

C•R BridgeX.win
7.6K posts

@0x_C_R
https://t.co/ZVesrOetG5 from Intarsia https://t.co/ppxMpbB5Zm https://t.co/fgd70M0FKx
2026 Yıllık Özeti
@0x_C_R hesabının Twitter yılını gör







🚨 DON'T ASSUME YOUR PASSPHRASE WILL SAVE YOU! IF YOUR SEED PHRASE HAS BEEN COMPROMISED, MOVE YOUR BITCOIN ASAP. If you're relying on your passphrase to protect your wallet, make sure it has enough entropy. A weak passphrase can be brute-forced if an attacker already has your seed phrase. The chart below shows the estimated time to brute-force a passphrase made from N truly random words selected from the 2,048-word BIP39 word list. Times shown are the average (half the keyspace). (I would move mine regardless of the times below)

this feature alone can change your life... 🔒 passphrase is a secret word you add on top of your 24 words seedphrase, available on all crypto hardware wallets > it generates a completely separate wallet. same device, different vault. > basically a second cold wallet for free > even if someone finds your seed phrase, they get nothing without the passphrase > takes few minutes to set up. no extra cost. no excuses > adds double security on top of your existing cold wallet setup tip: if ever someone forces you to open your cold wallet, you open the wallet without the passphrase. they see nothing important > passphrase isn't stored anywhere. it only exists in your head/physical storage your seedphrase is your first lock. the passphrase is the lock behind the lock. if you have a hardware wallet and no passphrase, you're halfway protected. i'll be sharing other important security lessons, follow for more 🫂





@HaileyLennonBTC COLDCARD, once programmed, cannot be re-upgraded until the user initializes it. We cannot ship units with affected firmware and expect users to upgrade. The safest action was to destroy the affected units and ship only those with the new fixed firmware.





from design to in game demo! you guys are seeing this shit live and uncut. notis on this will be ready to play before you know it. Slimewhale.io

Lets make a more exhaustive list of ways to "get hacked." Many of which I've mentioned before. Weak RNG: Use a wallet with a weak RNG (random number generator.) or other vulnerability. Some mobile wallets had this problem, and some vanity address generators had it too. Someone has a camera watching your screen and you view your seeds. You google a website and a scam site has done SEO or paid to be at the top of the search results Fake "support" messages you by direct message, or on socials to help you with your wallet or problem. Fake support pretends to be the exchange and asks you info they use to login as you and empty you, to "verify your account." You accidentally leak your seed on a livestream (sounds erotic.) You put your seed in plain text somewhere, and someone else finds it. You use a brain wallet with a phrase from a book and people constantly scan the chain for common phrases from books. You used an L2, and the L2 decided to take your money. You used an exchange and they decided to take your money. You used an exchange and they didn't decide to take your money, but got hacked or just exit scammed everyone at once You installed malware. RAT (remote access trojan). Address replacer, (replaces the address you copied with their address instead of the one you wanted.) You fell for vanity addresses made to look like one you've sent to in the past, but sent to you more recently, so when you look at the block explorer it looks like a previous legit address, same beginning and end, but the middle is different. People have lost lots of millions to this one recently, heck I think it's the majority of gas use on Ethereum now. You gave your coins or money to someone else to invest. They lost it / stole it. You fell for a romance scam or pig butchering scam, or AI boss asked me to send money scam or whatever scam of the day is. You installed an evil browswer extension. The front end you used got DNS hijacked and now points to an evil dapp. The X account you follow got hijacked and is now spreading malware links. You installed an ok browser extension but it got bought by, or exploited by evil and auto updated to evil. You set too wide a slippage trading on a DEX and got nuked. The state takes half ur money, cuz, uh, divorce, or whatever reason. You forget your seed words or don't write them down correctly. Some guy at the airport security just images your device and decides to empty whatever wallet he finds. You left a limit order in a wallet with no funds, but then you send funds one day and the stale order fills at a terrible price. Basically, in computers, physical access defeats most countermeasures, so it's wise to not have any unencrypted seed on any single device in a single place ever. You approved a dapp's permissions, but then one day the dapp gets evil, often by using an "upgradeable" proxy contract, becuase you never removed the permissions, or overapproved, or jsut shouldn't have ever used a contract wiht an upgradeable proxy ever, anyway. Oh, yeah, you install malware by doing a job interview, or talking to a reporter, but they're actually just scammers. Devs also fall for this by cloning repo's and installing whatever evil is in them. So the impersonation thing, whether it's for interviews, or investors, or getting hired is a very, very common vector for getting people to install viruses on their machines. People also fall for other kinds of impersonation, people pretending to be their boss, or pretending they need bailed out using AI vids. You use anything with an admin key. I could probably think of more, and I've mentioned the majority of these on here before. Feel free to add.











UPDATE: BTC Losses linked to the Coldcard wallet vulnerability have now climbed to $70 million, per Galaxy Research. Nearly 1,200 addresses have reportedly been drained, with more than 1,000 BTC stolen as the scale of the exploit continues to grow.





