Non puoi difendere la tua sovranità economica se regoli i conti nella valuta di chi ti sta attaccando.
Se il Canada vende energia, petrolio e minerali critici in cambio di dollari USA stampati a debito, i discorsi sui dazi restano fumo. Volete vera indipendenza e leva negoziale? Esigete #Bitcoin per le materie prime. @CanadianPM 🇨🇦⚡️
@MarkJCarney
Comunque è bello appartenere a quella parte di mondo che non ha bisogno di ammazzare bambini in giro per la terra per sostenere i propri vizi ed il proprio fancazzismo. @Rikki6ixx
Public heads-up for GPU cloud / rental providers and Trust & Safety teams:
There is a publicly disclosed hardware-wallet entropy issue that may lead to abuse of consumer GPU rentals — especially multi-GPU NVIDIA RTX 3090 / 4090 and similar CUDA cards — for offline BIP-39 seed recovery.
References: • Coinkite advisory: https://t.co/Dz1dW9JrA0 • Technical background: https://t.co/cvolFiwrC4 • Live theft tracker: https://t.co/EAl1wvF1r6
What this looks like technically: • Offline search of a reduced BIP-39 seed space via bulk PBKDF2-HMAC-SHA512 (2048 iterations) • Mk3: does not need GPUs — that space is small enough to brute-force cheaply, and Mk3 seeds are already linked to on-chain thefts • Mk4 and later: does need large amounts of compute. Those seeds are stronger but still weaker than full design entropy for some pre-fix units. Rough ballpark: recovering one seed ≈ ~10× RTX 4090s for about a day • On rental platforms this tends to look like long-running custom CUDA/hashing binaries or containers on multi-GPU 30/40-series instances — not normal training/inference API usage
Why this matters now: the low-hanging fruit (Mk3 and the weakest seeds that need little or no GPU) appears largely drained already — the tracker above shows the ongoing thefts. The next wave is Mk4-and-later seeds, which are compute-bound. Large blocks of rented consumer GPUs are the bottleneck for attackers.
This is not a vulnerability report against any platform. It's context so abuse / trust teams can:
1. Route future reports on this topic correctly
2. Optionally watch for suspicious multi-GPU, long-running custom CUDA jobs
3. Have background if law enforcement or researchers get in touch
cc: @vast_ai@runpod@clore_ai@TensorDock@SaladTech@akashnet@MassedCompute@Hyperstackcloud@fluidstack
Happy to help any team dig in.
BITCOIN’S FATAL CONTRADICTION
“Not your keys, not your coins” is not enough.
Who chose your key?
Every possible Bitcoin key already exists as a mathematical coordinate. A wallet does not create a magical new box: it selects one from an unimaginably large universe.
If a hardware wallet makes that selection inside an opaque device, you did not choose your key. You trusted a manufacturer to choose it correctly.
The COLDCARD scandal has now demonstrated why this matters.
Coinkite admits that integration bugs prevented the hardware random-number generator from contributing as intended. Its preliminary estimates put affected Mk2/Mk3 seeds at roughly 40 bits of effective search space and later affected models at roughly 72 bits—instead of the intended 128.
The source code was public.
The correct RNG code was present.
The reviews still failed to verify which function seed generation actually reached.
For years.
That is not a minor firmware bug. It is a failure at the exact moment ownership is born.
Users could buy the hardware wallet, keep it offline, hide the seed words, never reveal the PIN and follow every prescribed ritual—yet still receive a seed selected from a dramatically smaller search space.
Updating the firmware cannot repair an already affected seed.
Bitcoin culture tells ordinary people:
“Don’t trust. Verify.”
Verify how?
BIP39 itself says that it was designed to transport computer-generated randomness. Its checksum requires SHA-256. BIP93 states plainly that calculating a BIP39 checksum by hand is effectively impossible.
A person with a fair die, paper and a pencil can produce genuine entropy. But to convert that entropy into the standard accepted by most wallets, that person must return to a computer and trust—or somehow independently verify—the machine.
BIP93, through Codex32, is not the complete answer. But it recognizes the correct principle: seed creation, checksums, error correction and secret sharing should be designed so they can be performed and verified using paper, a pencil and simple lookup tables.
Yet BIP93 remains a Draft while the industry continues selling black boxes and calling delegated trust “self-custody.”
If Bitcoin requires billions of ordinary people to become programmers, firmware auditors and cryptographers merely to know whether their keys are truly theirs, Bitcoin will not liberate them.
Most people will remain with banks and exchanges—or stay away completely.
Poor users will bear the failures first. Wealthy users will retreat into institutional custody. Bitcoin will become the custodial and speculative product it promised to replace.
This is how Bitcoin fails.
Not because SHA-256 is broken.
Not because quantum computers arrive.
Not because governments ban it.
Bitcoin fails because the birth of ownership remains unverifiable for an ordinary human being.
We need interoperable wallet standards that allow a person to generate randomness physically, construct and verify a backup without an opaque device, and independently verify every transition from entropy to receiving address.
Until the user controls the birth of the key, “not your keys, not your coins” is incomplete.
If someone else chose the key, was it ever truly yours?
@Rikki6ixx@guybrushino
A direct response from @nvk@Coinkite@COLDCARDwallet would also be welcome. This is not an accusation of intent. It is a question about whether trustless key generation is actually possible for ordinary users.
I would especially value a technical response from @LLFOURN@lopp@achow101@blksresearch: if ordinary users cannot independently verify the birth of their seed, where exactly does self-custody begin?
Just received your advice on email, I'm not affected but anyway thanks guy for what are you doing for take on safety our community
@BULLBITCOIN_#btcpay