Sometimes I pause and reflect on the fact that my entire financial portfolio is currently composed of 1) an imaginary Internet ponzi coin and 2) the stock of a company famous for having the largest peak-to-trough drawdown in the history of financial market bubbles, and whose CEO is currently leveraged to the tits on the same Internet Ponzi coin (which he refers to as “the goddess of truth”), and that I consider this a sound financial strategy with a virtually 100% chance of retiring my bloodline.
Some thoughts on the Coldcard vulnerability:
This wasn’t an impossible AI super-hack. It appears to have been a BASIC coding error.
Like MANY Bitcoiners, I don’t have the background to personally audit every line of firmware on every device I use.
My heuristic has always been: the code is open source, and so many people who are insane autist coders and paranoid lunatics - as well as sophisticated teams of security-obsessed people at platforms like Casa, and Unchained recommend a device - it’s probably been thoroughly vetted.
Apparently that heuristic failed.
NVK and the Coldcard team deserve the most scrutiny, but this should be a wake-up call: open source doesn’t magically mean audited, and trust by reputation isn’t a replacement for formal and attested security review.
I also want to point out that this is why qualified custodians hold on behalf of corporations like $MSTR or ETFs and it would retarded and risky for them to do this themselves.
Independent, accountable, sophisticated review by teams of employed experts matters.
People who have never lost anyone’s bitcoin:
Michael Saylor, Brian Armstrong
People the plebs hate:
Michael Saylor, Brian Armstrong
Consider that the plebs are not serious people.
While there is a kernel of truth in some of their narratives, the extremism and Puritanism seen in certain corners of the plebslop podcast-sphere, was, like everything else in life, driven by incentives to sell you products.
Products like hardware wallets, collaborative custody services, bitcoin-only exchanges, home nodes, cases for home nodes, home mining rigs, books, podcasts (ad revenue) etc.
Be skeptical of everything and everyone.
Nobody is pure, and while it is fair to disagree with specific actions (Brian putting shitcoins alongside Bitcoin is imo a very bad thing, but Coinbase has a stellar safety record and has overall been a good thing for Bitcoin) insisting that a certain class of people are impure or bad for Bitcoin or whatever because they have a different vision for Bitcoin than you do is psy-opping yourself.
People holding $MSTR stock or who have left their coins on Coinbase since 2014 are sleeping soundly tonight. Are you?
many people will respond to this hack by abandoning their @COLDCARDwallet which is not irrational
but an alternative interpretation is that all RNG implementations are a risk. (I have no doubt that hackers all around the world are actively looking at every old HWW for similar exploits)
and in the event that another such exploit is found, your safest option may be to reboot that coldcard, as painful as that may be, and roll some dice
Totally justified from casa.
I read a great write up on single points of failure by @lopp and the @CasaHODL team early in my bitcoin journey that convinced me 2-of-3 collaborative custody multisig using different HWW vendors was the only way to go, and frankly I was shocked that people would keep any more than $10,000 or so on any solution with any single point of failure (including myself). Similar write ups have been written by the @unchained team.
Over the years I have advocated for this, and been called stupid by people who thought single sig + passphrase was superior.
But in the event of a seed generation entropy failure, your coins are now secured only by the entropy of your passphrase, and the only passphrase with sufficient entropy would be equivalent to a second seed phrase - which is more cleanly done with multisig. Second, a passphrase is not immune to a HWW manufacturer compromise or a supply chain attack.
The reality is that CC was the brand marketed and perceived by most as “the safest single option.”
This has proven the multi-sig advocates core claim that no single option is ever reliable. You simply don’t know what you don’t know.
Those with a CC mk3 in a multisig setup can now swap out that key and go on with their lives knowing that they remained protected by the entropy of seeds generated by two other methods (their second HWW and the collaborative provider).
Of course, it is not impossible that one of those other methods will prove unreliable in time, but it is exceptionally unlikely that two different zero day vulnerabilities are discovered in different platforms simultaneously and prompt swapping of the vulnerable key protects you against any subsequent failure.
As a cofounder of Casa, a product we built to prevent/solve this exact Coldcard vulnerabity, it is a weird situation to want to help people by selling them our product right now (and I experience the same hesitation in exchange meltdown situations).
People are understandably saying that it's wrong to be shilling your product when people are losing their money. And I certainly feel that myself...I don't want to "take advantage" of people in an emergency situation.
But on the other hand, imagine people are on a sinking ship. I built a life raft over the last 8 years that is perfectly crafted for this exact moment. Should I not offer them the life raft? I legitimately want to help people not lose their money and that is exactly why we built Casa.
https://t.co/RfiJHBPAJH
@zherbert@COLDCARDwallet It was a hard post to write, but it is also true that a dice roll seed generated on a cold card is likely more secure than an RNG code generated on any other device, and many do not offer a robust dice roll entropy integration.
it’s one thing to use hardware as an end user, but incorporating key generation from external hardware into your product without (1) disclosing it and (2) doing your due diligence on their derivation, is inexcusable.
I am very annoyed with @nunchuk_io for not disclosing sooner that their platform keys were generated with Coldcards.
HW wallet variety is crucial when setting up a multisig and every Nunchuk user has an extra Coldcard on their multisig that they prob didn't know about.
CHAINALYSIS: ATTACKER TARGETED LARGEST COLDCARD WALLETS FIRST, BLOCK SAYS INVESTIGATION TRACED SWEEPER’S WORKFLOW
Chainalysis says analysis of the $38M+ Coldcard exploit shows the attacker deliberately targeted the highest-value wallets first, including one holding $1.8 million, suggesting victims were profiled before the sweep began.
Roughly $30 million was stolen within the first 10 minutes before about 500 wallets were drained over 25 minutes.
Block’s Clay Garrett said investigators also confirmed the attacker used a paid account with a well-known blockchain services provider to query victim addresses during the operation.
The provider’s internal logs matched the timing and sequence of requests, but Block said it found no evidence the company knowingly assisted the theft.
Relevant information has been shared with authorities.
This post is direct at those who relentlessly criticized people (“not true bitcoiners”) for making other choices (ETFs, or example, or just holding BTC on Coinbase) that would have protected them. The ethos of Bitcoin is you should use it in whatever way is best for you, and self custody isn’t the best way for many people.
If you were worried about Saylor and Blackrock not showing proof of reserves / holding paper bitcoin, or using a collaborative multi-sig because it used kyc, so instead you kept all of your Bitcoin safe and sound on a coldcard, you might be a pleb.
ironically your one and only hope in a white hat recovery scenario is having used your coldcard to send coins to or receive coins from a kyc exchange that can attest to you having held the keys prior to the vulnerability being known
@nic_carter@BenJustman the only way you can 100% quantum proof your coins is to lose them all before quantum computers are developed. so, in a way, he solved the problem.