I write about security, crypto custody, on-chain finance, Bitcoin, AI agents.
I’ve built custody/key-management systems using MPC, TEEs, policy engines, and institutional wallet infrastructure.
Most crypto losses are not cryptographic failures — they’re product, policy, and operational failures.
@Lahannin A couple of things I'd push back on:
1) memorable passphrase - this makes it guessable via dict/rainbow attack, dice words is better with 6 random words
2) storing passphrase in a strongly protected password manager is a defendable choice
@MindfulArrow@Trezor unless you have Coldcard without Dice and without passphrase, the biggest risk right now is acting out of panic and making a mistake
@punk4307 Your keys on coldcard didn't have sufficient entropy, meaning guessable by the attacker. It has nothing to do with device being offline or Wasabi. Sorry for your loss, it's not your fault and this hack is very unfortunate.
But for future, look into entropy,passphrase,dice rolling
@brucefenton funny enough, closed source code would've prevented this from happening, security by obscurity is a thing and it does work. Open source software in itself is a good thing, but it's not religiously good and needs to be thought of in full context.
@Trezor Q to Trezor. If the 24 word seed was generated on Gen 1 trezor device and kept being imported to new devices, is it still safe? It comes down to 2 sources of entropy still being enoug, right?
@KyrosQF@cryptomanran yeah, it would probably only happen on a wick...
I think there will be a lot of demand for STRC as RWA on-chain, similar to how people do ETH looping, they'll loop STRC.