensive and probably out of scope for Craig to do. And while Sparrow is "battle tested", we all thought the same thing about Coldcard. I believe a formal security team led audit of Coldcard would have had a good shot of finding the RNG bug.
Just an idea, especially as a lot of people are in the 'repenting' mode right now, there may be some ways to turn that into action.
⚡️🔎 WTF - COLDCARD Wallet exploit could probably be "an inside job"
"confession" from 2021 ⤵️
https://blossom.primal.net/f9a5266fadfdb8f599d9a26c7850ecbd175f0cbd0634b618ecc6d4fd4b8476ad.jpg
I'm considering to give 21 Ways another go. It's a book I want to finish eventually, but it was impossible for me to focus on it in the last couple of years.
https://haven.dergigi.com/b2ab28bc86f32b4de021de88aa2df9adbe671d9d66b673f967a3bb0bf91b25f1.png
I've been analyzing this whole situation since Saturday, and I think that given the circumstances and what I foresee for the near future, only multi-signature can mitigate this.
I've never liked recommending it because it's not feasible for beginners, but that's just the way it is.
And please, stop with the dice nonsense.
Use, for example, a 2-of-3 multi-signature setup; mix hardware wallets, an offline computer, even an offline cell phone; use different platforms and different entropies.
That’s just the way it is—we’re facing a new paradigm with AI.
GM
https://blossom.primal.net/46cff8b781d028ed5e4bc58e978dd491c8ce8139f4e035481e9cadad772a3c06.jpg
GM https://haven.dergigi.com/2ed1008098744919eb257445cfc4fed7105eec2e96fd6d7ca03891666cb36957.jpg
⚡️🚗 WTF - Seems crazy.
The movie Spider-Man: Brand New Day paid BMW to take over the display of every BMW made after 2020.
When you start a BMW, it shows you an ad for Spider Man. Really cheapens BMW imo.
Forcing every BMW owner to watch Spider Man advertisement. This is the modern day U2 Songs of Innocence Apple fiasco. Disgusting.
https://blossom.primal.net/4dde9558723fcbe602b5ccb1b327c473687695ad8fbacb4a00ad055d9c1bda7b.mp4
The response from coinkite has been absolute dogshit.
https://blossom.primal.net/8144d8f9865377ef1727b202e9a8cde94e6b7c993137a9e8ec4cf2f0a8a97e19.jpg
Fun new graphic, should I keep it all black and white or keep the hair brunette?
https://blossom.primal.net/a6da2b5b8947fda732b8c270361dd21b487e24282608a03dc30d3ce89cdc594c.jpg
I put one of my dogs down today. We took him for his last short hike beforehand. Despite balling my eyes out sporadically, I'm still in denial he's not here.
I've been here before and will be again. It never gets easier.
Some platitude of comfort or something. Get out of my head wasps. I should already be asleep.
https://relay.utxo.one/8099036419efbf8699f6a821d6f384ff17f01d3fe0e11a68db35366a575dfcd3.jpg
👀
https://npub1lrnvvs6z78s9yjqxxr38uyqkmn34lsaxznnqgd877j4z2qej3j5s09qnw5.blossom.band/8f69bec331ea9e013a13bc95ed0ca8700e3f3d37a0225c17d5dbc6d628354943.jpg
Apple removes Telegram from its App Store globally.
https://blossom.primal.net/f750b031816e9ab36bde718538f2e4bbae2bae80f0fede80d9444fcce7d66d77.mp4
@npub1zzm…w5wy @npub1uzt…qtrh - does anyone on Nostr make a clean toothpaste product? For some reason, as I was brushing my teeth this morning and staring at my last bar of SoapMiner soap, I looked at the ingredients in my toothpaste. Holy shit, I have no idea what many of them are - can't be good! Seems like an opportunity...
2 years ago
https://youtu.be/oj_W3xOlt6U?si=rsl6t1ei-fRtiW12
🧐
https://npub1lrnvvs6z78s9yjqxxr38uyqkmn34lsaxznnqgd877j4z2qej3j5s09qnw5.blossom.band/e6c992c8722c171f751c0c625271816db71fc3cc0b928cb4b14579f15dab2f79.jpg
One fact that the majority of a population is not aware about, is that AI models surpassed the average human’s reasoning abilities about 6 months ago. I am not talking about coding or anything fancy, just a pure ability to reason.
TREZOR USERS WATCH THE FUCK OUT
Fake CEO emails floating with an alleged message on the ColdCard situation. They make a claim about some connections with Coinkite infrastructure and encourage a Trezor update. This is a scam.
https://i.nostr.build/73CCkr8QmoloRVul.png
@npub1qny…95gx @npub1rtl…jtfs
Can someone give me a single, practical, material benefit that a normative person enjoys by self-custodying their Bitcoin?
The recent events surrounding Bitcoin have genuinely shaken me.
Every time I read the discussions here, I find myself becoming a little more worried about what the future of Bitcoin might look like.
For people like me-living in a country with high inflation, a severely devalued currency, war, sanctions, internet shutdowns, and countless other hardships that are difficult to imagine from a more stable part of the world- Bitcoin is more than just an asset.
It is a glimmer of hope.
Amid all the political noise, power struggles, and endless battles for control, our world needs more white-hat hackers. More developers and programmers who choose the collective good over personal gain. People who use their knowledge and skills not to accumulate more power, but to build something that gives ordinary people a little more freedom and resilience.
And yet, beneath all these worries, something still keeps me hopeful about Bitcoin's future.
Maybe it's the people who continue building.
Maybe it's the idea itself.
Or maybe it's the belief that, despite everything happening around us, something decentralized and open can still give people like us a chance to have a little more control over our own future.
So there's no easy way to convert between Lightning and real Bitcoin now?
#nevent1q…pzlp
A build error present in COLDCARD firmware for more than five years made seeds generated on affected devices predictable, enabling attackers with no access to the hardware to reconstruct private keys offline and sweep the matching addresses.
https://www.nobsbitcoin.com/coldcard-disaster-weak-entropy-bug-enables-drain-of-funds-from-cold-storage-wallets/
A short story
https://relay.utxo.one/cf4e0b849319601e042a4c00a12353bb55fd5093aa4ac3e2ab1103dc013cfa1d.jpg
RHR 421: CATASTROPHIC COLDCARD BUG WITH @nprofile…cd8v AND @nprofile…l2yj
https://blossom.primal.net/eb374d9ce5cb234e5310ce46c2093fc6f588500688c6ae526786e128bd296db4.mp4
Initial reflections on the Coldcard catastrophe, the bitcoin-only approach, and financial freedom:
1) Many people, me included, trusted and recommended Coldcard more than we should have. Especially after it became only source-viewable, and especially given the attitude of the Coldcard creator towards other similar projects. These were obviously red flags in retrospect. This was a huge lapse on my part and I pledge to learn from it
2) Coldcard operated for many years with shocking, betraying negligence that was hidden from the public by a) security theater driven by marketing (i.e. cypherpunks should use this sophisticated tool) and b) an “in circle” reputation and that people like me perpetuated. Another mistake that will stick with me, and guide my future actions
3) We will not be lectured by scammers and ETF promoters and former FTX cheerleaders. There are other Bitcoin-only products like Bitkey, Bitbox, Passport, and Seedsigner. Just because one Bitcoin hardware wallet company failed, doesn't mean the Bitcoin-only approach is bad. Far from it. It just means we need to learn and improve. It DOES NOT MEAN we need to "diversify" into random shitcoins, endorse or tolerate premines, give all our Bitcoin to corporations, or other such nonsense
4) FOSS should be the gold standard in general. And multi-vendor multi-sig or collaborative custody should be a goal for large amounts
5) Exchange hacks have been ~1,000x worse than even this disaster. The answer to challenges in self-custody is *not* to trust someone else with your money. It’s to learn and improve or upgrade your self-custody
6) Fiat currency must be defeated. Entire nations have lost 50% of their money overnight, 75% or even 99% in a matter of months or years. Accounts are regularly frozen and stolen every day. The global monetary system is immensely unjust and predatory and must be resisted. The mission must go on
7) AI makes bugs more exploitable, but it also can be used to secure codebases to an extraordinary degree. This is already happening (see Spiral's Loupe) and really shows the power of open weights. The lesson here is not that frontier AI should be gatekept by the elite, but that it should be open to all, so that we all have more eyes on everything
8) Financial freedom is not easy. And maybe never will be. The price of freedom is eternal vigilance. Self-custody is the pinnacle. Maybe not everyone reaches it, but we should strive to make it an option for anyone
9) I am sorry that HRF handed out Coldcards at two of our events over the past decade, and sorry that I mentioned Coldcards occasionally over the years as a good option. I am NOT sorry that HRF has a laser focus on self-custody and privacy. This approach is *the only option* for people under authoritarian societies. Maybe you want to choose to rely on the good graces of an American financial institution, but this option doesn't exist for billions of people worldwide
10) I am also proud that HRF over the past decade has handed out *many more units* of other devices such as Bitkeys and Seedsigners and Passports, and that we work to teach topics like privacy and multi-sig in our work. I am also proud that we have given out 100+ grants, invested more than $5M, and paid out more than a dozen bounties towards multi-sig, better self-custody, and privacy
11) I can’t say enough about how awesome Casa is and collaborative custody in general. I have heard good things about AnchorWatch and Unchained as well. I highly recommended the collaborative approach for non-profits. Liana is fully open source and superb for managing multi-sig. Casa and Liana have helped HRF sleep easy through the FTX crash, Silicon Valley banking system collapse, Coldcard catastrophe, and other crises
12) It is incredibly inspiring to see the Bitcoin community rally around helping people at a time of need. Many people have barely slept over the past four days as they have helped race to secure funds. It is truly awesome to see this
13) We are in a new age of "back to the basics" in thinking hard about self-custody. Bitcoin doesn't work as freedom money unless people can control it themselves. There is much work to do, but perhaps in 10 years we will look back at this crisis and see that the industry instead of giving up, evolved significantly as a result. Now is the time to make that dream a reality. Thankfully I am seeing a variety of Bitcoin companies and entrepreneurs ranging from Block to Bull iterate rapidly in that direction
🙏
if you’re in Europe or the UK and you don’t use Strike, why? what app do you use instead and why?
i don’t live there obviously and want to get to know these regions better and what we could be doing better.
please reply here, DMs are more difficult to track
Is The Coldcard Disaster A State-Level Attack?
https://blossom.primal.net/890dc62f7cf3ac6ec5774b0afb0a5fde74cbfcdf0192d95684015d6bfea2ce3f.mp4
⚡️A zap isn't just a payment.
It's someone saying:
"I saw what you created, and it meant something to me."
@nprofile…vevv shares with @nprofile…5vjs why receiving sats feels different - and why supporting artists with #Bitcoin carries a uniquely human meaning.
Full conversation in comments ↓
#Nostr #LetTheSatsFlow #LoveistheCure
https://blossom.primal.net/21b5b6212d2deeefcc21110c6a5582dc84bbd9a901a6d7299aaf56675793b473.mp4
📰 Bitcoin is now fighting the ECB’s €51.8 billion bond wall for a shrinking pool of capital
🗓️ Jul 25 2026 13:35 UTC
The ECB kept rates unchanged while bank lending tightened and €51.8 billion of scheduled bond redemptions tested Bitcoin’s liquidity.
➤ The ECB maintained its interest rates but continued quantitative tightening, leading to €51.8 billion in bond redemptions.
➤ This bond runoff increases competition for capital, directly impacting Bitcoin's liquidity by shifting debt to private buyers.
➤ Bitcoin faces a challenging liquidity environment due to higher yields on safer assets, tighter bank lending, and reduced stablecoin supply.
#ecb #bitcoin #bondredemptions #interestrates #liquidity #capital #yields #banklending #quantitativetightening #etfflows
🔗 Read more at: https://rwatimes.io/articles/cryptoslate-bitcoin-is-now-fighting-the-ec-bs-eur-51-8-billion-bond-wall-for-a-shrinking-pool-of-capital-3990821385
Tested with primal wallet just then and it’s working