More / Bitcoin Reddit - 2 hours ago
Nvk history posts show he was completely aware of firmware vector attacks, and narrative is, never in 5 years they audited the code in the single most safety-critical function on the device, not even SWE prompting to ask a frontier model "...
More / Bitcoin Reddit - 2 hours ago
My seed used with this device was strong and I was unaffected by the security flaw in the RNG setup. Still, I’m re-doing everything. I am moving back to my ledger until I get a multisig setup with a SeedSigner or similar. It’s gonna be a pain t...
More / Bitcoin Reddit - 3 hours ago
???? Yellow ≠ broken. None of the nine Yellow products has a confirmed fund-loss-by-default flaw. Yellow means at least one of: (a) something security-critical sits outside independent verification. i.e., closed firmware or secure-element cod...
More / Bitcoin Reddit - 3 hours ago
As a thought experiment, suppose a white-hat had been the first to discover the Coldcard RNG vulnerability. How could they possibly have disclosed it responsibly, given that weak seeds had already been generated? A public warning would immediately cr...
More / Bitcoin Reddit - 3 hours ago
You probably heard the birthday paradox, having 23 people in a room creates a 50% chance that at least two of them share the same birthday. Applying it to the vulnerable search space in the ColdCard bug (Following reports that search space was reduce...
More / Bitcoin Reddit - 4 hours ago
This is a tough week for bitcoin community. Wishing speedy recovery of funds for everyone involved. Lessons learned for the rest: Hardware wallets - were always a vector of a possible attack. Just like you can't trust 100% your ISP, your PC and...
More / Bitcoin Reddit - 4 hours ago
Don’t trust, verify. Before blindly trusting exlib funcs. submitted by /u/CrouchingTurk [link] [comments]
More / Bitcoin Reddit - 7 hours ago
Bitcoin Drive Engaged submitted by /u/WizofWallstreet [link] [comments]
More / Bitcoin Reddit - 7 hours ago
Something that finally clicked for me after years in Bitcoin: when your hardware wallet generates a seed, you're trusting its RNG and its firmware with literally everything. For most people that's a reasonable trust tradeoff. But you don'...
More / Bitcoin Reddit - 8 hours ago
I thought sharing this would help anyone who lowered their confidence in BTC; here is the btc hack timelines. 2011 – 25,000 BTC stolen from mt gox 2012 – 24,000 BTC stolen from linode-hosted Bitcoin services. 2014 – 850,000 BTC lost/stolen in the co...
More / Bitcoin Reddit - 8 hours ago
Took me years of DCA’ing to get there. I went with Coldcard because it was marketed as “ultra-secure.” I knew multisig was technically safer. I wasn’t worried about my key being guessed… I was worried about someone physically stealing it or it being...
More / Bitcoin Reddit - 11 hours ago
Just saying sorry, i know some people get out their soap boxes, some point fingers, some laugh. For the ones that just woke up and had their lives turned upside down and stressing out, its going to hurt, but tomorrow will be another day. Sorry you ar...
More / Bitcoin Reddit - 12 hours ago
This is for the people on my last post who despite being on a bitcoin subreddit are somehow completely technically illiterate with regards to LLMs, and called me a naive idiot repeatedly. submitted by /u/Impressive-Gene-421 [lin...
More / Bitcoin Reddit - 13 hours ago
Like many of us, I have followed the news of the Coldcard disaster. It has left me stunned and I feel terrible for everyone who has lost their hard earned BTC. After thinking about it consistently since it happened, I believe this case is challenging...
More / Bitcoin Reddit - 14 hours ago
It is unbelievable that some kid with an LLM just stole $100m+ because no one bothered to check the source code. Also on GLM 5.2 (trained 16th June, no internet access). submitted by /u/Impressive-Gene-421 [link] [comments...
More / Bitcoin Reddit - 15 hours ago
TLDR: coldcard decided to move from open source licensing to a "source available" license that would prevent people from forking their firmware to make competing products. This meant they needed to replace GPL license crypto libraries, it i...
More / Bitcoin Reddit - 15 hours ago
Think of a seed phrase as a random specific coordinate on Earth that has your Bitcoin The default seed coordinate is ground level dirt where your treasure can be seen and stolen easily A passphrase is a skyscraper built on top of that coordinat...
More / Bitcoin Reddit - 16 hours ago
Spread your coins across multiple devices from different vendors. Reduce the blast radius. None of us here are reading the code. We assume someone else is. With AI getting better and better, we should expect more hacks coming. submitted by...
More / Bitcoin Reddit - 16 hours ago
Watching old tweets from Cold Card CEO, now you realize how the red flag was out there regarding "entropy". How on earth you make optional a critical step in a product that you admit to not trust even yourself. If you yourself admit t...
More / Bitcoin Reddit - 17 hours ago
Please utilize this sticky thread for all general Bitcoin discussions! If you see posts on the front page or /r/Bitcoin/new which are better suited for this daily discussion thread, please help out by directing the OP to this thread instead. Thank yo...
More / Bitcoin Reddit - 21 hours ago
The long and the short of it is that a developer disabled a compiler flag out of desperation in order to get the code to compile, then committed it with the commit message "runs". Specifically, in C: #define MICROPY_HW_ENABLE_RNG (0) In oth...