Tangle.hl

3.9K posts

Tangle.hl banner
Tangle.hl

Tangle.hl

@0xTangle

Growth/BD/Marketing @Trueo_ | @hlnames | Voice at @HLglobal_'s HL Radio | Organizer at @dctrlvan & @EthVancouver | Podcast: @Tangle_FM

Earth Katılım Nisan 2021
4.1K Takip Edilen6K Takipçiler
Sabitlenmiş Tweet
Tangle.hl
Tangle.hl@0xTangle·
Ever since hosting the Forum & AMAs at Sushi, many have asked if I continued podcasting or hosting shows. Today, that changes as I finally reveal the long-overdue podcast! The Tangle Collective will start by featuring shows with prominent figures from the digital asset and blockchain community. Over time, it will expand to include educational content, clips, and written materials. Over the years, I have gained extensive knowledge about this ecosystem and participated in many inspiring conversations. Few of these have been recorded. As a result, I aim to track ideas and insights and turn them into deep, meaningful content. Join me on this journey as we explore a variety of topics from a diverse group in this industry. Let’s get tangled!
Tangle FM@Tangle_FM

The moment has come to introduce: The Tangle Collective! After years of learning, building, and engaging throughout the crypto ecosystem, it's time to start turning these conversations and ideas into deep meaningful content. Welcome to the next chapter, let's get tangled!

English
128
7
229
11K
Reroll.gg
Reroll.gg@rerollgg·
@0xTangle Anytime I see "🎲🎲" it reminds me of the casino
Reroll.gg tweet media
English
1
0
1
25
Tangle.hl
Tangle.hl@0xTangle·
@dschamis Will always love the ticker $PURR 😸 And thanks for the great conversation 🙏🏼 Hyperliquid
English
0
0
5
185
David Schamis
David Schamis@dschamis·
When we were choosing a ticker for Hyperliquid Strategies, most of the obvious options were some variation of HYPE. They were fine. They were also boring. I pushed for $PURR because it was distinctive, connected directly with the Hyperliquid community and reflected the kind of company we wanted to build. Some people loved it immediately. Others still weren’t entirely convinced. I sat down with @0xTangle at the @HLglobal_ Hyperliquid Summit to discuss the decision, how I explain @HyperliquidX to traditional investors, and why we assembled @HypeStrat with such a deliberately TradFi-oriented team and board. The immediate goal is to provide an institutionally credible way to access HYPE. The larger opportunity is helping connect Hyperliquid with the trillions of dollars of financial assets that have yet to move onchain. That is why we are thinking beyond simply being a DAT.
English
14
7
141
7.1K
Tangle.hl
Tangle.hl@0xTangle·
This is a brutal situation for many Bitcoin holders. @COLDCARDwallet, disclosed a seed generation vulnerability that caused less entropy than thought. BUCKLE UP. HERE WE GO. It is time for everyone to revisit their security setup and understand exactly where the randomness protecting their Bitcoin came from. I have been extremely militant about generating seed entropy from 100+ physical dice rolls on an offline hardware wallet. I have generally used @KeystoneWallet because I prefer its air-gapped abilities. Before creating a real wallet, I perform a disposable test using a separate roll sequence. I enter those test rolls into the hardware wallet and independently reproduce the expected seed using an offline copy of the Ian Coleman BIP39 tool (online found here: iancoleman.io/bip39/). I never enter a real seed or real dice sequence into the live website or any internet-connected computer. When both systems produce the same result, it confirms that the hardware wallet is converting that particular dice sequence into the expected BIP39 mnemonic. This verification has limits. It does not prove that the entire device, firmware or supply chain is uncompromised. A sufficiently malicious device could behave correctly during a test and behave differently later. What the test establishes is that the dice-roll derivation works correctly for the tested sequence. After completing the disposable test, I wipe the hardware wallet and begin again with a completely new set of 100-plus physical dice rolls. THAT NEW ROLL SEQUENCE IS SECRET KEY MATERIAL. I never photograph it, type it into a phone, store it digitally, send it through a messaging app, or enter it into an internet-connected computer. Once the resulting seed has been securely recorded and verified, the original dice sequence should no longer be exposed. More than a year ago, I had a conversation with COLDCARD after noticing that its displayed seed did not match what I expected from my dice-roll input. I could not determine whether the discrepancy arose from how the device mixed its own entropy with my dice rolls, from a difference in the derivation process, or from a mistake in my verification method. Because I could not independently reproduce and fully understand the process, I stopped. I never transferred any meaningful funds to that COLDCARD Q, despite being interested in its QR code, NFC, and other features. That remains my fundamental rule: if I cannot understand and reproduce the seed-generation process, I am still trusting the device. According to Coinkite, a firmware integration error caused affected devices to use a software pseudorandom number generator as a fallback instead of receiving the intended randomness from the hardware RNG. The company currently estimates that affected Mk3 seeds may have had an effective search space of approximately 40 bits. Affected Mk4, Mk5 and Q seeds received additional secure-element entropy but may still have had only approximately 72 bits, rather than the expected minimum of 128 bits. Importantly, Coinkite says independent dice entropy was still included. At least 50 fair, private, and independent six-sided dice rolls provided approximately 128 bits of entropy from the dice alone. At least 99 rolls provided approximately 256 bits. This means a correctly performed 100-plus-roll process appears to protect against this particular RNG failure, provided the rolls were genuinely random, remained private, and were applied to the final seed that was actually used. I had no way to verify this, thereby voiding the “Don’t Trust, Verify” motto. It still does not eliminate every possible hardware, firmware, or supply-chain attack. Nothing does. It reduces dependence on the device’s internal random-number generator and gives the user an independently controlled source of entropy. Most hardware wallet users probably let their device generate their seed automatically. Until now, that has generally been viewed as reasonable when using reputable, well-reviewed hardware. This disclosure demonstrates that even open-source firmware, secure elements, and established manufacturers can contain subtle failures for years. Artificial intelligence does not suddenly make a properly generated 128-bit or 256-bit seed brute-forceable. What AI may do is help attackers audit old code, discover implementation mistakes, and automate attacks against wallets whose real search space is dramatically smaller than intended. We also live in an age in which people generate seeds through mobile apps, browser extensions, desktop software, custodial services, and even messaging bots. I do not consider a seed generated on a general-purpose, internet-connected device appropriate for securing long-term savings, I do expect them to get compromised at some point. This means those keys exist in a much larger and more complex attack environment. Malware, malicious browser extensions, cloud backups, screen capture, clipboard monitoring, operating system vulnerabilities, and user approved malicious transactions all create additional risk. I use hot wallets, but I treat them like the physical wallet in my pocket, which is convenient, useful, and limited to an amount I am prepared to lose. I am also cautious about hardware wallets that require a direct USB connection to a computer. Air gap reduces that particular exposure, but QR codes, NFC, microSD cards, firmware updates and transaction data are still communication channels and must be handled carefully. ALL OF THIS IS A DISASTER FOR NORMIES AND MASS ADOPTION. The average person should not need to audit random-number generation, understand entropy calculations, verify firmware or roll a die 100 times to hold assets safely. Every additional security step creates another opportunity for confusion, error, or permanent loss. For people who are willing to accept the responsibility, however, there are ways to reduce the risk. My preferred approach is to generate entropy using at least 100 fair and independent rolls of a physical six-sided die through a documented dice-only process. The implementation should be independently reproducible, and the real roll sequence must never touch an internet connected device. I personally prefer a properly generated 24-word seed, which begins with 256 bits of entropy. A genuinely random 12-word seed still contains 128 bits of entropy and is not presently practical to brute-force, so people should not panic merely because they use 12 words. A strong BIP39 passphrase can create an additional independent barrier. It is commonly called the “25th word,” although it can be much longer than one word. It also introduces a serious new failure mode: every passphrase produces a valid wallet, and forgetting or mistyping it can result in permanent loss. The passphrase should be backed up precisely and stored separately from the seed. Multisig wallets can add another powerful layer of protection, but only when they create genuinely independent failure domains. Ideally, the seeds should be independently generated, the signing devices should not all depend on the same hardware and firmware implementation, and the backups should be stored in separate locations. Multisig also creates additional complexity. Wallet descriptors, device configuration, recovery testing, and inheritance planning all matter. A sophisticated setup that the owner cannot reliably recover may be less safe than a simpler setup that has been thoroughly tested. The current COLDCARD disclosure concerns the seed-generation path, not a demonstrated defeat of Bitcoin’s cryptography or a universal compromise of hardware secure elements. Nevertheless, it is a serious reminder that a hardware wallet’s security claims are only as strong as their implementation. Anyone whose seed was generated on affected COLDCARD firmware should read Coinkite’s current advisory, and then migrate funds carefully. I continue to use Keystone as my primary hardware wallet. By providing my own independently generated dice entropy and verifying the derivation process before creating the real wallet, I feel more confident about where the randomness protecting my seed originated. That does not mean my setup is invulnerable. It means I have identified the assumptions I am making and reduced my dependence on at least one important component: the hardware wallet’s internal RNG. Do your own research. Understand the tradeoffs in your setup. Keep only limited spending balances in hot wallets. Test your recovery process before relying on it. Most importantly, help your friends and family understand that buying a hardware wallet is not the final step. They must also understand how it generates, stores, and uses their keys. I welcome criticism of this post and my approach. I am always looking for weaknesses in my own security model. At the end of the day, my goal is to help others remain safe and secure in the wild, wild, wild west that we continue to endure. (Ideas all my own, slop via GPT)
Tangle.hl tweet mediaTangle.hl tweet media
English
3
5
33
6K
HL Eco
HL Eco@hl_eco·
Hyperliquid Summit NYC, hosted by @HLglobal_, is a goldmine of knowledge shared by asset managers, builders, academics and policy advocates. Search everything by keyword or meaning, and jump straight to the moment it was discussed, at hl.eco/learn
English
2
0
24
2.9K
Tangle.hl
Tangle.hl@0xTangle·
@Truthcoin “Not all” rather than “no” and I can get behind this. Dice are your friends, even if this is high friction.
English
0
0
0
189
Tangle.hl retweetledi
dctrl.
dctrl.@dctrlvan·
Happy Birthday Ethereum! 🥳🎉 Swing by dctrl tonight at 6 PM! 📍328 W Hastings Street Sign up below! 👇 luma.com/bz2uldqt
dctrl. tweet media
English
2
1
6
203
Tangle.hl
Tangle.hl@0xTangle·
“Less freedom” It’s clowns like him that adopt the capture of Bitcoin, make it custodial, and keep it dumb as a pet rock. Covenants have been widely accepted prior to the BIP-110 infection; efforts should resume post-haste. Custodial solutions fail. Ossify, and die.
Michael Saylor@saylor

Censorship forbids miners to serve willing buyers. Larger blocks dilute blockspace scarcity and raise bandwidth and validation costs. Covenants permanently complicate consensus and create new attack surfaces. Less freedom. Less scarcity. More risk.

English
0
0
8
403
Tangle.hl
Tangle.hl@0xTangle·
Should this post hit your timeline, and you are unsure of what this “BIP-110” thing is, here is a pretty quick explanation to get you up to speed:
𝐓𝐗𝐌𝐂@TXMCtrades

@marsspitsbarz What this saga has ultimately shown is that a lot of bitcoiners are extremely retarded

English
2
0
3
564
David Seroy 🏔️
David Seroy 🏔️@david_seroy·
You can buy BTC with tighter spreads on-chain than on Binance: pamm.wtf/exec. PropAMM's on EVM still quite novel, but very impressive.
English
3
0
5
617
Tangle.hl
Tangle.hl@0xTangle·
@brian_trollz I’ve had this tweet bookmarked for way longer than I care to admit. You also realize you can never unpin it, right?
English
0
0
1
38
Tangle.hl
Tangle.hl@0xTangle·
@inversebrah These knotzis are really sumting special. Putting the bsv’ers to shame
English
0
0
0
33
Tangle.hl retweetledi
HL Global
HL Global@HLglobal_·
On July 16, HL Global welcomed 200 attendees, 40 speakers, and 20 sponsors to the New York Athletic Club for the Hyperliquid Summit 2026. Across two stages, Hyperliquid ecosystem teams joined leading financial institutions, investors, policy leaders, and academics to examine where Hyperliquid stands today, and where it is headed next. 1/
HL Global tweet media
English
51
40
376
42.2K