💫Had a wonderful chat with @freeborn_farmerr about healing after great loss, why the Coldcard incident was a gift in disguise, and why he believes knowing your local farmer matters as much as self custody.
Full Episode: https://t.co/QtBMXxp4Rm
✨ Had a wonderful chat with @JeffBoothh about whether Bitcoin is still decentralized and secure, and whether he thinks it’s been captured.
Jeff is one of the people I trust most in Bitcoin, and some BIP110 supporters may not agree with his perspective. Jeff sees Bitcoin
A hardware wallet is not a security posture. Neither is a titanium backup, a passphrase, or multisig.
They are components.
Security posture is what holds them together and checks the assumptions that can still make the whole system fail. https://t.co/Ajos9TJQNl
🌎 Had a wonderful chat with Myriel, author of The Cosmic Whitepaper, about how burnout led her to Bitcoin, why Bitcoin is on its evolutionary journey like humanity, and how the cosmos can help guide us all.
"I feel more at home on Nostr." ✨
I keep hearing “ Bitcoin is captured!”
I don’t know, I don’t feel Bitcoin is anymore captured than it was 4 years ago.
All of this was inevitable.
It started well before Knots and BIPs.
You allowed the narrative of Bitcoin to become almost exclusively SOV.
The lesson here should be less about Bitcoin being captured and more about how Bitcoin is used as a MOE…because blocks are empty and as much as you feel passionately about limiting spam…you simply are not using it as a MOE.
The problem is simpler than what’s being disputed.
🔖Such a great article, Simon, expressing many of the ideas I share. I really appreciate your work. This is the line that especially hit me:
"Bitcoin structurally makes changing consensus harder than defending consensus. The mechanism that prevented the change I supported
⚡️Had a great chat with co-founder of about how Bitcoin saved his family, why he's on a mission to orange pill others with, the Coldcard hack, A.I. how the dollar's collapse hits the Midwest hardest and more...
Shoutouts
While contemplating life and Bitcoin by the ocean today, I concluded:
No one seems to have all the answers. I certainly don’t.
BIP110 didn’t go as planned. I never said it would pass. I simply believed in the message behind it, while others didn’t. Consensus won. I respect that
🌍From a cosmic perspective Myriel says, "Is Bitcoin going to remain a monetary layer, or does it go beyond?"
That is the question. In the meantime, remain calm and be kind to each other. Here is her substack:
Bitcoin Knots vs Core: A Karmic Decision
🙏 Honored to be featured on latest video for my interview with of . Matt Hill and Matt Kratter are both outstanding teachers for all of us, especially non techy Bitcoiners 🧡
Beautifully said Elizabeth. I love the reminder to value kindness, humility, and sovereignty while remembering that Bitcoin is peer to peer and we still need each other. 🧡⚡️
Intimately familiar with unexpected loss, I recognize the weight many in the Bitcoin community are carrying. The following article is my reflection on what creation asks of us, the value of open collaboration, and how we steward freedom tech. https://t.co/2oKpmWAxWc
Had an interesting chat with @MattHill about the Coldcard breach and why he calls it "unforgivable negligence. We then discuss the controversial BIP110 proposal, the potential soft fork, what he thinks could happen if it isn't accepted, and why he believes chaos could follow.
I find this division among Bitcoiners due to BIP110 both interesting and upsetting. It feels a bit like left vs right in politics, except that most people on both sides ultimately want Bitcoin to succeed. They just disagree on the best way to get there.
In retrospect, BIP-110 didn’t fail because of the proposal. It failed because of the people leading the conversation around it, like Luke, Matt, Justin Bitchler and the like. The hypocrisy, censorship, and tribalism did more damage than any technical criticism ever could.
Join me AND @PaulaBTCEdge as we discuss the latest news in Bitcoin and how the Bitcoin protocol helps to diminish broken incentives. She was my first guest and I would love to have her back on the show for a future episode. Thanks again, Paula!
https://t.co/wzBuXujIa6
🌞Woke up thinking about Bitcoin and self custody again.
“Don’t trust, verify” has been haunting me. The reality is that many of us still have to trust wallet makers, exchanges, and Bitcoin companies.
My heart goes out to everyone who had their Bitcoin stolen.
My heart goes out to everyone who did everything right and still lost their Bitcoin. My heart especially breaks for those who lost life changing amounts.
We don't have control over much in life, but we do have control over how we respond. As heartbreaking as this is.
$1.6 million dollars in Bitcoin was drained from my account on July 29th in the Cold Card wallet hack.
My Bitcoin was in cold storage. My keys were on a ColdCard device kept in a safety deposit box that had never been connected to the internet.
This part's nerdy, but here's what happened:
Hackers discovered a vulnerability in the part of the hardware wallet code used to create seed phrases.
This allowed them to use AI to brute force guessing seed phrases.
I was at our cottage and heard about the hack today.
"No way this affects me." I thought.
I logged into Wasabi––software that lets me view my bitcoin wallets online.
Right away I saw lines of red transaction–withdrawals–and I knew.
From 9:36pm - 9:43pm on July 29th, every wallet I had had been emptied.
18.25245043 btc gone. That's just over $1.6 million dollars CAD.
Perhaps the hardest part about this is that I did everything right.
I never shared my seed phrase with anybody. My devices never touched the internet. Everything was kept in multiple safes and safety deposit boxes.
None of it mattered. All because the hardware that created the seed phrase originally had one line in their code from 2021 that had a vulnerability.
I'm filing a police report and a report with the Ontario Securities Commission. But I don't expect to recoup anything.
A part of me is trying to make sense of what just happened. Or try to figure out a lesson in it. I'm struggling. $1.6 million is a staggering amount of money to have stolen.
I guess all that I can think about right now is that I'm so damn happy that I'm an entrepreneur and that my earning potential is under my control. Mark my damn words. I'll recover.
Check out these two Bitcoin seed phrases:
(a general lesson in entropy)
SEED A:
ocean tiger silver dance pigeon melody crystal rocket amber jungle violin sunset.
Now check out this one:
SEED B:
garden mirror silent canyon river melody crystal rocket amber jungle violin sunset
They both look random to me.
But this is the issue that has unfortunately happened with the Coldcard wallet bug.
It's random generator didn't give sufficient randomness.
You can't tell the two phrases apart if you use the device to give you your words.
You get them. You write them down. Stamp them in steel. Done.
All proper 12-word BIP-39 seed phrases starts with 128 bits of high-quality randomness (entropy).
And most devices have a TRNG (True Random Number Generator).
If that TRNG is flawed or has a bug, the device doesn't produce the full 128 bits of real entropy (or 256 bits for a 24-word seed phrase).
SEED A above was generated with 128 bits of entropy.
SEED B, however, was generated with only 40 bits of entropy.
Again, so what? Doesn't someone still have to guess those 12 words?
With only 40 bits of entropy, a skilled attacker could download the entire possibilities of those seed words, which is about 1.1 trillion.
Although large, that's small enough to run a program, extract every possibility, and begin taking funds from wallets with balances.
This is the bug/attack that struck Coinkite with their Coldcark MK3 generated seeds (using firmware 4.0.1 and later).
You cannot spot the problem just by looking at the words👀
SEED A above has the full 128 bit entropy, and thus gives 340 undecillion combinations.
This number can't be brute forced with any computing power currently available to man.
The fix?
Roll your own words for true, full randomness you can see and verify. Add a passphrase (a 13th "word") to increase that randomness. And don't let those words touch the internet.
But still... look into multi-sig. It really solves so many problems that we've had and continue to have.
⚡️Had a wonderful chat with about losing access to his early Bitcoin, why the desire for agency and self responsibility led him to live on a Bitcoin standard, and why Bitcoiners should spend more time building than fighting.
Rules without rulers.
Rules create consensus. Consensus emerges when independent nodes enforce the same rules.
I'll be interviewing @MattHilll, founder of @start9labss, on The Bitcoin Edge to discuss these ideas and the Core vs. Knots debate.
What questions should I ask him?
@_MattHill_ and @start9labs will go down in history as true heroes in the story of Bitcoin as a monetary protocol, that defeated all those who would seek to destroy it. Thank you!!!