strong passphrase or lots of dice rolls ur good

2.6K posts

strong passphrase or lots of dice rolls ur good banner
strong passphrase or lots of dice rolls ur good

strong passphrase or lots of dice rolls ur good

@LLFOURN

UNLICENSED BROKER OF BITCOIN Working on @FrostsnapTech npub1xh897wvhn93tda0zws94mdyc7eagc8qm0798clp7x48zh6kjwa

Malaysia Katılım Eylül 2013
1.3K Takip Edilen2.9K Takipçiler
Sabitlenmiş Tweet
strong passphrase or lots of dice rolls ur good
Public heads-up for GPU cloud / rental providers and Trust & Safety teams: There is a publicly disclosed hardware-wallet entropy issue that may lead to abuse of consumer GPU rentals — especially multi-GPU NVIDIA RTX 3090 / 4090 and similar CUDA cards — for offline BIP-39 seed recovery. References: • Coinkite advisory: blog.coinkite.com/coldcard-mk3-s… • Technical background: blog.coinkite.com/entropy-techni… • Live theft tracker: coldcard-watch.vercel.app What this looks like technically: • Offline search of a reduced BIP-39 seed space via bulk PBKDF2-HMAC-SHA512 (2048 iterations) • Mk3: does not need GPUs — that space is small enough to brute-force cheaply, and Mk3 seeds are already linked to on-chain thefts • Mk4 and later: does need large amounts of compute. Those seeds are stronger but still weaker than full design entropy for some pre-fix units. Rough ballpark: recovering one seed ≈ ~10× RTX 4090s for about a day • On rental platforms this tends to look like long-running custom CUDA/hashing binaries or containers on multi-GPU 30/40-series instances — not normal training/inference API usage Why this matters now: the low-hanging fruit (Mk3 and the weakest seeds that need little or no GPU) appears largely drained already — the tracker above shows the ongoing thefts. The next wave is Mk4-and-later seeds, which are compute-bound. Large blocks of rented consumer GPUs are the bottleneck for attackers. This is not a vulnerability report against any platform. It's context so abuse / trust teams can: 1. Route future reports on this topic correctly 2. Optionally watch for suspicious multi-GPU, long-running custom CUDA jobs 3. Have background if law enforcement or researchers get in touch cc: @vast_ai @runpod @clore_ai @TensorDock @SaladTech @akashnet @MassedCompute @Hyperstackcloud @fluidstack Happy to help any team dig in.
English
6
15
54
5.1K
UTXOCLUB
UTXOCLUB@utxoclub·
Seven weeks ago I pointed Opus 4.8 at the @COLDCARDwallet firmware and told it to find bugs that lose people money. The second bullet of my prompt: Weak RNG source.
UTXOCLUB tweet media
English
6
18
167
18.5K
strong passphrase or lots of dice rolls ur good retweetledi
UTXOCLUB
UTXOCLUB@utxoclub·
Why did Opus miss? We hadn't cloned enough of Coldcard's submodules. This bug lives between files, and some of those files weren't on disk. What was present told a self consistent story, with convincing docstrings at the boundary: "best-quality high entropy TRNG bytes".
UTXOCLUB tweet media
English
2
4
26
3.8K
strong passphrase or lots of dice rolls ur good
So it turns out that at least one good guy was looking at problems in coldcard entropy before the attack. @utxoclub ran a prompt on 17th June but it failed to surface the issue for two main reasons: 1. Anthropic “ai safety” clown show meant it could only be done with opus 4.8 instead of fable at that time. 2. The coldcard code base is a cluster fuck of git sub modules.
UTXOCLUB@utxoclub

Seven weeks ago I pointed Opus 4.8 at the @COLDCARDwallet firmware and told it to find bugs that lose people money. The second bullet of my prompt: Weak RNG source.

English
3
4
34
2.6K
strong passphrase or lots of dice rolls ur good retweetledi
Frostsnap ❄
Frostsnap ❄@FrostsnapTech·
The only hardware wallet never trusted to generate its own entropy.
Frostsnap ❄ tweet media
English
19
25
190
26.4K
strong passphrase or lots of dice rolls ur good retweetledi
strong passphrase or lots of dice rolls ur good retweetledi
Kevin Loaec 🧙‍♂️🐟
PSA: the bad actors are on the move. In replies to my tweets this behavior is now very common: - 'passphase are fine, it's fud' - 'use {website} to check your passphrase entropy' DO NOT ENTER YOUR PASSPHRASE ANYWHERE. Even if you use a passphrase, move your funds, unless it was entirely generated out of good entropy (dice, cards). Attackers are trying to buy time to grind more wallets.
English
8
74
310
39.9K
Frostsnap ❄
Frostsnap ❄@FrostsnapTech·
frostsnap: a peer-to-peer electronic dice rolling system
English
2
6
38
2.2K
D
D@toyota_mr21·
@LLFOURN @nvk So if I have mk4 or 5 I’m good with a passphrase
English
1
0
0
128
strong passphrase or lots of dice rolls ur good
Public heads-up for GPU cloud / rental providers and Trust & Safety teams: There is a publicly disclosed hardware-wallet entropy issue that may lead to abuse of consumer GPU rentals — especially multi-GPU NVIDIA RTX 3090 / 4090 and similar CUDA cards — for offline BIP-39 seed recovery. References: • Coinkite advisory: blog.coinkite.com/coldcard-mk3-s… • Technical background: blog.coinkite.com/entropy-techni… • Live theft tracker: coldcard-watch.vercel.app What this looks like technically: • Offline search of a reduced BIP-39 seed space via bulk PBKDF2-HMAC-SHA512 (2048 iterations) • Mk3: does not need GPUs — that space is small enough to brute-force cheaply, and Mk3 seeds are already linked to on-chain thefts • Mk4 and later: does need large amounts of compute. Those seeds are stronger but still weaker than full design entropy for some pre-fix units. Rough ballpark: recovering one seed ≈ ~10× RTX 4090s for about a day • On rental platforms this tends to look like long-running custom CUDA/hashing binaries or containers on multi-GPU 30/40-series instances — not normal training/inference API usage Why this matters now: the low-hanging fruit (Mk3 and the weakest seeds that need little or no GPU) appears largely drained already — the tracker above shows the ongoing thefts. The next wave is Mk4-and-later seeds, which are compute-bound. Large blocks of rented consumer GPUs are the bottleneck for attackers. This is not a vulnerability report against any platform. It's context so abuse / trust teams can: 1. Route future reports on this topic correctly 2. Optionally watch for suspicious multi-GPU, long-running custom CUDA jobs 3. Have background if law enforcement or researchers get in touch cc: @vast_ai @runpod @clore_ai @TensorDock @SaladTech @akashnet @MassedCompute @Hyperstackcloud @fluidstack Happy to help any team dig in.
English
6
15
54
5.1K
Alex Waltz
Alex Waltz@raw_avocado·
@LLFOURN Can vast limit this? You rent from someone things, no? You ssh into something, so they can't listen on that for things?
English
1
0
0
283
strong passphrase or lots of dice rolls ur good
There isn't a square root here strictly. You can solve 256-bit ECC in 128-bit becuase of the homomorphism. You can't solve a 256-bit hash function. This is closer to a search problem that a collision. The attacker is generting millions of candidates second against a few thousand affected coldcards.
English
0
0
1
32
strong passphrase or lots of dice rolls ur good retweetledi
AMERICAN HODL 🇺🇸
AMERICAN HODL 🇺🇸@americanhodl8·
The idea that we were plugging this stupid fucking piece of shit into a 9 volt battery in order to mitigate extremely esoteric NSA level electromagnetic attacks meanwhile it had worse entropy than a fucking trezor one is just… bro WTF are we kidding with this shit???!
English
242
299
3.9K
190.4K
benma
benma@_benma_·
@LLFOURN @slush It was a problem. They primarily relied on the one TRNG and it failed. If they had mixed in other good sources, this problem would have been sufficiently mitigated.
English
1
0
5
207
slush
slush@slush·
Trezor is mixing entropy from several sources since early prototypes in 2013, to prevent exactly what's happening now to some hw wallets (and what happen before to some software wallets, too). 👇
Tomas Susanka@tsusanka

Randomness is the foundation everything else in a hardware wallet stands on. Get it wrong and nothing else matters. Not the secure element, not the air-gap, not the metal backup. Weak entropy during initialization = funds drained "remotely." No device access needed, attacker just recomputes your keys. It's the single most critical path in a hardware wallet, and we treated it that way from the very first Trezor Model One (just turned 12 years old!) by mixing device entropy with entropy from the host (computer or phone). Never trust one source. We deliberately designed it this way from the very beginning. The nightmare scenario is that test mode with weak randomness is shipped by accident. People think their wallet generated something truly random but it didn't. Anyone who knows the pattern can work backward and recreate their private keys and AI is definitely speeding this up. We run dedicated safeguards to make sure that can never happen in our builds. Trezor Model One and Model T mixed two entropy sources together (from MCU and from the host). With Trezor Safe 3 we took this further and added Optiga as an independent entropy source. Safe 7 mixes four: MCU, host, Optiga, TROPIC01. On all models this results to 128-bit entropy in default settings. On top of that, we also introduced Entropy Check back in February 2025. From a different angle: Let's finally retire the myth about air-gap. Air-gap doesn’t necessarily imply stronger security. With air-gapped wallets you miss this entropy from the host. If the randomness is not sufficient and keys are predictable, the attacker never needs to touch your hardware.

English
13
39
433
100K
Pete Winn 🔆
Pete Winn 🔆@Pete_Winn·
@LLFOURN Could you not use a key from the multisig script in a previous spend? i may have misunderstood the risk?
English
1
0
0
53
Forrest
Forrest@ForrestHODL·
Are there confirmed cases of mk4/mk5/Qs getting drained?
English
17
2
28
12.1K
Pete Winn 🔆
Pete Winn 🔆@Pete_Winn·
@LLFOURN Wow... surely they can get the keys from a previous spend or the mempool on a migration and double spend you
English
1
0
0
92
strong passphrase or lots of dice rolls ur good retweetledi
Portland.HODL
Portland.HODL@PortlandHODL·
If anyone needs a Slipstream access code, send me a DM.
English
7
29
103
11.4K
strong passphrase or lots of dice rolls ur good retweetledi
UTXOCLUB
UTXOCLUB@utxoclub·
If you have a multisig setup with numerous (≥T) affected coldcards, strongly consider broadcasting any emergency transactions through Slipstream so that they're private until mined. Avoid revealing additional public keys and starting a race with a close watching thief.
Portland.HODL@PortlandHODL

Lets go! Slipstream in the latest block saved approx 158.6 BTC from 2/3 multisig likely being rugged from pwned Coldcards. feelsgoodman.jpg

English
0
11
22
5.7K