@KeystoneWallet During the recent website/firmware incident, what security boundary failed, what security boundary continued to protect users, and what changes have you implemented to ensure a similar incident cannot occur again?
@Bitkey@BEN0WHERE
Bitkey Security Review – Questions for the Bitkey Team
My goal is to understand whether Bitkey is an appropriate solution for securing a substantial long-term Bitcoin holding. These questions are intended to clarify the security model, trust assumptions, and long-term resilience of the platform.
1. Security Model
Can you describe Bitkey's complete trust model?
What components must I trust, and what components are trust-minimized?
Which assumptions are fundamental to Bitkey's security?
2. Phone Security
The phone appears to be the most exposed component of the system.
If an attacker gains complete control of my unlocked phone, exactly what actions can they perform?
Which actions are impossible without the Bitkey hardware device?
Under what circumstances can the server co-sign with only the phone?
How does Bitkey distinguish between a legitimate user and malware operating on a compromised phone?
What safeguards prevent a compromised phone from escalating its privileges?
3. Spending Limits
The daily spending limit appears to be an important security feature.
How is the daily spending limit technically enforced?
Does it apply to every transaction that does not involve the hardware device?
Can the spending limit be changed from a compromised phone?
What approvals are required to increase, remove, or disable the limit?
Can a compromised phone perform multiple transactions up to the daily limit before the owner has time to respond?
4. Recovery
If my phone is compromised:
What is the recommended recovery procedure?
Can I immediately replace the compromised phone and restore my wallet?
Can I sweep all funds into a newly created Bitkey wallet using the remaining secure signing path?
Does recovery require any trust assumptions beyond those already documented?
5. Firmware and Hardware
How are firmware updates authenticated?
Where are the firmware signing keys stored and protected?
Are firmware builds reproducible so users can independently verify released binaries?
How does Bitkey verify that a device has not been tampered with before first use?
What protections exist against supply-chain attacks?
6. Server-Assisted Signing
Can Block mathematically demonstrate that the server key cannot spend my bitcoin without my participation?
Under exactly what conditions will the server refuse to co-sign a transaction?
Can those server-side policies change without my knowledge or approval?
How are those policies independently audited?
7. Privacy
What information does the Bitkey app transmit to Block?
What metadata is retained?
Can wallet activity be associated with my identity, phone number, email address, or IP address?
Does Bitkey support privacy-enhancing technologies such as Tor?
Are there plans to support direct connection to a personal Bitcoin node?
8. Long-Term Resilience
If Block were acquired, discontinued Bitkey, or ceased operations, how would users recover their bitcoin?
Can every Bitkey wallet be recovered independently of Block?
What parts of the system remain dependent on Block's continued operation?
What is the long-term strategy for ensuring users retain sovereignty over their bitcoin?
9. Independent Verification
Has the complete Bitkey system including the mobile app, firmware, backend services, and recovery process been independently audited?
Are those audit reports publicly available?
How can users independently verify that the software they install matches the published source code?
Closing Question
If you could answer only one question, it would be this:
Assume an attacker has complete control of my unlocked phone. Please describe every action they can perform, every action they cannot perform, and exactly what additional approvals are required before any bitcoin can leave my wallet.
Understanding that security boundary would provide the clearest picture of Bitkey's suitability as a long-term Bitcoin custody solution.
The lie you've been told stops today.
You want to know what inflation really is?
Strip away the economics textbooks, the PhD jargon, the CNBC smooth-brains explaining "supply chain pressures" like they discovered fire.
Inflation is theft.
Pure. Surgical.
Government. Sanctioned. Theft.
It's not rising prices, that's the symptom, not the disease.
Inflation is your government printing currency units faster than you can earn them, deliberately diluting every hour you've ever worked into monetary vapor.
They're not raising the cost of living.
They're lowering the value of your life.
See that?
Milton Friedman said it decades ago, and they buried it under a mountain of Keynesian propaganda:
"Inflation is always and everywhere a monetary phenomenon."
Translation: Every cent of inflation comes from one place and one place only. Printing money.
• Not greedy corporations.
• Not supply shocks.
• Not your local grocery store.
Bureaucrats in suits, armed with spreadsheets and the legal authority to counterfeit, systematically destroying your purchasing power while lecturing you about "price stability."
Bitcoin fixes this.
Satoshi never said, "Bitcoin is for everyone."
What Satoshi built was a system that is open to anyone.
Those are different ideas.
Permissionless access doesn't remove responsibility.
It removes permission.
With that comes learning.
The better question isn't who Bitcoin is for.
It's whether we're willing to understand the responsibilities that come with owning it.
@ProofOfMoney As an educator, why wouldn't the 17.39 Bitcoin have been allocated to multiple wallets sharing the same seedwords that included a 25th A+ entropy passphrase as part of each wallet?
@AndrewZywiecMD A claim can be proven when the available evidence or the logical framework is sufficient to rule out all alternatives. Whether the claim is phrased positively or negatively is secondary.
In fact, every negative statement has a corresponding positive statement:
. . . rolling the dice
You yelled from the rooftops,
GET TO ONE BITCOIN
With an ETF, you own shares in a fund, not the private keys to Bitcoin itself.
"Not your keys, not your coins" is a core principle in the Bitcoin community.
Counterparty risk
You depend on the ETF issuer, custodians, brokers, and financial system to operate correctly.
Additional intermediaries introduce additional points of failure.
Government regulation
ETFs exist within the regulated financial system.
Governments can change tax rules, reporting requirements, trading restrictions, or sanctions that affect ETF holders.
Account restrictions
Brokerage or bank accounts can sometimes be frozen due to court orders, fraud investigations, sanctions, compliance reviews, or administrative errors.
If your ETF is held through such an account, your access to it may also be restricted until the issue is resolved.
Financial surveillance
ETF ownership is generally linked to your identity through regulated financial institutions.
Some people prefer self-custody because it reduces reliance on centralized intermediaries, though self-custody does not make someone anonymous.
Tokenization of assets
Some governments and financial institutions are exploring tokenized versions of real-world assets such as stocks, bonds, and real estate.
Take a deep breath. Then another. Then another. Take the kids out for a walk in the forest. Another on the beach. Watch a sunrise and a sunset together. Get in the habit. Health is the first wealth. Cultivate that. It's the first principle. Take a deep breath. Then another. Begin. All things anew. Build back stronger. Start here. Create a separate Vault for yourself and for each kid. Separate seedwords and passphrases. Teach your kids every step of the way. Learn by teaching. This is a family affair. The savings plan. Deposit $10 in each Vault. Ask ChatGPT based on your skill set and interests for multiple ways to add $1000, $5000, $10,000 to your monthly income. You're on your way. Opportunity is everywhere. Be grateful. No looking back. Don't try, do.
@_Adrian@Digvijay_BTC Adrian is shedding much needed light, Simon @SimonDixonTwitt is shedding much needed light. Would be good to have both in a room together shedding their light on all of us.
If you're holding Keystone 3 Pro, your seed phrase generation is already more secure than most 🛡️
Here's what's happening inside the device, and why it matters 👇
Most wallets rely on one chip to generate your seed phrase. One flaw in that chip, one point of failure ⚠️
Keystone 3 Pro is built differently:
→ Two separate secure chips each generate random numbers
→ Both are combined before the phrase is created
→ One bad chip can't compromise the result 🛡️
Want zero reliance on chips? Use dice roll entropy.
Roll a casino-grade 6-sided die 99 times = ~256 bits of entropy.
No internet. No device. Pure randomness. 🎲
A BIP39 passphrase adds one more layer on top. Even if someone gets your seed phrase, they can't reach your wallet without it. 🔐
What actually protects you:
→ Use multiple entropy sources, or generate your seed with dice
→ Add a strong BIP39 passphrase
→ Store it separately from your seed phrase
Randomness is the root of your security.
Keystone is built to get that right from the start.
@Apollosviper@isabellasg3 Maybe Isa is asking for the benefit of us all. It's called a community dialogue. Otherwise Isa has friends who can privately guide her. She's young. She's cool. Chill.
Bitcoin isn't real! It's not physical!
Yeah? Neither is the number seven, but I bet you'd notice if your bank balance dropped by seven figures.
Let me break the spell for you: money has never been "real."
Money is a collective hallucination—a social construct we all agree to pretend exists so we don't have to barter chickens for dental work.
Gold wasn't money because it fell from heaven with "LEGAL TENDER" stamped on it.
We picked gold because it was the least-bad physical object that checked the boxes:
- Scarce
- Durable
- Divisible
- Portable
- Verifiable
It was the analog solution to our shared idea.
But here's the thing about analog: it's slow, heavy, and requires armed guards.
And here's the thing about humans: we engineer better tools.
We went from abacus to iPhone. From carrier pigeons to satellites.
From gold bars locked in vaults to Bitcoin—verified by thermodynamics, secured by energy, and transmitted at the speed of light.
Bitcoin is the digital versioin of money. Just like X is the digital version of town hall.
Gold was the best we could do for many centuries.
Bitcoin is what we can do now that we have cryptography, distributed consensus, and proof-of-work anchored in physics.
Your grandpa trusted gold because he could hold it.
You trust Bitcoin because you can verify it.
One required faith in a metal. The other requires faith in math.
Guess which one has never been debased, diluted, or confiscated by executive order?
The concept of money is a human mental construct.
Always has been. Always will be.
The only question is: do you want your construct built on scarcity enforced by governments—or scarcity enforced by code?
Gold was monetary technology for the industrial age. Bitcoin is monetary technology for the information age.
Welcome to the upgrade.
If you use Windows 11, you need to read this right now.
Your PC is logging every website you visit. Every app you open. Every file you create. Every word you type.
Microsoft turned it all on by default. And with the new Recall feature, it is now taking screenshots of your screen every few seconds and storing them.
The switches are scattered across settings Microsoft made deliberately hard to find.
Here are 6 moves to shut it off: 🧵
🚨💥 SE PRENDIÓ HOLANDA (Paises Bajos) 🇳🇱💥🚜
Los Agricultores holandeses se levantan masivamente NUNCA permitirán que el gobierno Gløbalista ROBE sus TIERRAS y prohíba a sus hijos cultivar para siempre...
Los Agricultores están listos para la mayor protesta de la historia contra su gobierno.
Los Medios no quieren que veas esto. COMPARTE!! 🔥
YOU CAN NOW SEND #BITCOIN OFFLINE WITHOUT INTERNET VIA BILLIONAIRE JACK DORSEY'S BITCHAT
THE APP IS SO POWERFUL GOVERNMENTS AROUND THE WORLD ARE TRYING TO BAN IT
GITHUB WANTS TO DELETE THE CODE
GLOBAL FREEDOM TECH IS SPREADING 🔥