James O'Beirne

12.5K posts

James O'Beirne banner
James O'Beirne

James O'Beirne

@jamesob

dumb carpenter, 10+yr bitcoin dev

Katılım March 2008
1.1K Takip Edilen16.2K Takipçiler

2026 Yıllık Özeti

@jamesob hesabının Twitter yılını gör

Sabitlenmiş Tweet
James O'Beirne
James O'Beirne@jamesob·
I just dumped a lot of what I know about running big LLMs locally into a Github repo (github.com/jamesob/local-…). I'm pretty impressed with what I'm getting out of the GLM-5.2 REAPs and opencode - we're getting close to Claude locally. File an issue and I'll add to the repo.
English
14
25
182
23.4K
James O'Beirne retweetledi
Udi Wertheimer
Udi Wertheimer@udiWertheimer·
bitcoin wallets that cannot be hacked in 2016 malte moser, @ittayeyal and @el33th4xor published “bitcoin vaults” and “bitcoin covenants”, describing how a simple, harmless upgrade to bitcoin script could help build hack-resistant wallets the secret is simple: instead of attempting to build a perfect self-custody system, accept that humans are imperfect and WILL make mistakes. therefore mistakes must be recoverable moser-eyal-sirer “vaults” add a delay to transactions. imagine if your hardware wallet had a 24 hour delay whenever sending transactions. during that delay, if you notice something is fishy (you’re getting hacked!) you hit a special button and your funds are directed to your coinbase deposit address instead, for example that’s it! you only rely on coinbase (again, just an example) if your main wallet got hacked. if you’re not hacked, you use your wallet normally and coinbase cannot control it. you simply have to wait 24 hours when sending. for long-term storage this is usually fine in crypto (non-bitcoin), institutional grade solutions like Safe on EVM and Squads on solana protect over $100B in assets in constructs that are similar to the 2016 vault proposal. many/most major companies in those ecosystems use those solutions and they are considered an obvious best-practice over there but in bitcoin, this can’t be implemented without simple upgrades like OP_CTV, OP_VAULT, OP_CAT, or others over the years, in addition to moser, eyal and sirer, many experts like @jamesob, @JeremyRubin, @kanzure, @EliBenSasson — and even retards like yours truly — have attempted to promote any of those proposals to enable this kind of safer custody. it still hasn’t been done, imo mostly due to political and puritanical reasons (various versions of “i don’t like the people who proposed this”) but the truth is that if this feature was in bitcoin, many coldcard users would’ve been directed to use it, and would’ve been safe today. vaults and covenants don’t require wallets and humans to be perfect. they assume that they aren’t. people who don’t want to use vaults and covenants don’t have to. but people who want to use them should be allowed to. it’s time to give bitcoiners covenants.
Udi Wertheimer tweet media
English
43
62
353
51.1K
Vinny Pardi
Vinny Pardi@VinnyPardi·
@mshodl In his happy place
Vinny Pardi tweet media
Upper Arlington, OH 🇺🇸 English
2
0
8
870
Justine O’Beirne
POV, I took a road trip with my bitcoin devolver husband while bitcoin was kind of on fire. Coding in the car, coding at lunch… this man be coding
Justine O’Beirne tweet mediaJustine O’Beirne tweet media
English
51
7
435
39.8K
Mandrik
Mandrik@Mandrik·
@mshodl Bro has lost his mind letting a woman drive!
English
6
1
63
1.9K
Garand Thumb
Garand Thumb@GarandThumb1·
boomers really be like this
Garand Thumb tweet media
English
358
563
20K
320.4K
Joe Carlasare
Joe Carlasare@JoeCarlasare·
Suggesting any Coldcard setup is secure right now is indefensible. There’s a space right now doing that. The only sensible mitigation is to stop trusting this vendor. @w_s_bitcoin @ProofOfMoney
English
51
26
517
29K
Rob Hamilton
Rob Hamilton@Rob1Ham·
If I have a preexisting relationship with you, and you're an engineer in bitcoin, and for some reason you are unable to access K3, hit me up. I'm loading up a personal credit card with credits right now, and creating a fan out of repos that need to be evaluated.
English
23
51
288
30.1K
Doc
Doc@DrBitcoinMD·
slept on it feel even worse today very little silver lining to be found actually went to church this morning to light some candles and pray for those affected, some of whom I know very well
English
21
8
558
18.9K
James O'Beirne retweetledi
Peter McCormack 🏴‍☠️🇬🇧🇮🇪
Tough to know what to say about ColdCard...pretty much everything has been said that can be said about tech, security etc... So I'll say three things: 1. As someone who made and lost a shit ton of money once, life changing money...I'll say this, you get over it. Why? Because money never does buy happiness, it just buys the thought of happiness. The reality is as cliche as it comes, but happiness comes from other places. You'll know in your heart what makes you happy, and it isn't money. 2. That said, money is security, for you and your family, I get it. So, the only thing you can do is knuckle down, grind, and get yourself to the place you need to be. Days become weeks, weeks become years and you will get where you need to be. 3. ColdCard - might take some flack for this. However stupid this mistake is, there will be people behind this hurting. When Bitcoin world comes at you it is rough, I've been there. I still think we need ColdCard in our world. They made a mistake, a monumental fuck up, a mistake they will never make again. Final thought...at the height of my depression when I was coming off drugs, I couldn't get out of bed, I was gripped with chronic anxiety. My brother used to call me every morning and say "things will get better", and they did, it took time, but they did. I promise if you are hurting, time will heal. Kiss your wife, laugh with your kids, tomorrow is another day. DMs open if anyone needs anything.
English
184
114
2.6K
136.8K
James O'Beirne
James O'Beirne@jamesob·
Ran a lengthy Kimi-based verification across all `coldcard/firmware` tags: BIP-39 (passphrase) integration is SAFU The problem is: your passphrase has to be very long and very unwieldy to be cryptographically relevant, so don't necessarily trust yourself.
James O'Beirne tweet media
English
28
21
214
49.2K
James O'Beirne
James O'Beirne@jamesob·
@NEEDcreations Pack 12 BIP-39 words into "AFormatLikeThis" for the passphrase - should fit under the Coldcard 100 character passphrase limit, is easily backup-able.
English
5
4
50
6.1K
James O'Beirne retweetledi
Zero-Knowledge Goof
Public heads-up for GPU cloud / rental providers and Trust & Safety teams: There is a publicly disclosed hardware-wallet entropy issue that may lead to abuse of consumer GPU rentals — especially multi-GPU NVIDIA RTX 3090 / 4090 and similar CUDA cards — for offline BIP-39 seed recovery. References: • Coinkite advisory: blog.coinkite.com/coldcard-mk3-s… • Technical background: blog.coinkite.com/entropy-techni… • Live theft tracker: coldcard-watch.vercel.app What this looks like technically: • Offline search of a reduced BIP-39 seed space via bulk PBKDF2-HMAC-SHA512 (2048 iterations) • Mk3: does not need GPUs — that space is small enough to brute-force cheaply, and Mk3 seeds are already linked to on-chain thefts • Mk4 and later: does need large amounts of compute. Those seeds are stronger but still weaker than full design entropy for some pre-fix units. Rough ballpark: recovering one seed ≈ ~10× RTX 4090s for about a day • On rental platforms this tends to look like long-running custom CUDA/hashing binaries or containers on multi-GPU 30/40-series instances — not normal training/inference API usage Why this matters now: the low-hanging fruit (Mk3 and the weakest seeds that need little or no GPU) appears largely drained already — the tracker above shows the ongoing thefts. The next wave is Mk4-and-later seeds, which are compute-bound. Large blocks of rented consumer GPUs are the bottleneck for attackers. This is not a vulnerability report against any platform. It's context so abuse / trust teams can: 1. Route future reports on this topic correctly 2. Optionally watch for suspicious multi-GPU, long-running custom CUDA jobs 3. Have background if law enforcement or researchers get in touch cc: @vast_ai @runpod @clore_ai @TensorDock @SaladTech @akashnet @MassedCompute @Hyperstackcloud @fluidstack Happy to help any team dig in.
English
6
17
55
5.7K
James O'Beirne retweetledi
EVAN KALOUDIS
EVAN KALOUDIS@evankaloudis·
Bitcoin should have covenants and vaults.
English
9
4
41
2.1K
bk
bk@britttttkelly·
i was always a bit too dumb to use coldcard
English
26
7
246
11K
Trey
Trey@trey21m·
@jamesob @nvk @DocHex Assuming no issues with seeds generated by adding 100+ dice rolls to CC's bad TRNG?
English
1
0
3
195
satsie
satsie@satsie·
Get in the car kids! We’re going to a playground but it’s an hour away so we can spend the drive listening to Twitter spaces for updates on the Coldcard vulnerability
English
10
2
69
2.1K
James O'Beirne retweetledi
sanket1729
sanket1729@sanket1729·
The actual entropy is much less than 72 bits for mk4 onwards. 72 bit assumes security coming from several corelated timer fields. Not the same as 72 bits from crypto eng source. My napkin math says it is almost 50 bits. Please move away from mk4 devices too.
COLDCARD@COLDCARDwallet

COLDCARD Mk3 Security Advisory If you generated a seed on a Mk3 after firmware 4.0.1, your funds may be at risk. Mk4, Q and Mk5 are not affected based on our early analysis. Read the advisory and migrate carefully: blog.coinkite.com/coldcard-mk3-s…

English
8
38
186
29.2K