New @FREOPP: Our paper on how to end the cycle of tuition hikes and student loan bailouts, and actually reduce the cost of higher education, building on reforms in the One Big Beautiful Bill Act.
Taxpayers spend $150 billion per year on student financial aid. A quarter of that debt will never be repaid, and it's taxpayers rather than the colleges who will absorb the loss.
@Avik and @JustinWStapley outline how Congress can implement accountability: https://t.co/4h3ZMSYJ3f
I have spent over $10,000 scanning 100+ bitcoin ecosystem related libraries looking for vulnerabilities with Kimi K3 running as quarterback.
Myself and a small "Red Team" have found multiple serious vulnerabilities impacting the ecosystem. They vary in scope severity, but this is a call to action.
For any critical tier vulnerability that was identified if I was able to immediately demonstrate a POC (proof of concept), I have already responsibly disclosed to the maintainers.
HERE IS HOW YOU CAN HELP ME
IF YOU ARE NOT TECHNICAL:
- please share with me any repository that is on github that I can scan, we want to cast a wide net. It takes a few moments for you to link github accounts, we'll take it from there
- if that project does not have a SECURITY.md make an issue asking the dev to list one
IF YOU ARE TECHNICAL:
- If you are a maintainer or contributor to a project, I may have already scanned your repo, hit me up I'll share the results, if not I'll add your project to the list.
- If I can trust you to do larger review to start looking through this stuff to give me more eyes let me know.
AI Has forever changed software development. Tomorrow marks 1 week of Kimi k3 being live in open weights.
We are going to accelerate.
But there are silver linings to the @COLDCARDwallet tragedy. (1) every other hardware wallet manufacturer is using frontier AI to audit their codebase if they weren’t already. (2) more ppl now appreciate the value of multi-sig. (3) the era of judgy moralizing Puritanism is over.
Remember, when you buy a hardware wallet, always:
1. Download the firmware binary
2. Disassemble and review bootloader code, cryptographic routies, and pin entry logic
3. Trace the call stack
4. Search for hardcoded keys, memory safety bugs, and logic flaws
5. Check secure boot enforcement and firmware signature checks
6. Review build configs & linker files
7. Perform a black-box entropy sampling analysis
8. Verify how it handles corrupted inputs or invalid states
9. Flip off Saylor cuz you're a real Bitcoiner, bruv
“I have spent close to $5k on LLM tokens over the past 24 hours scanning over a hundred bitcoin related repositories. As of now, I have seen no vulnerability that has me concerned about any hardware device outside of the Cold Cards.”
Amazing work from Rob and sound advice here
@sesi_the_man@SeedSigner@BTCsessions@ODELLXYZ@rabbitholerecap@COLDCARDwallet@MartyBent@nvk "Ten31 (...) proud investors in Coinkite. The only external investor in Coinkite. ColdCard has a dice roll feature. When you create a new seed, you can choose (...). If you choose the dice roll feature, that's like for advanced users only, don't (...) just don't do that" - Odell.
@L0laL33tz@nvk https://t.co/Bvykw32i2b’s home page is *far* from what it should look like given what just happened. They’re making the bare minimum effort.
There is value in making #bitcoin multi-sig more accessible to normies, as @Bitkey and @CasaHODL try to do. But @PeterMcCormack is 100% right. Most normies aren’t there, and won’t get there unless they lose trust in normie brokerage accounts.
Bitcoin will never scale if:
1. Everyone is meant to verify code
2. Everyone is meant to run a node
3. Everyone is meant to know what an XPub is
I've said this all the time - maxis scream at me, I am still right, they are still wrong. They are out of touch with normal people.
I know some of you are like, well I did it, don't trust verify - well done nerd, but you are a tiny tiny minority.
Sure there will be a hardcore group who will do all this, the nerds that keep the system honest.
Normal people will keep on exchanges, use ETFs, sometimes single sig.
If you get someone to multi-sig, well done, it will be rare, but well done. Many will just trust well structured institutional products.
Cry as much as you like, I was right before and I am still right.
JUST IN: Dustin Dettmer (@dusty_daemon) digs into the COLDCARD firmware commit history to uncover what actually happened in the code to introduce one of the worst bugs for self-custody in recent bitcoin history
https://t.co/PhaNZS23Lt