@parman_the This was “the hill to die on” it was “necessary for bitcoin’s survival” it “has to happen or the bitcoin network is fully captured and I’m afraid of what kind of world we’ll have without bitcoin 😱.”
Now it “was just a battle bro we’ll get em next time.”
🚨🚨🚨EMERGENCY DISCLOSURE🚨🚨🚨
CON-001: Consensus Divergence
Severity: Critical
Confidence: High
Description: If you run BIP 110, your node will have stalled and will be unable to use bitcoin for sending or receiving payments.
Remediation: Running Bitcoin Core
I have spent over $10,000 scanning 100+ bitcoin ecosystem related libraries looking for vulnerabilities with Kimi K3 running as quarterback.
Myself and a small "Red Team" have found multiple serious vulnerabilities impacting the ecosystem. They vary in scope severity, but this is a call to action.
For any critical tier vulnerability that was identified if I was able to immediately demonstrate a POC (proof of concept), I have already responsibly disclosed to the maintainers.
HERE IS HOW YOU CAN HELP ME
IF YOU ARE NOT TECHNICAL:
- please share with me any repository that is on github that I can scan, we want to cast a wide net. It takes a few moments for you to link github accounts, we'll take it from there
- if that project does not have a SECURITY.md make an issue asking the dev to list one
IF YOU ARE TECHNICAL:
- If you are a maintainer or contributor to a project, I may have already scanned your repo, hit me up I'll share the results, if not I'll add your project to the list.
- If I can trust you to do larger review to start looking through this stuff to give me more eyes let me know.
AI Has forever changed software development. Tomorrow marks 1 week of Kimi k3 being live in open weights.
We are going to accelerate.
Absolutely devastated for anyone impacted by the @COLDCARDwallet entropy exploit.
I recommended Coldcard devices as a solid hardware wallet option in my videos and to consulting clients for years, and while I always recommended user-generated entropy w/ 100+ dice rolls as the gold standard for seed generation (and multisig especially for larger amounts), it’s unfortunately a very difficult bar to achieve especially for users just starting out.
If you still have any bitcoin on Coldcard devices where you are not absolutely certain of the robustness of your user-generated entropy, move it immediately even if it’s temporarily to a trusted centralized exchange.
As users contemplate improved self-custody setups, multi-vendor multisig with devices like @FoundationHQ, @Trezor, and @Blockstream have to be the answer even for more modest amounts. These co-signing devices can be coordinated by software like @SparrowWallet or as part of a collaborative custody setup like with @CasaHODL. @Bitkey is also a compelling, user-friendly option.
I have multisig videos on my channel (do NOT use Coldcard devices as part of these setups) as do @BTCsessions and others.
Take some time to understand the pros/cons of these options.
As @lucasdcf said, one of the more humbling aspects of all this is that this vulnerability existed without detection for as long as it did. For a community that espouses “don’t trust, verify” this experience is tough to swallow, and I’m glad to see the mobilization across teams in the space using frontier AI models to pressure test security-critical projects (and props to teams that were already doing this).
Even for someone as arrogant and mocking as @nvk, I would not wish this burden of responsibility on anyone. While chances of recovery may be remote, be sure to keep your Coldcard devices as part of any law enforcement follow-ups that may come out of this.
This is a massive blow to self-custody, one of the essential elements of Bitcoin and self-sovereignty. The community will recover, but things will take time. Be supportive of each other, offer to help friends and family. Feel free to DM me if you think I can be helpful.
I will post a blog article later today. But TLDR:
- it's worse than you think.
- Mk4, MK5, Q will get drained.
- multisig of Coldcard devices, or multisig where Coldcard signatures are sufficient to reach the threshold are at risk.
- MINISCRIPT WALLETS are ALSO at risk, if you use Coldcards where only CC signatures are enough to spend, or to recover.
No need to panic, but time to plan a move to new mnemonics/devices in the next few days, if you used a Coldcard in your setup.
Today, Mastercard is announcing plans to expand settlement capabilities to include stablecoin, intraday, holiday, and weekend options, giving partners more choice in how and when transactions are settled. That means we’re:
✅ Enabling greater choice to settle in fiat or regulated stablecoins
✅ Improving liquidity management for time sensitive, cross border flows
We’re supporting settlement with @Circle’s USDC, @Paxos-issued stablecoins including USDG,USDP and @PayPal’s PYUSD, @Ripple’s RLUSD and @SoFi’s SoFiUSD across a range of supported blockchain networks including Arbitrum, @Coinbase’s Base, @CantonNetwork’s Canton, Ethereum, @0xPolygon, @Solana, @Tempo and XRPL. ARQ Finance, CBW Bank, @crossriverbank, @Lead_Bank and @Nuvei will be among the first to support.