The story about the Aussie brewery recycling ASICS heat to power 20,000 gallons of beer production each month keeps getting better.
Turns out the Bitcoin mining runs 100% on excess solar from the brewery's rooftop panels => no grid power => lower carbon footprint
Dear COLDCARD attackers,
Congratulations. You successfully found a bug, exploited, and have collectively gathered around 1,500 bitcoin.
Now you are sitting on one of the most blacklisted coin stacks in history. It will be nearly impossible for you to exchange for currency or deal with any institution. Every move you make will be highly scrutinized and tracked. Presumably for the rest of your lives, you will be looking over your shoulder.
I suggest you plea with CoinKite to return all stolen funds in return for an audit fee of 5% of the loot. This way your work is rewarded and you are able to enjoy the fruits of your labor.
Respectfully,
hodlers worldwide
Update: Don’t assume you have time.
If your seed was generated on a Coldcard and you haven’t already moved your bitcoin, please act immediately. Call your friends. Call your family. Make sure they know.
The @Strike team and I are here to help if you need us, customer or not.
👋I'm knowledgeable. Full disclosure, I lead the team that builds Bitkey. Gonna share some thoughts to help you make a decision and aim to be totally honest and transparent here. Hope you're OK with a long post so I can just share my full thoughts. This isn't canned, this is me just sharing my thoughts live.
What's great?
The 2-of-3 multi-sig setup is a superpower for a number of reasons. It helps protect against the type of things that happened in this incident. Our entropy is solid, but if it weren't on one of the keys, that's not alone enough to threaten your bitcoin. We generate entropy in 3 different environments (the phone, the hardware, and the server). This helps diversify, where a bug in one wouldn't be present in the others.
On top of this, 2-of-3 gives you flexibility where you can spend funds without Bitkey being involved. Even if @blocks disappeared (we have the Emergency Exit Kit for that). Block can be involved when you lose a key and need to recover.
You can also turn on a feature that lets you set a daily limit you'd like to spend on the go. With this on, our server will co-sign with your app key up to that limit daily, so you don't have to take your hardware if you'd like to spend while you travel or are out and about.
Our recovery system is unmatched. Lose your phone? Tap your wallet on your new phone and you're back in. Lose your Bitkey? Tap your new hardware, wait 7 days while we make sure nobody contests your recovery request, and you're in. Lose your phone and your Bitkey? If you've spent the 2 mins it takes to set up a recovery contact, they can help decrypt your app key from your cloud, without ever having access to it.
The 2 of 3 also allow us to provide an inheritance feature that is extremely easy to set up. It requires that your beneficiary have a Bitkey, but we give you a discount when you set it up and within minutes, your loved ones are protected.
We have a design without a seed phrase, which just means we take care of storing the seed for you in a redundant, resilient way. Because of this, onboarding is dead simple and takes less than 5 minutes and is easy enough for anyone of any age / experience level.
We're the only collaborative custody service that can't see any of your activity except one's we're involved in signing. This is because we invented Chaincode Delegation (https://t.co/jVGOV9GGeA).
We're fully FOSS. Our code is online and editable.
Where can we get better?
We need more utility features and we've already planned many of them. We've got support for transaction notes on the way, which is our first step towards ultimately supporting UTXO labeling and coin control. We're talking about how we can use this to support features like account separation.
We don't yet support lightning. Do we want to? Yes. Is it hard to do native lightning for mobile self custody? Yes. But there are lots of really interesting newish options that some type of lightning support much more straightforward and we will talk to the community about the right shape/tradeoffs for this when we make it past some of the other stuff I mentioned.
The lack of seed phrases is a tradeoff. We think it's the right one for most who self custody now and will in the future, but certainly not for all. If portability of your keys to other wallets is a crucial feature for you, Bitkey isn't right wallet. And that's OK. If portability of your funds is most important, then luckily we have Bitcoin transactions which allow you to move your funds from Bitkey to any other wallet.
So many of the things that make Bitkey great are because of the seedless decision. It reduces phishing capability, takes the burden of securing cryptographic materials off of customers, and in our opinion, greatly reduces the stress of self custody.
I'm not trying to do a sales pitch, so pardon if any of it sounds that way! There are other great products and services on the market as well. I do want people who have questions about our product to get the answers they're looking for. I'm really sorry you've gone through the roller coaster you've been on.
I'm so on edge, I just had a freak out. I was double checking my coldstorage, on Sparrow via my node. Everything looked good, decided to refresh the wallet, and it immediately refreshed to only 980K sats! I screamed like a little girl! My wife runs over: "Did they get us?" My mind was in cognitive dissonance because I know I made my own seeds and passphrase. How could this be!? After about 15 seconds of sheer panic, the 980K sats started resonating as familiar. I looked at the tab. "hotwallet" Thank God. Turns out I must have bumped an arrow key by accident at the same moment I did command R, because it switched over to my hotwallet at the very instant I tried to refresh my Coldstore hodl. Holy crap my heart is still racing.
developing situation, but if you are currently using coldcard move your funds out of an abundance of caution
bugs have been found and exploited using ai
if you used dice rolls to generate your seed, you should be fine
if you use a passphrase, you should be fine
if you use multisig, you should be fine
would still move funds out of an abundance of caution
this sucks, coinkite team should release more info soon
Tell me again why Bitcoin mining on landfills is not an amazing way to reduce emissions and pollution, decentralize the network further, all while monetizing wasted energy profitably without need for a subsidy?
This is central banking in a nutshell:
A group of rich guys go to the king and say: "Hey, you need money for your war. We'll give you all the money you want."
The king says: "Great, where's the money?"
They say: "We're going to make it up. We'll write numbers in a book and that's your money now."
The king says: "What do I owe you?"
They say: "You pay us back with interest."
The king says: "Where do I get that money?"
They say: "You tax your citizens."
The king says: "What if I can't pay it all back?"
They say: "That's fine. We'll lend you more. Same deal."
The king says: "And what do you do with the IOUs I gave you?"
They say: "We use them to prove we have money, so we can lend even more money to other people and charge them interest too."
The king says: "So you made up money, lent it to me, I tax my people to pay you back, and then you use my debt to make up even more money and lend it to everyone else?"
They say: "Yes."
The king says: "What did it cost you?"
They say: "Nothing."
That's literally how the Bank of England started in 1694. The Bank was formed to finance King William's war with France. The king gave the Bank a charter, granting it a monopoly on money.
The king could have as much money as he wanted. The bankers could always earn interest. Taxpayers covered the bill.
Now replace "king" with "United States Government" and you have the Federal Reserve in 1913. Same story, different country.
It doesn't end there.
185 central banks exist in the world today.
Across the globe, the governments get as much money as they want, the bankers load their pockets with interest, and the taxpayers pay for it all.
Oh, and if you don't pay your taxes, they'll fine you, penalize you, or throw you in jail.
The ONLY way out of this is to STOP USING THEIR MONEY.
As long as you're using the money that central banks control, the central banks will have control.
You have to stop giving them energy.
Use a different form of money that they can't control.
This is why Satoshi Nakamoto created Bitcoin.
“Only one who, amid the upheaval of his soul, is forced to live in an age when war, violence, and the tyranny of ideologies threaten the very life of each person, and within that life its most precious substance, the freedom of the soul, can know how much courage, integrity, and strength it takes to remain faithful to one’s deepest self in times when madness seizes the masses.
One must first have doubted and despaired of reason and of human dignity oneself in order to praise the exemplary act of the man who remains standing amid the chaos of the world.” - Stefan Zweig
How could the U.S. Treasury build a massive Bitcoin reserve without spending a dime extra?
We’ve created the a Bitcoin Tax Payment Model to simulate this under the hypothetical Bitcoin for America Act.
The projections? Striking. 🧵
⚡️What you are looking is the United States government admitting, indirectly, that the entire post-2008 financial model failed but cannot be allowed to collapse in public.
These losses are not on junk loans or risky bets.
They are on Treasuries and agency MBS.
In other words:
the safest assets in the system broke the system.
When the base layer cracks, everything above it becomes theater.
This is why nothing has “blown up,” even though the numbers are 6 times worse than 2008.
If the Fed let these losses matter, the game ends.
So the Fed simply decided they do not matter.
That is the real truth.
1. The banking system is now a ward of the state.
When banks hold hundreds of billions in underwater government debt and cannot realize the losses without detonating themselves, they stop being independent firms.
They become liquidity conduits for the state.
This is what Japan entered decades ago.
The United States is now there too.
A system where:
•banks cannot mark their assets
•the regulator cannot allow default
•the central bank cannot normalize rates
•the sovereign cannot admit insolvency
…is not a market system.
It is a managed decay loop.
2. The real plan is slow-motion financial repression.
You cannot fix a 600 billion hole with growth.
You cannot fix it with productivity.
You fix it by:
•inflating nominal GDP
•holding rates below inflation
•capping long term yields by force or stealth
•letting time and price level erode the losses
This is exactly what the Fed is doing without saying it.
Everyone sees QT on the surface.
No one sees the monetary repression operating underneath.
3. The chart is the fingerprint of a hidden default.
When sovereign debt becomes unpayable in real terms, nations do not declare bankruptcy.
They default through the currency.
This is how empires die softly.
Not with a bang, but with:
•perpetual deficits
•suppressed yields
•rolling liquidity crises
•and a currency that buys less every cycle
The chart is the early chapter of that story.
4. This is the birth of the post sovereign collateral era.
When the base layer of the financial system becomes politically managed and economically impaired, capital begins searching for a collateral that:
•cannot be diluted
•cannot be massaged
•does not depend on bank capital
•does not rely on sovereign credibility
•marks to market in real time
You know exactly what that is.
5. The deepest truth
This chart is the sovereign system saying:
“We broke the collateral foundation of our own monetary regime, and the only way out is to inflate reality until you stop noticing.”
And deep down, at the level where all narratives fall away, the system knows one thing:
The next global reserve collateral will not be issued by a government.
That is the real signal.
Congress slipped a provision into a recent spending bill capping hemp-derived THC products at 0.4mg per serving, effectively banning 95% of legal items like gummies, seltzers, and vapes that exploded after the 2018 Farm Bill legalized low-THC hemp. This nukes a multibillion-dollar industry providing milder alternatives to alcohol or cannabis, without public debate or evidence of widespread harm—states already regulate it safely. Lobbyists from booze and pharma likely pushed it to crush competition, not protect consumers, revealing cronyism over free markets.