
strong passphrase or lots of dice rolls ur good
2.6K posts

strong passphrase or lots of dice rolls ur good
@LLFOURN
UNLICENSED BROKER OF BITCOIN Working on @FrostsnapTech npub1xh897wvhn93tda0zws94mdyc7eagc8qm0798clp7x48zh6kjwa




Full stop: this bug is insane, and just purely inexcusable. But the timing of the exploit is literally right after Kimi released open weights for a frontier quality model (specifically without safeguards). My understanding is Coldcard has been audited by US frontier models, and it did not locate or identify this. Kimi was used by multiple people that I know to verify and reproduce this issue. It's undeniable that Kimi played a role in this specific bug being isolated and exploited. That's not relevant to the fault, or blame, that is on Coinkite, but it is nonetheless a serious factor to consider and appreciate looking at the wider ecosystem.



MK4s are vulenerable but are millions of times harder to steal from. MK3s can be stolen from a decent laptop, mk4,5s and Q would need much more compute. The model: - attacker has a roughly 2^20 UUID range that it knows cold cards fall in - checks a 16 button press variancer in user behavior before generating the seed You should still promptly remove funds from mk4,mk5 and Q.





Seven weeks ago I pointed Opus 4.8 at the @COLDCARDwallet firmware and told it to find bugs that lose people money. The second bullet of my prompt: Weak RNG source.

An acquaintance of mine intentionally left a small amount of bitcoin in a ColdCard MK4 RNG created seed phrase (that was originally a "duress" wallet) to see when it might get swept. Last night it got swept to bc1qzm5pauxyv7t7vqstzpumqcn066wfjsmev34mf3. So at this point any RNG generated seedphrase on any ColdCard product is under active attack. Move quickly if you're exposed.








Randomness is the foundation everything else in a hardware wallet stands on. Get it wrong and nothing else matters. Not the secure element, not the air-gap, not the metal backup. Weak entropy during initialization = funds drained "remotely." No device access needed, attacker just recomputes your keys. It's the single most critical path in a hardware wallet, and we treated it that way from the very first Trezor Model One (just turned 12 years old!) by mixing device entropy with entropy from the host (computer or phone). Never trust one source. We deliberately designed it this way from the very beginning. The nightmare scenario is that test mode with weak randomness is shipped by accident. People think their wallet generated something truly random but it didn't. Anyone who knows the pattern can work backward and recreate their private keys and AI is definitely speeding this up. We run dedicated safeguards to make sure that can never happen in our builds. Trezor Model One and Model T mixed two entropy sources together (from MCU and from the host). With Trezor Safe 3 we took this further and added Optiga as an independent entropy source. Safe 7 mixes four: MCU, host, Optiga, TROPIC01. On all models this results to 128-bit entropy in default settings. On top of that, we also introduced Entropy Check back in February 2025. From a different angle: Let's finally retire the myth about air-gap. Air-gap doesn’t necessarily imply stronger security. With air-gapped wallets you miss this entropy from the host. If the randomness is not sufficient and keys are predictable, the attacker never needs to touch your hardware.






Lets go! Slipstream in the latest block saved approx 158.6 BTC from 2/3 multisig likely being rugged from pwned Coldcards. feelsgoodman.jpg








