@marsspitsbarz Very easy to set multi sig with Jade they have stateless signing doesn’t keep seed until signing use QR code with another wallet I used blue wallet yes Blockstream is gay don’t persecute me but it’s really good function for multisig I’ve gotother single sig air gapped computer
@BritishHodl@Puncher522 Don’t tell me you’ve bought IBIT shares and think you own Bitcoin? 🤦♂️🤣 is learning the very basics too much for you Brit boy 🤣🤙
I’m a borderline retard so I could be completely wrong on my interpretation here.
But these dumb fucks over at @COLDCARDwallet changed the call path on seed generation and NEVER checked that it still pointed to their own hardware RNG. They only checked that their hardware RNG code still existed in the binary.
Pre 2021 call path
New Wallet
→ ckcc.rng_bytes()
→ Coldcard’s own hardware TRNG
Post 2021 call path
New Wallet
→ ngu.random.bytes()
→ rng_get()
→ Weak software Yasmarang PRNG
Why did it fall back to the Yasmarang software RNG? Because they had set MICROPY_HW_ENABLE_RNG to 0, probably thinking it disabled MicroPython’s RNG completely.
Instead it made MicroPython compile the weak software version because that’s the only rng_get that existed. The MicroPython hardware path would have given the full 128 bits of entropy the same as their own RNG.
All they had to do was audit the call path they changed.
This entire fucking disaster would never have happened.
🖕🖕🖕🖕🖕🖕🖕🖕🖕🖕🖕🖕
This is what growth looks like. Trust no company, verify everything. Build entropy, hone your knowledge and skills and above all stack relentlessly. And please block every scammer who’s pouncing on this tragedy to con plebs into selling their corn for a Blackrock IOU