RayRay

8.7K posts

RayRay banner
RayRay

RayRay

@TruthyRay

#lickface

Katılım Aralık 2008
666 Takip Edilen113 Takipçiler
Unit of a Count
Unit of a Count@countbitcoin·
Imagine: having 5 Coldcards MultiSig MK3's jurisdictionally separated around the world RN Fucking Nightmare
English
20
15
316
20.2K
RayRay
RayRay@TruthyRay·
@Scavacini777 Slipstream for now. But ai will be perpetually looking for this exploit. So it's important to get those comprised coins moved to a safe address.
English
0
0
1
47
VANITY FAIR
VANITY FAIR@VanityFair·
Andrew Tate's lawyer has a warning for the GOP: “If Trump doesn’t support him, and if the next people who are going to be running for office potentially are just like, yeah, down the river he goes, that young cohort of people will break with the Republican Party in the next election" vanityfair.visitlink.me/EK0c9w
English
71
33
139
536.2K
RayRay
RayRay@TruthyRay·
@BraddrofliT Of all the people in the world who this should happen to, it's Mitch McConnell.
English
0
0
0
42
RayRay
RayRay@TruthyRay·
@BraddrofliT Just announce an election and make them roll his weekend at Bernie's ass out. This isn't hard.
English
2
0
2
437
Brad
Brad@BraddrofliT·
If it is true that Mitch McConnell died before the “proof of life” photo was released on July 12, as Kentucky Gov. Andy Beshear claims, this is a SERIOUS crime and those responsible MUST be prosecuted and put behind bars under the maximum sentence.
English
450
4.6K
31.7K
524K
RayRay
RayRay@TruthyRay·
@Self_Sovereign_ @JoeyTweeets There will be wallets still standing after this AI wave passes, and everything will be "mythos tested" marketed or whatever. Antifragile meme persists. I think.
English
0
0
0
12
Jordan
Jordan@Self_Sovereign_·
@JoeyTweeets A couple of months ago everybody panicked over quantum being able to break bitcoin in a matter of years Little did they know AI was going to do it in a matter of months. It might actually be over.
English
1
0
1
284
JOEY
JOEY@JoeyTweeets·
What the fuck
Scott Marmoll@bitcoinsbanker

Thanks to a generous credit of tokens from @PPQdotAI , Kimi K3 and an ape with a laptop (me) have conducted the following analysis of a bunch of projects / companies wallet softwares. @Coinkite , @OPENDIME , @SeedSigner , @Bitkey , @bluewalletio , @PhoenixWallet , @SparrowWallet , @Trezor , @Blockstream , @Ledger , @BitBoxSwiss , @SpecterDIY , @ElectrumWallet , @SamouraiWallet 🟡 Yellow ≠ broken. None of the nine Yellow products has a confirmed fund-loss-by-default flaw. Yellow means at least one of: (a) something security-critical sits outside independent verification. i.e., closed firmware or secure-element code (Opendime, Ledger, open source please!), vendor-run recovery infrastructure (Phoenix/ACINQ, Jade's oracle, Bitkey's WSM); (b) a real but bounded weakness, such as a zero-work-factor KDF (BlueWallet), weak legacy KDFs on a hot wallet (Electrum), no-SE DIY hardware with thin maintenance (SpecterDIY), a just-patched vulnerability awaiting its report (Bitkey); or (c) a dead/unmaintained product whose crypto reviewed clean (free Samourai!). In every case the entropy/key-generation path itself was reviewed and found sound unless the cell says otherwise.

English
5
1
23
10.6K
Scott Marmoll
Scott Marmoll@bitcoinsbanker·
Thanks to a generous credit of tokens from @PPQdotAI , Kimi K3 and an ape with a laptop (me) have conducted the following analysis of a bunch of projects / companies wallet softwares. @Coinkite , @OPENDIME , @SeedSigner , @Bitkey , @bluewalletio , @PhoenixWallet , @SparrowWallet , @Trezor , @Blockstream , @Ledger , @BitBoxSwiss , @SpecterDIY , @ElectrumWallet , @SamouraiWallet 🟡 Yellow ≠ broken. None of the nine Yellow products has a confirmed fund-loss-by-default flaw. Yellow means at least one of: (a) something security-critical sits outside independent verification. i.e., closed firmware or secure-element code (Opendime, Ledger, open source please!), vendor-run recovery infrastructure (Phoenix/ACINQ, Jade's oracle, Bitkey's WSM); (b) a real but bounded weakness, such as a zero-work-factor KDF (BlueWallet), weak legacy KDFs on a hot wallet (Electrum), no-SE DIY hardware with thin maintenance (SpecterDIY), a just-patched vulnerability awaiting its report (Bitkey); or (c) a dead/unmaintained product whose crypto reviewed clean (free Samourai!). In every case the entropy/key-generation path itself was reviewed and found sound unless the cell says otherwise.
Scott Marmoll tweet media
English
87
169
702
115.2K
RayRay
RayRay@TruthyRay·
@HeerJeet not counting the black people is a tell.
English
0
0
1
845
RayRay
RayRay@TruthyRay·
@SatoshiBagger Maybe if they had that level of generosity when other wallets had issues. But no, they just shrugged with a smirk and said they were unaffected and offered a discount code. F em. Off to the dustbin.
English
1
0
2
15
Satoshi Bagger
Satoshi Bagger@SatoshiBagger·
Honestly: Do you think Coinkite and their Coldcard can recover from this? At work I sometimes prefer working with someone that has made a mistake and learnt from it...
English
16
1
9
847
RayRay
RayRay@TruthyRay·
@mechanakamoto Arrogance. Skeleton staff. Spent more money on marketing than security. Should cease to exist.
English
0
0
0
49
Mecha Nakamoto
Mecha Nakamoto@mechanakamoto·
Bitcoiners What U think about the ColdCard thing? Be real
English
170
1
58
14.2K
RayRay
RayRay@TruthyRay·
@tsusanka @em Does the entropy test only at initiation of the seed, or does it check each time the wallet is connected to the suite? I read it twice and am not sure. Example, say I created a seed years ago, will the suite be checking the randomness of the seed later on? If I recovered?
English
1
0
1
108
Tomas Susanka
Tomas Susanka@tsusanka·
Randomness is the foundation everything else in a hardware wallet stands on. Get it wrong and nothing else matters. Not the secure element, not the air-gap, not the metal backup. Weak entropy during initialization = funds drained "remotely." No device access needed, attacker just recomputes your keys. It's the single most critical path in a hardware wallet, and we treated it that way from the very first Trezor Model One (just turned 12 years old!) by mixing device entropy with entropy from the host (computer or phone). Never trust one source. We deliberately designed it this way from the very beginning. The nightmare scenario is that test mode with weak randomness is shipped by accident. People think their wallet generated something truly random but it didn't. Anyone who knows the pattern can work backward and recreate their private keys and AI is definitely speeding this up. We run dedicated safeguards to make sure that can never happen in our builds. Trezor Model One and Model T mixed two entropy sources together (from MCU and from the host). With Trezor Safe 3 we took this further and added Optiga as an independent entropy source. Safe 7 mixes four: MCU, host, Optiga, TROPIC01. On all models this results to 128-bit entropy in default settings. On top of that, we also introduced Entropy Check back in February 2025. From a different angle: Let's finally retire the myth about air-gap. Air-gap doesn’t necessarily imply stronger security. With air-gapped wallets you miss this entropy from the host. If the randomness is not sufficient and keys are predictable, the attacker never needs to touch your hardware.
English
51
102
810
130.1K
Brad Mills 🔑⚡️
Brad Mills 🔑⚡️@bradmillscan·
I’m incredibly surprised Bitcoin has not sold off to make new lows on this hack news. If this does not drop us below 58k then that was likely the cycle bottom.
English
59
10
317
23.9K
RayRay
RayRay@TruthyRay·
@JamesKhoroshin @_t_o_o_r_a_j_ The logic is that computers and hardware by their very nature are deterministic. Making deterministic machines create random numbers might be impossible to guarantee.
English
0
0
3
141
Adonisman
Adonisman@JamesKhoroshin·
@_t_o_o_r_a_j_ Why is that ? Are you saying that all wallets random generators are faulty?
English
2
0
3
518
T o o r a j - ₿⚡ ∞/21M
If you used your wallet's seed-word generation logic instead of rolling your own seed words, no matter which wallet you use, you are at risk. Perhaps not at immediate risk, but at risk.
English
9
4
49
4.5K
Mr.Hodl
Mr.Hodl@MrHodl·
Just spoke to an MK3 user who didn't use dice. Their short passphrase wasn't brute-forced yet, funds are safe. Doesn't look like they're grinding passphrases yet. Don't wait! Create a new private key ASAP. If you're in America, Best Buy sells @Bitkey and @ledger. GO TO THE STORE RIGHT NOW AND GET A NEW HARDWARE DEVICE.
English
33
40
322
33.5K
RayRay
RayRay@TruthyRay·
Wondering how MK3 addresses were identified. Was there a similarity in the actual addresses? Was only the /84 path addresses easily identified? Was only a subset of addresses identifiable? Why would that be?
English
0
0
1
32
BTC Teacher
BTC Teacher@BitcoinTeacher_·
@Scavacini777 @grok Bro jus get a new wallet it isn’t worth it. Grok doesn’t know if you are at risk
English
2
0
6
1.1K
₿TC-GUS🧡🪢
₿TC-GUS🧡🪢@Scavacini777·
So @grok since I rolled dice to generate my ColdCard MK3 seed phrase in 2023 then my seed wasn't really at risk?
English
9
0
16
16.6K
shaquille o'atmeal
shaquille o'atmeal@crypt0e·
I've used Trezor's seed generator; how effed am I?
English
24
1
72
27.9K
RayRay
RayRay@TruthyRay·
@JoeCarlasare @Trezor @Ledger Trezor uses a random number generator on the device combined with a random number generator from the host computer that it's using during seed generation. So if the trezor RNG was compromised, the seed would still have entropy from the RNG on the computer. So should be fine.
English
1
0
3
3.6K
RayRay
RayRay@TruthyRay·
@BreeNewsome Apparently the good guy with a gun wasn’t the only way to combat a bad guy with a gun.
English
0
0
0
282