Dear COLDCARD attackers,
Congratulations. You successfully found a bug, exploited, and have collectively gathered around 1,500 bitcoin.
Now you are sitting on one of the most blacklisted coin stacks in history. It will be nearly impossible for you to exchange for currency or deal with any institution. Every move you make will be highly scrutinized and tracked. Presumably for the rest of your lives, you will be looking over your shoulder.
I suggest you plea with CoinKite to return all stolen funds in return for an audit fee of 5% of the loot. This way your work is rewarded and you are able to enjoy the fruits of your labor.
Respectfully,
hodlers worldwide
As far as grave-dancing goes, this is my good/naughty list.
GOOD:
- stressing the importance of paranoid nerd stuff like multi-vendor multi-sig and self-generated entropy (sure: it's complex and scary, and beyond reach for many currently, but when shit will really hit the fan it will be necessary anyway, so it should be seen as an ideal to achieve, not a quirk to mock),
- stressing the risk of bitcoin-specific devices over commodity phones or laptops (the former pay the objective advantage of smaller attack surfaces with the disadvantage of more niche and less reviewed/battle-tested code),
- stressing the importance of good UX over just tech (even if paranoid nerd stuff was doable on CC, some people didn't bother, while stuff like BitKey, for all the criticisms we may have, makes at least multi-sig a default and as simple as possible),
- stressing the importance of full FLOSS (the vulnerability was introduced together with the licence change and fewer people were incentivized to reuse/audit the public code),
- stressing the importance of some level of industry honest and peaceful cooperation on education and security standards on top of healthy free-market competition (the signing device space was full of animosity and excessive FUD, which frankly CoinKite was not immune to either, and that didn't help, since some users mistook the early alerts for CC-targeting FUD).
NAUGHTY:
- shilling custodial exchanges, ETFs and other big KYC honeypots as an alternative (they will also be hacked with frontier LLMs, and even more so than hardware devices, but on top of that they will also get some users kidnapped by thugs buying KYC lists, and EO6102ed by governments),
- shilling your own favorite brand of covenant soft fork as an urgent silver bullet (people who didn't care to set up a multi-sig would probably have not cared to set up a non-interactive vault, especially if it was a newer and more exotic feature: again UX and education on what already exists are the priority over introducing new stuff),
- shilling shitcoin-enabled competitors because CC was bitcoin-only (the number and size of hacks against generalist and amateurish "crypto" software, even if less impressive than the ones against custodial exchanges, put this episode in perspective: diluting focus to chase token-printing was and remains a bad idea).
Wallets created on a BitBox are not affected by the Coldcard RNG vulnerability. A BitBox seed combines five independent entropy sources. One weak source does not compromise the result.
More here: https://t.co/aNGg8DldZk
Tldr for scared people:
1) If you have significant money on keys generated by a ColdCard Mk3 without proper dice rolling and without a strong passphrase, MOVE THEM NOW, even just to a hot wallet, while you fix your cold setup (if your hot device is compromised you may lose funds anyway, but if you leave them there you most likely will pretty soon, so don't wait for the perfect setup to move, move now and perfect later).
2) If you have significant money on keys generated on a more recent ColdCard, or on a Mk3 with a very strong passphrase, or in a MK3 multisig you didn't spend from yet, you have more time. Take a few calm, focused hours in the next few days, create a good setup, understand it, test it, and then move. Mind privacy, even if it may seem the least of your concerns now. I personally use a 4-layer segregation between phone LN wallets, a LN node, a JAM wallet, a cold setup with decreasing threshold 3/3 multisig with Liana: a old laptop with Tails with persistent storage on Electrum, an old Ledger NanoS, a ColdCard Q, in all 3 I generated entropy externally with cards, the other seeds generated from the ColdCard with BIP85. There's no one size fits all.
3) If you don't use ColdCard, it's still a good occasion to review and improve your setup. Use multisig with different vendors to spread out the risk. If you have money on exchanges, the very same LLMs that found this will also find vulnerability in those massive honeypot. Take your money away from there asap.
@Pascal_Laurent_ È colpa del denaro che usiamo che non mantiene il proprio valore anzi lo perde con il tempo che passa. Sì se continua così sarà sempre peggio! Sempre meno o sempre minor qualità. Il denaro FIAT come tecnologia, come sistema che conosciamo, è rotto!
Honored to follow you! The spirit of commerce also includes capital savings and Gresham/Thier-kinds of considerations (to spend the worse money first and the best one later, when you can). Hodling IS using, indeed. In the case of your road trip, you were out of bad money, and it would be against the spirit of commerce to default on your obligations with merchants and creditors, so you acted consistently by spending your good money too! :)
Fiat is so catastrophically broken that grown adults are cramming shiny rocks into underground bunkers like medieval peasants hiding grain from the tax collector.
We live in the 21st century.
We can split atoms, edit genes, and launch cars into orbit.
Yet people are hoarding metal because they don't trust their government's paper.
That's a civilization-wide distress flare.
Silver belongs in solar panels and circuit boards, powering the energy transition and technological progress.
Gold belongs in electronics, automotive systems, and medical devices and worn as jewelry.
Instead, they're sitting in dark vaults doing absolutely nothing.
Locked away as dead capital.
Hoarded by people who correctly diagnosed that fiat is a dumpster fire but reached for the Bronze Age solution instead of the digital one.
This hoarding distorts prices and chokes innovation. It artificially inflates the cost of industrial inputs. Progress literally slows down because we're using resources meant for production as a hedge against monetary collapse.
Industrial metals should be powering technology, not sitting in vaults as monetary theater.
Bitcoin was designed to be money.
Nothing else.