@cguida6@LukeDashjr PoW change is the nuclear option.
17.000 nodes are enforcing #BIP110 so let's keep calm and hold the line even in case of initial low signaling.
Get prepared! ๐ช๐ป๐ช๐ป๐ช๐ป
@cguida6@LukeDashjr PoW change is the nuclear option.
17.000 nodes are enforcing #BIP110 so let's keep calm and hold the line even in case of initial low signaling.
Get prepared! ๐ช๐ป๐ช๐ป๐ช๐ป
๐จBREAKING๐จ You guys... @BitcoinKnots v29+RDTS is now the number #1 ๐ฅ bitcoin node client software version among @LukeDashjr's census of Bitcoin nodes! This just happened. ๐ฅ๐๐ฏ Keep doing what you're doing, don't stop. #BIP-110.
๐จBREAKING๐จ You guys... @BitcoinKnots v29+RDTS is now the number #1 ๐ฅ bitcoin node client software version among @LukeDashjr's census of Bitcoin nodes! This just happened. ๐ฅ๐๐ฏ Keep doing what you're doing, don't stop. #BIP-110.
BIP-110 mandatory signaling is days away.
38 / 1430 blocks signaling (2.7%).
Need 1109/2016 for early lock-in.
~587 blocks until mandatory.
We already knew miner support would be weak. That was never the point.
People keep confusing who actually decides the rules of Bitcoin.
Miners produce blocks.
Node runners enforce consensus.
This is decentralized by design. The protocol itself gave us the tools (version bits + mandatory signaling window). We are using them.
Node runners are putting things back in their proper place.
Run Knots. Enforce the rules. Donโt Trust. Verify.
#BIP110 #BitcoinKnots
IMPORTANT UPDATE
WE HAVE CONFIRMATION FUNDS ARE STILL BEING RECOVERED ON NO PASSPHRASE MK3 DEVICES.
THERE IS HOPE FOR RECOVERY IF YOU ACT FAST
MK4S WITH SHORT PASS PHRASES ARE BEING SWEPT
NO ONE IS SAFE ACT NOW
GET YOUR BITCOIN OFF COLD CARDS
Let's speak the truth. It's not self-custody nor @Coldcard users that failed but only @Coinkite disastrously.
The @Coldcard is the only wallet having a low entropy issue. ๐๐๐
Thanks to a generous credit of tokens from @PPQdotAI , Kimi K3 and an ape with a laptop (me) have conducted the following analysis of a bunch of projects / companies wallet softwares. @Coinkite , @OPENDIME , @SeedSigner , @Bitkey , @bluewalletio , @PhoenixWallet , @SparrowWallet , @Trezor , @Blockstream , @Ledger , @BitBoxSwiss , @SpecterDIY , @ElectrumWallet , @SamouraiWallet
๐ก Yellow โ broken. None of the nine Yellow products has a confirmed fund-loss-by-default flaw. Yellow means at least one of: (a) something security-critical sits outside independent verification. i.e., closed firmware or secure-element code (Opendime, Ledger, open source please!), vendor-run recovery infrastructure (Phoenix/ACINQ, Jade's oracle, Bitkey's WSM); (b) a real but bounded weakness, such as a zero-work-factor KDF (BlueWallet), weak legacy KDFs on a hot wallet (Electrum), no-SE DIY hardware with thin maintenance (SpecterDIY), a just-patched vulnerability awaiting its report (Bitkey); or (c) a dead/unmaintained product whose crypto reviewed clean (free Samourai!). In every case the entropy/key-generation path itself was reviewed and found sound unless the cell says otherwise.
None of my engineer friends have CC. I had no idea CC had so many users. I'm afraid the most vulnerable to CC were those listening to influencers instead of engineers. NVK had antagonized engineers years ago which didn't help a white hat to be able to find this before black hats.
Confirmed #COLDCARD bricked ๐
A rushed firmware hotfix introduced a critical failure: a transient STM32 TRNG error could permanently fault the RNG. Since itโs used before the PIN screen, affected devices to become effectively bricked.
https://t.co/qloYvCygAm
@BTCsessions 2 of 3 multisig with seeds created with @SeedSigner , @SpecterDIY and bitcoinlib running on a Raspberry/laptop always offline device.
It requires some technical skills but all of the three are dyi open source projects I would trust the most.
@4nt1b110@wtogami So It would be a mouse and cat game between the attacker and the victim, wouldn't It?
And what about the multisig case disbling RBF should mitigate?
If the miner pools disabled RBF, would that prevent an attacker from RBF a transaction from a vulnerabile multisig address?