A 22-year-old student teacher in Illinois sent a private Snapchat message to her boyfriend and two roommates.
A student had walked up to her laptop and deleted her lesson plan mid-class. frustrated, she typed something like "should I shoot him" with a gun emoji. venting. four people. private group chat.
An hour later, police walked into her school and arrested her.
here's what happened in between.
Snapchat's AI scanned the private message. flagged it as a potential threat. automatically reported it to the FBI. the FBI forwarded it to local law enforcement. deputies arrived at the school within the hour.
she cooperated immediately. handed over her phone. when shown the message she said: "oh yes. okay. yeah. i'm realizing that was a bad joke. i did not mean it at all serious at all."
police determined she was not a threat. school officials determined she was not a threat. prosecutors reviewed and issued a disorderly conduct charge. she was released the next morning. she lost her student teaching placement.
This means:
Snapchat scans private messages.
Not just public posts or stories. private group chats between you and your closest contacts. automated AI. no human reviewed it first, got flagged and reported.
Snapchat AI → FBI → local police → school → arrest.
in under an hour.
Snapchat's privacy policy says it may share your information with law enforcement when it believes there is a risk of harm. the definition of "risk of harm" is determined by an algorithm.
you are not told when a message is flagged.
you are not told when a report is filed.
you find out when the police arrive.
the message was private.
it wasn't.
$1.6 million dollars in Bitcoin was drained from my account on July 29th in the Cold Card wallet hack.
My Bitcoin was in cold storage. My keys were on a ColdCard device kept in a safety deposit box that had never been connected to the internet.
This part's nerdy, but here's what happened:
Hackers discovered a vulnerability in the part of the hardware wallet code used to create seed phrases.
This allowed them to use AI to brute force guessing seed phrases.
I was at our cottage and heard about the hack today.
"No way this affects me." I thought.
I logged into Wasabi––software that lets me view my bitcoin wallets online.
Right away I saw lines of red transaction–withdrawals–and I knew.
From 9:36pm - 9:43pm on July 29th, every wallet I had had been emptied.
18.25245043 btc gone. That's just over $1.6 million dollars CAD.
Perhaps the hardest part about this is that I did everything right.
I never shared my seed phrase with anybody. My devices never touched the internet. Everything was kept in multiple safes and safety deposit boxes.
None of it mattered. All because the hardware that created the seed phrase originally had one line in their code from 2021 that had a vulnerability.
I'm filing a police report and a report with the Ontario Securities Commission. But I don't expect to recoup anything.
A part of me is trying to make sense of what just happened. Or try to figure out a lesson in it. I'm struggling. $1.6 million is a staggering amount of money to have stolen.
I guess all that I can think about right now is that I'm so damn happy that I'm an entrepreneur and that my earning potential is under my control. Mark my damn words. I'll recover.
$1.6 million dollars in Bitcoin was drained from my account on July 29th in the Cold Card wallet hack.
My Bitcoin was in cold storage. My keys were on a ColdCard device kept in a safety deposit box that had never been connected to the internet.
This part's nerdy, but here's what happened:
Hackers discovered a vulnerability in the part of the hardware wallet code used to create seed phrases.
This allowed them to use AI to brute force guessing seed phrases.
I was at our cottage and heard about the hack today.
"No way this affects me." I thought.
I logged into Wasabi––software that lets me view my bitcoin wallets online.
Right away I saw lines of red transaction–withdrawals–and I knew.
From 9:36pm - 9:43pm on July 29th, every wallet I had had been emptied.
18.25245043 btc gone. That's just over $1.6 million dollars CAD.
Perhaps the hardest part about this is that I did everything right.
I never shared my seed phrase with anybody. My devices never touched the internet. Everything was kept in multiple safes and safety deposit boxes.
None of it mattered. All because the hardware that created the seed phrase originally had one line in their code from 2021 that had a vulnerability.
I'm filing a police report and a report with the Ontario Securities Commission. But I don't expect to recoup anything.
A part of me is trying to make sense of what just happened. Or try to figure out a lesson in it. I'm struggling. $1.6 million is a staggering amount of money to have stolen.
I guess all that I can think about right now is that I'm so damn happy that I'm an entrepreneur and that my earning potential is under my control. Mark my damn words. I'll recover.
COLDCARD BUG DEMO: Duplicate Wallet Found in 4.7 Seconds
Developer John S built a simulator to illustrate the severity of the COLDCARD entropy bug.
On an M1 Max, it found two identical wallet seeds after generating about 1.26 million seeds, taking just 4.7 seconds.
Statistically, a duplicate seed would be expected roughly once every 1.3 million wallet generations under the simulated 40-bit entropy model.
He says the most concerning part is that this kind of test could have been run in seconds on simulated hardware, or over a few days on the actual STM32 chip.
According to him, developers likely never performed it because they assumed the hardware RNG could never fail so dramatically.
He believes hardware wallet testing should include “complete idiot” unit tests that assume even seemingly impossible failures can happen.
👋I'm knowledgeable. Full disclosure, I lead the team that builds Bitkey. Gonna share some thoughts to help you make a decision and aim to be totally honest and transparent here. Hope you're OK with a long post so I can just share my full thoughts. This isn't canned, this is me just sharing my thoughts live.
What's great?
The 2-of-3 multi-sig setup is a superpower for a number of reasons. It helps protect against the type of things that happened in this incident. Our entropy is solid, but if it weren't on one of the keys, that's not alone enough to threaten your bitcoin. We generate entropy in 3 different environments (the phone, the hardware, and the server). This helps diversify, where a bug in one wouldn't be present in the others.
On top of this, 2-of-3 gives you flexibility where you can spend funds without Bitkey being involved. Even if @blocks disappeared (we have the Emergency Exit Kit for that). Block can be involved when you lose a key and need to recover.
You can also turn on a feature that lets you set a daily limit you'd like to spend on the go. With this on, our server will co-sign with your app key up to that limit daily, so you don't have to take your hardware if you'd like to spend while you travel or are out and about.
Our recovery system is unmatched. Lose your phone? Tap your wallet on your new phone and you're back in. Lose your Bitkey? Tap your new hardware, wait 7 days while we make sure nobody contests your recovery request, and you're in. Lose your phone and your Bitkey? If you've spent the 2 mins it takes to set up a recovery contact, they can help decrypt your app key from your cloud, without ever having access to it.
The 2 of 3 also allow us to provide an inheritance feature that is extremely easy to set up. It requires that your beneficiary have a Bitkey, but we give you a discount when you set it up and within minutes, your loved ones are protected.
We have a design without a seed phrase, which just means we take care of storing the seed for you in a redundant, resilient way. Because of this, onboarding is dead simple and takes less than 5 minutes and is easy enough for anyone of any age / experience level.
We're the only collaborative custody service that can't see any of your activity except one's we're involved in signing. This is because we invented Chaincode Delegation (https://t.co/jVGOV9GGeA).
We're fully FOSS. Our code is online and editable.
Where can we get better?
We need more utility features and we've already planned many of them. We've got support for transaction notes on the way, which is our first step towards ultimately supporting UTXO labeling and coin control. We're talking about how we can use this to support features like account separation.
We don't yet support lightning. Do we want to? Yes. Is it hard to do native lightning for mobile self custody? Yes. But there are lots of really interesting newish options that some type of lightning support much more straightforward and we will talk to the community about the right shape/tradeoffs for this when we make it past some of the other stuff I mentioned.
The lack of seed phrases is a tradeoff. We think it's the right one for most who self custody now and will in the future, but certainly not for all. If portability of your keys to other wallets is a crucial feature for you, Bitkey isn't right wallet. And that's OK. If portability of your funds is most important, then luckily we have Bitcoin transactions which allow you to move your funds from Bitkey to any other wallet.
So many of the things that make Bitkey great are because of the seedless decision. It reduces phishing capability, takes the burden of securing cryptographic materials off of customers, and in our opinion, greatly reduces the stress of self custody.
I'm not trying to do a sales pitch, so pardon if any of it sounds that way! There are other great products and services on the market as well. I do want people who have questions about our product to get the answers they're looking for. I'm really sorry you've gone through the roller coaster you've been on.
APPLE INCLUDED THE BITCOIN WHITEPAPER IN EVERY MAC FOR OVER 4 YEARS.
THE DOCUMENT WAS HIDDEN IN MACOS SYSTEM FOLDERS SINCE CATALINA IN 2019.
IT WAS DISGUISED AS A SCANNER SAMPLE FILE.
MILLIONS OF MAC USERS UNKNOWINGLY HAD A COPY OF SATOSHI NAKAMOTO'S ORIGINAL BITCOIN WHITEPAPER ON THEIR COMPUTERS FOR YEARS.
CRAZY 🔥
Even hardware wallets can have bugs. Even old wallets (with long history) can have bugs.
How to mitigate? Split your funds in a few wallets maybe? This has a different set of risks. Nothing is 100%.
Stay informed. Stay SAFU!