Who benefits from the Coldcard hack?
The Financial Industrial Complex does.
We took a hit.
We mourn the loss of those affected.
We come back stronger.
If we don’t self-custody and run nodes, we end up with BlackRockCoin in a Coinbase collateralised debt obligation.
피해는 진행되고 있지만 상당�� 큰 이슈였고,
심약한 초보 셀커인은
그냥 거래소로 돌아갈까 하는 것을
많이들 고민했을 듯
포기하지 말고 이 참에 보안 공부를 하고,
좀 더 개인주권을 챙기는 계기가 되었으면.
Don’t trust, verify는 그걸 외치며 스티커나눠주는
그 회사에게도 해당되는 말임
I am very annoyed with @nunchuk_io for not disclosing sooner that their platform keys were generated with Coldcards.
HW wallet variety is crucial when setting up a multisig and every Nunchuk user has an extra Coldcard on their multisig that they prob didn't know about.
@Bitcoin_Murern@LukeDashjr Parkinson's tremors remain constant at a frequency of 4-6Hz. Therefore, they do not appear to contribute to an increase in entropy.
"I'm scared there's no safe place for my bitcoin."
Security is not a binary attribute. You are always making trade-offs between convenience of your own access & inconvenience of unauthorized access.
The only perfectly secure BTC is that which you send to an unspendable script.
결국 기초를 제대로 못 다지�� 무너진다.
비트코인에서 가장 중요한 것은
충분히 높은 엔트로피로 시드를 만들고,
기술을 좀 더 닦고 (패프,멀티)
그것을 절대 노출하지 않으며,
내 노드로 브로드캐스팅하는 것.
여기서 하나라도 빠지면
OG고 뭐고 ㅈ도 아닌 놈임
그 외 나머지는 전부 +@
Serious question. If Coldcard’s RNG was silently bypassed for years due to a firmware/build bug, what’s stopping the same class of subtle entropy failures from existing in other hardware signing devices (Trezor, Ledger, BitBox, Jade, etc.)?
Are we just assuming their TRNG + mixing designs are solid because nothing has blown up yet, or has anyone actually audited the equivalent code paths?
The first post was the advisory and what users should do.
This second post has the technical details: what actually went wrong, why our reviews missed it, the impact across Mk3/Mk4/Q/Mk5, and what we changed.
https://t.co/HshUxevCl3
( current evaluating Mk3 firmware release )
The first post was the advisory and what users should do.
This second post has the technical details: what actually went wrong, why our reviews missed it, the impact across Mk3/Mk4/Q/Mk5, and what we changed.
https://t.co/HshUxevCl3
( current evaluating Mk3 firmware release )