ʇɹɥɐW uıɯƎ ⚡Nuri.com

21.7K posts

ʇɹɥɐW uıɯƎ ⚡Nuri.com banner
ʇɹɥɐW uıɯƎ ⚡Nuri.com

ʇɹɥɐW uıɯƎ ⚡Nuri.com

@em

Get Reach or Die Tryin’ https://t.co/4x0YV0fzqI Bitcoin & Non-Custodial Banking

Bitcoin Katılım Ocak 2009
7.3K Takip Edilen2.9K Takipçiler
ʇɹɥɐW uıɯƎ ⚡Nuri.com
Ok interesting. I need one to test if I can generate a valid key like its advertised everywhere but I haven't been able to do so except when I know the UID of a device, so I believe thats the key to this whole thing... I need a real affected device though to proof it, waiting for my order to arrive to do so. Will publish my report later on GitHub but I burned through so many token and GPU compute by now that I either do something totally wrong or it's not as easy as advertised to actually get into those things without having some more information.
English
1
0
0
25
Pledditor
Pledditor@Pledditor·
Wow. It's true 😬 They updated the website since I made this tweet (likely in reaction I assume). They added a new disclosure that these devices have the old bugged firmware. Instead of halting sales, they are choosing to sell the remaining stock of bugged units. Abhorrent
Pledditor tweet media
Pledditor@Pledditor

Wow. If this is true, this is abhorrent. @ODELLXYZ @MartyBent @ten31funds I know you are shareholders. Does this company have a board? Where is the corporate governance? This should not be happening. x.com/i/grok/share/8…

English
60
55
598
52.1K
Ledger
Ledger@Ledger·
Not completely. We strongly believe in an open-source approach. It's a great set of principles that advocates openness and transparency, some of our core values. That's why we're constantly working towards making source code components available, reviewable, and auditable. Importantly, a majority of Ledger's code is open source, including Ledger Wallet™, Wallet API, Secure SDK, and embedded applications on our devices. Ledger takes transparency seriously. Our proprietary software is essential for the security of the Secure Elements, which utilize advanced technology from trusted manufacturers to implement hardware countermeasures against potential attacks, even with physical access. Some code is tied to the Secure Element's security peripherals, which are proprietary intellectual property of the manufacturer. Revealing this would compromise the very security we aim to protect. You can learn more about our approach to open-source software in this article: support.ledger.com/article/111323…
English
10
6
74
5.1K
ʇɹɥɐW uıɯƎ ⚡Nuri.com
bitcoin game theory, holder have no incentive to cause panic to lower the price of bitcoin, this is a security mechanism built into bitcoin from day one and somehow even documented in the white paper, its dangerous though if the word does not get out because of this, but I think it got out to the people that must hear this - the wallet developers.
English
0
0
0
7
Dr. Margot Paez
Dr. Margot Paez@jyn_urso·
@thetrocro @basedlayer It’s still a small amount of bitcoin comparatively speaking to the total amount of issued bitcoin. But given how institutions are custodial they probably feel immune to this retail damage.
English
1
0
1
117
ʇɹɥɐW uıɯƎ ⚡Nuri.com
@MagicalTux @COLDCARDwallet @Pledditor trying to proof the hack like I do? I still think without knowing the UIDs it's hard to impossible to actually crack this. I have running many GPUs since days and have not been able to produce a valid signature from any of the drained addresses, will publish a report soon.
English
1
0
0
50
ʇɹɥɐW uıɯƎ ⚡Nuri.com retweetledi
Satochip
Satochip@satochip·
@ozsats256 I would not recommend Tangem at all… too many red flags here.
English
0
1
2
67
ʇɹɥɐW uıɯƎ ⚡Nuri.com
@nuri (beta) technical design and target audience is similar. We're trying to step in your shoes, being the onchain @CashApp with the similar security promises like @Bitkey. Nuri is cheap secure self-custody for the masses. - passkey prf derived seeds - seedless by default - musig2 by default - cosigning passkey auth gated - recoverable only with the user key - we do not hold any user keys (technically not even the cosigning key) - architecture that allows guardians - a hardware wallet with biometrics (nfc card) fully open source github.com/nuri-com/nuri-… - full bitcoin lightning support feel free to take a look and connect / share ideas. I am following your product closely and I I think you are doing everything right!
English
0
0
0
15
mcshane
mcshane@mcshane_capital·
know many people who simply moved funds to @Bitkey been extremely critical of seedless in the past, but in times of crisis that team showed competence, reliability & leadership. Competition makes Bitcoin better. We need more wallet providers with new ideas.
English
11
4
143
7.9K
Richard Byworth ∞/21M
Richard Byworth ∞/21M@RichardByworth·
I cannot stop thinking about the crime of negligence that the @COLDCARDwallet team committed against some true bitcoiners. These bitcoiners set themselves up between 2021 and 2023, a brutal time in the market, a time that needed real conviction. Conviction that was tested time and time again through the crypto scams, and now they were let down by trusting what was supposed to be one of the industry’s leading hard wallet providers. It’s really heartbreaking. The team behind cold wallet need to do everything in their power to make the victims of their negligence whole.
English
66
33
744
30.2K
calle
calle@callebtc·
It seems like Mk4, Mk5 and Q1 are basically Mk3/2 (trivially exploitable in your laptop) with physical access and targeted attack (with access to the device's UID).
English
8
5
101
12.8K
ʇɹɥɐW uıɯƎ ⚡Nuri.com
Great article thanks for sharing. And it makes sense. I thought you might be able to produce a million numbers, look at them, and "see" that they are non-random. Like having some matching non-random output. Or of course, if you get the same number twice, obviously it's broken. Thanks for answering.
English
0
0
0
14
Tomas Susanka
Tomas Susanka@tsusanka·
Randomness is the foundation everything else in a hardware wallet stands on. Get it wrong and nothing else matters. Not the secure element, not the air-gap, not the metal backup. Weak entropy during initialization = funds drained "remotely." No device access needed, attacker just recomputes your keys. It's the single most critical path in a hardware wallet, and we treated it that way from the very first Trezor Model One (just turned 12 years old!) by mixing device entropy with entropy from the host (computer or phone). Never trust one source. We deliberately designed it this way from the very beginning. The nightmare scenario is that test mode with weak randomness is shipped by accident. People think their wallet generated something truly random but it didn't. Anyone who knows the pattern can work backward and recreate their private keys and AI is definitely speeding this up. We run dedicated safeguards to make sure that can never happen in our builds. Trezor Model One and Model T mixed two entropy sources together (from MCU and from the host). With Trezor Safe 3 we took this further and added Optiga as an independent entropy source. Safe 7 mixes four: MCU, host, Optiga, TROPIC01. On all models this results to 128-bit entropy in default settings. On top of that, we also introduced Entropy Check back in February 2025. From a different angle: Let's finally retire the myth about air-gap. Air-gap doesn’t necessarily imply stronger security. With air-gapped wallets you miss this entropy from the host. If the randomness is not sufficient and keys are predictable, the attacker never needs to touch your hardware.
English
51
99
798
128.1K
beau
beau@itsbeaudean·
Built a small Tasks plugin for @NousResearch Hermes. The UI and the agent both manage the same simple tasks.md file. I can tick something off in the app or ask Hermes to add, complete or reprioritise it in chat. No second database or sync layer. It even works through the Desktop SSH connection to my VPS.
beau tweet media
English
3
0
16
1.9K
Justin Bechler #BIP-110
⚠️ All you need to know: neither @nvk nor any of the Bitcoin celebrities who enabled his abuse lost a single sat.
English
29
31
385
16.9K
Satochip
Satochip@satochip·
@BTC_JEDI21 Do you check Satochip? Open-source javacard running full BIP39 #Bitcoin signing stuffs.
English
1
0
1
199
ʇɹɥɐW uıɯƎ ⚡Nuri.com
I think everyone who claims that you lost funds should sign a message from the drained account and proof it, I think its not so easy to fake that right now, and it would build trust and actually enable donations etc. I think many scammers out there just trying to grab some sats right now.
English
1
0
10
468
🏔Adam🏔
🏔Adam🏔@denverbitcoin·
I might have to spare some sats for this poor guy that apparently lost 8 years of bitcoin savings…absolutely brutal. God speed, good sir 🍻
🏔Adam🏔 tweet media
English
14
2
68
9.9K
DeepSeek
DeepSeek@deepseek_ai·
🚀 DeepSeek-V4-Flash Official API is now LIVE in public beta! 🔷 We’ve massively upgraded its Agent capabilities—benchmark scores are now far surpassing the V4-Pro-Preview. Check out the massive performance leap below! 👇 🔷 The official V4-Flash now natively supports the Responses API format and is fully adapted for Codex! Check out the configuration details in our official API docs: api-docs.deepseek.com/quick_start/ag…
DeepSeek tweet media
English
1.6K
3.4K
28.8K
8.3M
ʇɹɥɐW uıɯƎ ⚡Nuri.com
@cline only way forward is to buy credits, is that correct? How much worse/better are your credits compared to @OpenRouter and others? For example for Kimi K3 (most important) and can I just create multiple 10 usd accounts with you (asking for a friend) instead of waiting for my weekly limit to reset?
ʇɹɥɐW uıɯƎ ⚡Nuri.com tweet media
English
0
1
0
78
ʇɹɥɐW uıɯƎ ⚡Nuri.com
No single point of failure is what we all need to repeat all over again and again in wallet development. I think this is the responsibility of wallet developers. We must make sure that there is no single point of failure and openly show what we do and how we do it to proof it. Open source obviously. The bitcoin lesson is randomness in keys not necessarily multisig. Multisig with two coldcards would not have helped you. Both together like two different keys, with two different sources of randomness, are better of course, but a multisig wallet created with the same private key generation mechanism is not more secure than a single sig.
English
0
0
0
90
Stephan Livera
Stephan Livera@stephanlivera·
The Bitcoin custody lesson for all of us: remove single points of failure. If you can DIY that with dice-roll entropy + multi-vendor multisig, great. If you can’t, there’s no shame in using a guided multisig solution that helps you set it up properly.
English
32
7
112
10.3K
laz1m0v
laz1m0v@laz1m0v·
@em Obviously, but if he's spreading FUD when the numbers aren't good... it means he's trying to sell you something...
English
2
0
1
63
laz1m0v
laz1m0v@laz1m0v·
🚨ALERLT LARPER :"Mk4/Mk5/Q are being drained!!!" Chill. Base entropy was already ~72 bits. Add even a medium passphrase (12-16 solid chars) and you’re sitting on 130-150+ bits total. That’s not “immediate risk”. That’s still harder than most people will ever break. Stop the FUD.
Kevin Loaec 🧙‍♂️🐟@KLoaec

It's happening. Mk4, Mk5, Q are now actively drained. Breaking an Mk4 is HARDER than breaking a weak passphrase, so your Mk3 "passphrase protected" are at immediate risk (if less or around 32 bits entropy).

English
3
10
24
3.2K