The Coldcard bug explained in simple terms:
Normally, a hardware wallet generates your 12 word seed phrase using true randomness.
Think of it like a lottery with roughly 340 undecillion possible tickets (that’s a 340 followed by 36 zeros). Every ticket has an equal chance of being picked, making the odds of guessing your seed essentially zero.
The bug didn’t shorten the 2,048-word BIP-39 word list. It changed how the wallet picked the words.
Instead of choosing from the entire lottery, the wallet kept picking from the same tiny corner because the “random” numbers were partially predictable from things like the device’s ID and timing.
Imagine that instead of 340 undecillion possible combinations, your wallet accidentally chose from only a few billion. That’s still a huge number, but astronomically smaller than what Bitcoin’s security is designed to provide.
Your seed phrase still looked completely normal. The words came from the same 2,048-word list. Nothing looked suspicious.
But for an attacker, the search space became millions of trillions of trillions of times smaller.
Meet kbd-1.0-codex-micro, built with @work_louder.
Map the buttons and joystick to your workflow, and keep your pinned chats in view.
Get yours before stock returns 410.
I don’t think most people realize how utterly strange it is that Google does not have an AI harness that is competing with OpenAI and Anthropic.
Their ineptitude at product management has now gone from hobbling a company that was guaranteed to win to exposing it to existential risk.
This is a company worth trillions of dollars that is medically unable to ship a product.
Using any of their services as an administrator is the same type of torture that it was 15 years ago.
Google’s inability to fix this should be studied in business books for decades to come. Starting now.
It is the single strangest thing I’ve ever seen in business. They literally invented modern AI, and all they have to show for it is annoying pop-ups in Gmail and Google Docs that make everyone want to vibe code an alternative.
The best evidence that ASI already exists is a theory that it’s at work inside of Google already, making sure they lose.
What an absolute abomination.
What happened if someone chiselled a nose on just one of the sculptures wrong ? Did the whole temple need to be carved out again? Yet, they did not get it wrong .. how?
Carved downwards out of a single piece of rock , with no tools other than hammers and chisels ..
.. detail of carvings and sculptures within the temple are not just exquisite , but absolutely precise and accurate in form and in geometry.. from top to bottom
.. that’s a mystery greater than the mystery of the Pyramids of Giza…
The system of mathematics in ancient India came down from our scriptures and formed the basis of a lot of our music ( Taal ) , art and architecture, .. our Philosophy was not linear .. but circular .. where the finite met the infinite again and again in concentric circles .. like how the Universe is ..
The closest modern science now comes to it is what we call Quantum computing , Quantum entanglement . The theories on which Google has built the ‘Willow’ .. the words fastest Quantum Computer.
The British changed our education system and made it linear. The colonizers did not have any understanding or knowledge of Quantum .. we did .. but over time of colonisation.. we lost the knowledge and Wisdom ..
.. yes, Wisdom too .. for knowledge without Wisdom is dry , with the true and wider meaning squeezed out of it .
No wonder that when the greatest Indian Mathematician of all time was asked how he solved some of the most perplexing questions that all the greatest physicists and mathematicians in world were unable to solve ..
Ramanujan replied ..
..’My Devi comes to me.. ‘
#ElloraCaves #India #AncientMathematics #Upnishads #Architecure #Quantum #Willow #Wisdom #QuantumComputers #PyramidsofGiza #Ramanujan #AI #colonization #vedicculture #MyDeviComesToMe
Social media trends have turned the world’s most beautiful places into endless bathroom lines at a concert, where everyone waits for hours just to take the same photo to show to people who couldn’t care less 🌎📸
Nothing captures the shallow decay of our time better than this
In light of what happened, I'm doubling down on skills like /improve.
A frontier model got pulled. If it happened once, it's gonna happen again. Fable today. 4.9 tomorrow or maybe gpt 6 one day.
So, treat intelligence as borrowed. Drain intelligence when it's available. Build a catalog of plans today. Then implement later with a cheaper, open source, or a model you control.
Build the backlog now.
https://t.co/rqHw0fPv4G
Dear US government,
Since you've just blocked Fable and Mythos on critical national security grounds, here are some other tools that pose a similar threat to the American people:
- Microsoft Teams
- SAP
- Salesforce
- Jira
- Outlook
Please do what you must to save America 🇺🇸
‼️🚨 Unauthenticated attackers are gaining SYSTEM on domain controllers with crafted packets.
The vulnerability being exploited is CVE-2026-41089, a CVSS 9.8 hole in Windows Netlogon, and exploitation in the wild has been confirmed.
A patch has existed since May 12. Every DC still behind is not just vulnerable, but according to the Centre for Cybersecurity Belgium are also actively being pwnd.
River CEO @Leishman built a time-lock encryption oracle as a side project.
Upload a file, choose when it should be unlockable, and the system encrypts it with an RSA key that only becomes available at the specified time. Anyone with the encrypted file can decrypt it in their browser once the key is released.
It publishes RSA keys for each minute over the next 30 days, then releases the corresponding private key at the top of each new minute. Works in the browser for humans and via curl and openssl for developers and AI agents.
Use cases: delayed data access, embargoes, sending messages or files to the future, or anything else that needs a trustless time delay.
🚨 We recently discovered that an unauthorized party obtained a token with access to the Grafana Labs GitHub environment, enabling the threat actor to download our codebase. (1/6)