I recently read something that I can't stop thinking about.
It said: there is a line that should never be crossed. When someone knows you are facing one of the hardest times of your life and still chooses to disrespect you or add to your stress, something darker is at play.. Cruelty in moments of deep vulnerability is intentional. And when a person can hurt you while knowing how fragile you are, that kind of betrayal changes how you see them forever.
Nobody talks about how people who grew up in broken and dysfunctional homes don’t have big dreams. They only dream of having a home no one can take away and a person who won’t abandon them.
Yeah I might just blow my shit smooth off ngl I can't keep throwing away 5 days of my life every week for 17/hr, I'm literally never going to save any money or be able to do anything I want to do so what the fuck is the point genuinely
families and psychiatrists think the schizo is giving up by using reality altering substances, but he is actually attempting to go back into an episode to decrypt the symbolic delusions into a singularity to exorcise the psychosis of its impurities
and ascend
Adult autistic regression SUCKS. My verbal processing has tanked in the last few years. I can almost never actually say what I mean out loud, in conversation. Oftentimes I feel trapped in my brain. I don't feel like the people in my life can actually know me. I feel like I constantly misrepresent myself. I do not know how I managed to function socially as a child or adolescent.
Looks like Coldcard was a state-backed, inside job spanning multiple years of careful planning.
The revelation of earlier tweets like the one below heavily suggests that this was long premediated by Coldcard insiders.
The heist was optimized around max public shock value and minimum discretion.
Given all the facts, we must answer:
- Why did the attacker completely disregard privacy by consolidating stolen coins into a single address?
- How did the attacker, who clearly planed this for a long time, fail to plan to cover their own tracks?
- Why did the attacker use KYC'd service providers?
- Why did Coldcard make these "wink-wink easter egg" posts about this exact bug around the same time the bug first appeared in the code base?
- If it was merely a "retirement attack," why not exercise discretion so you could actually retire?
- Why did the timing line up with major politically relevant developments like CLARITY and a bear market?
The only theory that answers all these questions well is a state-backed operation involving Coldcard insiders. It was never about the money. It was about attacking self custody, one of the core premises of Bitcoin.
I did not want to make this accusation initially even though I did suspect it. Now the evidence is on my side so I am adding the insider point to the theory.
The folks who think there is no conspiracy need to answer some hard questions:
If you think it is a script kiddie using an open source LLM like Kimi, you need to answer why he would do this but not ask Kimi or Google how to cover up his tracks despite planning at least for a few months.
If you think it was a random Bitcoin hater who doesn't care about the money, you need to answer why Coldcard put out these clearly suggestive tweets at the same time.
(Note: you can say coincidence, that's your right).
Skeptics: I would love to hear your answers!
For me the inside job theory squares all the corners and also explains the company's actions over the last few years.
- Antagonizing security researchers -> less visibility into code
- Discredit competitors -> cause confusion
- Heavily fund the marketing engine -> draw in the hardcore Bitcoiners; promote a strong brand association with self custody
- All these easter eggs + NVK hating plebs -> mock the would-be victims and create learned helplessness
All of this comes together really well to the mess we have today.
What a nightmare. By implementing the tariffs illegally, and now having to unwind them, the Trump administration created over $100 billion of profit for corporations selling foreign products, at the expense of American consumers.
Your refund: $0.00
Apple’s profit: $2.2 billion
How safe if your Bitcoin seed phrase?
The difference between 40 bits and 256 bits is not a small upgrade.
It is the difference between minutes and longer than the age of the universe.
people who stored their btc on coldcard got drained because of entropy.
the seed generation was reproducible, anyone could recompute their keys.
so i went through every other hardware wallet to see how they make your seed, and whether the same thing can happen again.
@Trezor: mixes the device's randomness with randomness from your computer, and the device has to prove it used both. even if its chip is fully broken, you're still fine. the best design here by far.
@BitBoxSwiss: 5 separate sources of randomness combined. one bad source can't sink you. open source, reproducible builds, dice supported.
@FoundationHQ: built their own randomness circuit out of plain resistors and capacitors, open source, on top of two other sources. no black-box chip to trust. supports dice.
@KeystoneWallet: 2 secure chips from 2 different manufacturers, combined. also lets you roll 99 dice and publishes how to check the result yourself.
@Blockstream: jade pulls from 7 things: radio noise, cpu counters, battery, temperature, camera, your input, the app. very hard to break all of them.
@SeedSigner: your dice are the only source. no chip to trust at all. and they ship a guide teaching you to verify their own math. weakest hardware, strongest proof.
@OneKey: secure element plus mcu combined on device, open source firmware. solid, but you can't add your own randomness.
@Ledger: one certified chip (AIS-31, EAL5+). good randomness. but it's a single source, closed source, and you cannot verify any of it. you're trusting them completely.
@Tangem: key is born inside the chip and never comes out. audited by three firms. same trade: strong, and impossible for you to check by design.
@ngrave_official: mixes chip randomness with your fingerprint and room light. clever. but the "EAL7" badge covers one software component, not the whole device.
@ELLIPAL: single certified chip, no software fallback, fails closed instead of guessing. closed source, so take it on faith.
@SafePal: 2 chips mixed. they've never published the details.
@COLDCARDwallet: patched now, and dice on coldcard were always verifiable. but every seed made between 2021 and 2026 is permanently burned.
one source = ledger, tangem, ellipal. that one source fails, everything fails. their answer is to make it excellent and certified. that's exactly the bet coldcard lost.
many sources = trezor, bitbox, passport, jade, keystone. one broken source never reaches your key.
and every one of these claims 128 or 256 bits.
coldcard did too. certification doesn't help either, coldcard's chip was fine, the code just stopped calling it.
the only thing that saves you is being able to check.
roll your own dice. verify the words yourself.
It's Orwell's 'Memory Hole' - destroy the hard copies and then one button press deletes the digital versions whenever they choose. These people are demons.