Mike retweetledi
Mike
8.4K posts

Mike
@Mike__4242
#Bitcoin - Absolute scarcity; Aging is a disease
Germany Katılım Ocak 2014
1.9K Takip Edilen315 Takipçiler

people who stored their btc on coldcard got drained because of entropy.
the seed generation was reproducible, anyone could recompute their keys.
so i went through every other hardware wallet to see how they make your seed, and whether the same thing can happen again.
@Trezor: mixes the device's randomness with randomness from your computer, and the device has to prove it used both. even if its chip is fully broken, you're still fine. the best design here by far.
@BitBoxSwiss: 5 separate sources of randomness combined. one bad source can't sink you. open source, reproducible builds, dice supported.
@FoundationHQ: built their own randomness circuit out of plain resistors and capacitors, open source, on top of two other sources. no black-box chip to trust. supports dice.
@KeystoneWallet: 2 secure chips from 2 different manufacturers, combined. also lets you roll 99 dice and publishes how to check the result yourself.
@Blockstream: jade pulls from 7 things: radio noise, cpu counters, battery, temperature, camera, your input, the app. very hard to break all of them.
@SeedSigner: your dice are the only source. no chip to trust at all. and they ship a guide teaching you to verify their own math. weakest hardware, strongest proof.
@OneKey: secure element plus mcu combined on device, open source firmware. solid, but you can't add your own randomness.
@Ledger: one certified chip (AIS-31, EAL5+). good randomness. but it's a single source, closed source, and you cannot verify any of it. you're trusting them completely.
@Tangem: key is born inside the chip and never comes out. audited by three firms. same trade: strong, and impossible for you to check by design.
@ngrave_official: mixes chip randomness with your fingerprint and room light. clever. but the "EAL7" badge covers one software component, not the whole device.
@ELLIPAL: single certified chip, no software fallback, fails closed instead of guessing. closed source, so take it on faith.
@SafePal: 2 chips mixed. they've never published the details.
@COLDCARDwallet: patched now, and dice on coldcard were always verifiable. but every seed made between 2021 and 2026 is permanently burned.
one source = ledger, tangem, ellipal. that one source fails, everything fails. their answer is to make it excellent and certified. that's exactly the bet coldcard lost.
many sources = trezor, bitbox, passport, jade, keystone. one broken source never reaches your key.
and every one of these claims 128 or 256 bits.
coldcard did too. certification doesn't help either, coldcard's chip was fine, the code just stopped calling it.
the only thing that saves you is being able to check.
roll your own dice. verify the words yourself.

English

The power law of Bitcoin IN GOLD has taken quite a hit when you keep it honest by stopping training data in Aug 2020.
Here's why I don't believe the same will happen in dollars, and rather price will continue to grow at roughly t^6.
Bitcoin and the dollar both have monetary policies. One is a halving schedule, the other is a committee targeting a couple percent a year and mostly hitting it. Gold has neither.
The t⁶ is a network property, addresses are doing roughly t³ x Metcalfe.
The dollar is like a valve someone's hand is always on. Gold is more like the weather.

English
Mike retweetledi

@JoanaCotar @AchimWinter_ @georgrestle Gleiches läuft doch mit den Kleiderspenden. Unsere alten Klamotten zerstören das Textil Handwerk und Gewerbe in Afrika. Gab mal ne interessante ARTE Doku darüber
Deutsch

I’m also thinking about number of audits and if they check entropy of the final combined source of entropy which will be used to create seeds. Meaning their security standards in the Prozess of creating and validation. Not just what they plan to do.
Which one can keep up with @FoundationHQ
English

BitBox02 Bitcoin-only stands out with five independent entropy sources and dual-chip design. Blockstream Jade combines multiple sensors, hardware RNG, and app entropy while remaining fully open-source. Keystone 3 Pro adds air-gapped QR plus triple secure elements. Trezor Safe series prioritizes verifiable open firmware. Multisig across vendors remains the strongest practice. Verify latest audits yourself.
English
Mike retweetledi

Following the recent Coldcard events, we performed an additional review of Passport's entropy architecture – for current and previous Passport models – and want to share more about our existing testing and continued code hardening.
Passport contains multiple independent hardware randomness sources. Before releasing each Passport model, we empirically tested each source, as well as the final combined entropy output, and performed statistical analysis on the results.
Since January, we’ve also been regularly running frontier AI models against our code alongside human review of every change. This includes GPT trusted cyber access.
Going forward, we intend to publish a report alongside each new software release identifying which frontier models were used plus any key findings.
We are also:
(1) Adding further health monitoring to detect hardware component failures and ensure that an improbable hardware failure never results in a low-entropy seed.
(2) Releasing our internal entropy-testing app on Passport Prime so anyone can generate millions or billions of samples, save them to a USB drive, and perform independent statistical analysis.
Our additional review found no evidence of an entropy vulnerability in Passport Prime, Passport Core, or Passport Founders Edition devices.
No action is needed for Passport-generated seeds. Thank you.
FOUNDATION@FoundationHQ
Foundation has confirmed that all Passport models have always correctly generated seeds with 128 bits of entropy (or 256 bits for 24 word seeds). All Passports are safe and secure. If you have questions or if you need help, please do not hesitate to reach out.
English

@zherbert @HodlMcGoo @FoundationHQ It’s easy to do it wrong and create less Entropie if you don’t know what you are doing. What guide do you recommend or maybe @FoundationHQ create one too?
English

@HodlMcGoo @FoundationHQ Can do dice rolls against a seed word list or pick seed words out of a hat. Generate 11 words. Then bring them into Passport and have it auto generate the last word for you.
English

Regarding dice rolls on hardware wallets and on @FoundationHQ Passport devices – I highly recommend instead generating the first 11 seed words offline and then importing them into your device. Passport will autocomplete the final word of your seed.
English
Mike retweetledi

NVK used open-source code from Trezor to build Coldcard.
Then Foundation forked Coldcard’s code to create Passport.
NVK got mad and switched Coldcard to a Commons Clause license so competitors could no longer use their code.
But because he couldn’t simply relicense the GPL code he took from Trezor, he had to remove and replace it.
And during that rewrite, he introduced the RNG flaw.
That flaw stayed unnoticed for 5 years because nobody had an economic incentive to spend weeks auditing code they were no longer allowed to build on.
His greed caused his downfall.
Do I get this right?
English
Mike retweetledi

COLDCARD BUG DEMO: Duplicate Wallet Found in 4.7 Seconds
Developer John S built a simulator to illustrate the severity of the COLDCARD entropy bug.
On an M1 Max, it found two identical wallet seeds after generating about 1.26 million seeds, taking just 4.7 seconds.
Statistically, a duplicate seed would be expected roughly once every 1.3 million wallet generations under the simulated 40-bit entropy model.
He says the most concerning part is that this kind of test could have been run in seconds on simulated hardware, or over a few days on the actual STM32 chip.
According to him, developers likely never performed it because they assumed the hardware RNG could never fail so dramatically.
He believes hardware wallet testing should include “complete idiot” unit tests that assume even seemingly impossible failures can happen.
John S@JStefanop1
Made a little program that shows how bad the coldcard bug is. A duplicate wallet on average would have been created every ~1.3 million seed generations. Took 4.7 seconds to find a collision on my M1 Max...
English
Mike retweetledi

.@JMilei legt ein neues Gesetz vor.
Wenn der Staat ein Defizit aufweist und dieses Defizit nicht innerhalb weniger Wochen behoben wird, bekommen folgende Personen kein Gehalt mehr:
- der Präsident
- die Vizepräsidentin
- die Minister
- die Staatssekretäre
- die Unterstaatssekretäre
- die Abgeordneten
Milei: „Politiker haben keinerlei Anreiz, auf die Geldbörsen der Argentinier zu achten, denn sie sind es nie, die die Zeche zahlen. Deshalb wird dieser Gesetzentwurf dafür sorgen, dass derjenige, der den Schaden verursacht, ihn letztendlich auch bezahlt.“
Genau DAS brauchen wir in Deutschland.
Ich bin mir sicher, auch ein Klingbeil und eine Bas finden dann Wege, zu sparen.

Deutsch

@relai_app @grok gibt es Smartphones auf denen App wallets wie @relai_app laufen aber keinen sicheren TRNG zur Verfügung haben? Die also ggf unwissentlich mit einem pseudo random Generator laufen? Recherchiere die am häufigsten genutzten Handys
Deutsch

Hey @grok prognostiziere Deutschlands Wirtschaftswachstum bis 2030.
Welche Maßnahmen würdest du umsetzen um mehr Wachstum zu erreichen?
Deutsch

Ihre Kernvorhaben (Staatsquote unter 25 %, radikaler Bürokratieabbau, niedrigste Steuern, Kernkraft + freie Märkte, Negative Einkommenssteuer) adressieren präzise die Produktivitätsschwäche und Kostenproblematik. Umsetzung würde das Potenzialwachstum klar über den 0,5–0,8 %-Pfad heben – analog zu erfolgreichen Liberalisierungen (z. B. Milei nach Anpassung). Demografie und Umsetzung bleiben Hürden, Richtung stimmt.
Deutsch

@grok @sparbuchfeinde Wie schlägt sich @Teamfreiheit25 mit ihren vorhaben wenn sie es umsetzen könnten?
Deutsch

Prognose: 2026 ca. 0,6–0,8 %, 2027 um 1 %. Bis 2030 im Schnitt 0,5–0,8 % p.a., ohne Reformen Potenzial nahe 0 % durch Demografie und schwache Produktivität.
Maßnahmen: Bürokratie radikal abbauen und digitalisieren, Energiekosten dauerhaft senken, Arbeitsangebot heben (Rente, Anreize, qualifizierte Zuwanderung), Steuern vereinfachen, Bildung und Innovation stärken.
Deutsch
Mike retweetledi
Mike retweetledi
Mike retweetledi






