📢 Excited to share my latest project - 'Bijli,' a non-custodial Bitcoin Lightning Wallet ⚡️built with Flutter & LDK (@lightningdevkit)! I've been working on this project during weekends for months, and I'm thrilled to show you a quick demo.
https://t.co/7wXIw468Hl
#Bitcoin
Breath. Bitcoin will always be under attack. They didn't even start the real "then the fight us" phase (illegal status in most jurisdictions, arrests of people promoting it without collateral pretexts, appstore bans, attacks on mining farms to produce empty blocks, restriction on general use hardware, ban on main github repos, etc.). For now we just see an extreme focus of cybersec attacks on our sovereign stack. Bugs that were always there are being found and exploited. But they were there, so it was a matter of time. We have to fix them, full stop. Even if the Lightning Network will be marginally disrupted, the way it's built will allow us to always rebuilt it antifragile-style. In this specific case the Lightning Network is not (yet) under attack, it's currently only LND on BTCPay.
I’m honest enough to admit this…
The only reason I ever bought coldcards was because I wanted to be part of the maxi cool kids club.
That is an incredibly cringe and stupid reason for using any security product.
Let alone a bitcoin wallet.
- NVK deserves this
- Coldcard users do not deserve this
- Move the funds and throw CC in the trash
- Never think about suicide, even if you lost money
I never lost money in such incidents but lost a significant amount on bitmex in 2017. Took years to recover.
Life goes on.
I don't really understand why firmware updates and all thsi drama.
Just tell: If you've any hww product from coldcard take those menmonics, restore it on sparrow or blue, create a fresh new wallet in blueor sparrow and send max from the cc exploit restored wallet to this new wal
🚨 NOTICE: Claims that current firmware permanently bricks COLDCARD devices are incorrect.
If this TRNG fault occurs, power-cycle it: fully remove all power, then restart.
The state is volatile, nothing is written to flash, and it fails closed. Fix:
https://t.co/hV7nrBMn0U
@americanhodl8 all this was marketing tactics of coinkite, so that the noobs can feel like maxis & cypherpunk whereas the real story is that they fucked up from the basis
I believe we’re entering Bitcoin’s Middle Age.
When it announced Project Glasswing, Anthropic was right. It admitted it had built a model powerful enough to destabilize the world. Fable was then released but with guardrails.
Then Chinese labs shipped open-weights models with similar capabilities. And the Bitcoin apocalypse began (not of Bitcoin the protocol but of the stuff built on top of it).
I fully agree with @giacomozucco here. I started following Bitcoin in late 2016, and I also believe this is the worst bear market ever - because the attacks of the last few days are dragging the entire sector back to its fundamentals: the on-chain protocol.
Look at what is happening: a human negligence in Coldcard's firmware, ignored for five years, was exposed in hours.
@Boltzhq stated its swaps are being bombarded by AI-driven attacks (https://t.co/gxCTY30LUM) and disabled the service. With it, many Lightning services are cooked. The first real casualty of this new AI era is the open-source code of the services built on top of Bitcoin.
I may be wrong, but we are losing the AI race and I think we’ll continue losing it.
The AI race is won by whoever has more money, more funding, more capacity to pay for frontier-model tokens: whether attacker or defender. And the Bitcoin world is still a niche: an asset worth less than 2 trillion dollars, in a world where single companies are worth more, let alone state or para-state organizations willing to attack open-source software. When those players attack, they can pay for orders of magnitude more tokens than the defenders (the companies and contributors maintaining Bitcoin's open-source tools). Defenders are outnumbered and outspent.
I believe this trend will continue. I believe we are entering Bitcoin's Middle Age: everything we have been talking about in recent years (stablecoins on Bitcoin, swaps, new protocols, ecash, RWA) will not materialize for a long time. All these implementations will be the most vulnerable, because their AI-defense funding cannot match the AI-attack budgets of their enemies.
I believe we’ll go back to the origins: on-chain Bitcoin, saving, store of value, spending with solid LSPs. For a long time.
This is not necessarily a bad thing. The fiat world will keep inflating probably even faster, as state-driven attackers print more and more to attack everything tied to individual freedom, everything that helps people escape the state cage.
Bitcoin is antifragile, censorship-resistant, made to thrive in hostile environments.
Bitcoin will remain the asset of the resistance and it will become ever more fundamental for individual freedom, in a world where AI centralizes the power to enforce rules even further. Because AI hands more power to whoever already holds financial power, and today that means big financial institutions and states. Bitcoin is the only force pointing in the opposite direction.
So whatever happens in the coming weeks and months: do not despair.
Stay strong. Self-custody is the only hope for your freedom.
Dear podcasters & influencers,
Don't feel bad for not looking at the firmware, it's absurd to expect that from non-hardcore technical people, when even the hardcore ones did not look.
Don't feel bad for recommending the ColdCard to people, you were told by multiple people this is a solid product, you operated under the assumption that "smart" people are honest and did their due diligence.
Don't feel bad because you got paid to shill ColdCard, that is an honest business deal, nothing wrong with sponsorships.
What you should absolutely feel bad and guilty about is whenever you saw nvk doing shitty things and you turned your head around, because you thought he will stop sponsoring you, it may affect your chance of getting a grant, or the wider group will think you are not one of the cool kids for talking back at nvk.
Or whenever someone brought a criticism to nvk and you joined in discrediting that person or making stupid comments to signal your alliance to nvk, instead of at least saying hey maybe he has a point.
If you did this, you were a coward and you have directly contributed to people losing money.
This is NOT a RNG, self-custody or AI failure.
This was a lack of scrutiny on very IMPORTANT piece of software that does VERY sensitive operations.
Every time anyone tried to poke at ColdCard or even just ask questions nvk would always dismiss them, call it FUD and attack their character.
Nvm the absolute abysmal attitude he had against competitor, who now still acted like gentlemen despite this generational dunking opportunity.
Everything someone did to push scrutiny away from this project has directly contributed to this disaster.
Bitcoin transactions are irreversible, and you can't change the past, so no point in beating yourself over it, at the end of the day there is not 1 single person that did this, it was pretty much everyone.
The one thing you can do that will have a positive impact forward, is to tell the truth and when you see someone not doing that, make sure to point it out.
If you read this and decide to go after people who promoted CC you are a dickless loser, and are only going to make this very mad crisis even worse.
We can't start yelling at each other in a few weeks, when we won't have anything to talk about anyway.
None of my engineer friends have CC. I had no idea CC had so many users. I'm afraid the most vulnerable to CC were those listening to influencers instead of engineers. NVK had antagonized engineers years ago which didn't help a white hat to be able to find this before black hats.
Back then I did a small writeup on "Does Secure Element Even Matter in Hardware Wallets?" I shared it with some of the best knowledgeable bitcoiners that in the @studentofbtc group, but never ended up publishing it. Given the recent discussions, here it is https://t.co/Eg8prLnhJy
While developing cryobrick, I became skeptical of building a hww without a secure element. Since I lack expertise in security reviews, pentesting, and hardware security, I didn't feel comfortable continuing the project and eventually left it. I did my best with cryobrick (1/2)
🔒 CryoBrick is safe & unaffected by recent wallet bugs! We use standard software CSPRNG via device-level system entropy to generate unique 128-bit keys.
"System noise" means your phone captures random, microscopic clock-cycle timing variations between background tasks.
I cannot stop thinking about the crime of negligence that the @COLDCARDwallet team committed against some true bitcoiners.
These bitcoiners set themselves up between 2021 and 2023, a brutal time in the market, a time that needed real conviction. Conviction that was tested time and time again through the crypto scams, and now they were let down by trusting what was supposed to be one of the industry’s leading hard wallet providers.
It’s really heartbreaking.
The team behind cold wallet need to do everything in their power to make the victims of their negligence whole.