
Zero-Knowledge Goof
2.6K posts

Zero-Knowledge Goof
@LLFOURN
UNLICENSED BROKER OF BITCOIN Working on @FrostsnapTech npub1xh897wvhn93tda0zws94mdyc7eagc8qm0798clp7x48zh6kjwa



So it turns out that at least one good guy was looking at problems in coldcard entropy before the attack. @utxoclub ran a prompt on 17th June but it failed to surface the issue for two main reasons: 1. Anthropic “ai safety” clown show meant it could only be done with opus 4.8 instead of fable at that time. 2. The coldcard code base is a cluster fuck of git sub modules.










Airgapping is a larp, secure elements are just PIN authenticators, and extra dice rolls are a prayer

Seven weeks ago I pointed Opus 4.8 at the @COLDCARDwallet firmware and told it to find bugs that lose people money. The second bullet of my prompt: Weak RNG source.


Full stop: this bug is insane, and just purely inexcusable. But the timing of the exploit is literally right after Kimi released open weights for a frontier quality model (specifically without safeguards). My understanding is Coldcard has been audited by US frontier models, and it did not locate or identify this. Kimi was used by multiple people that I know to verify and reproduce this issue. It's undeniable that Kimi played a role in this specific bug being isolated and exploited. That's not relevant to the fault, or blame, that is on Coinkite, but it is nonetheless a serious factor to consider and appreciate looking at the wider ecosystem.



MK4s are vulenerable but are millions of times harder to steal from. MK3s can be stolen from a decent laptop, mk4,5s and Q would need much more compute. The model: - attacker has a roughly 2^20 UUID range that it knows cold cards fall in - checks a 16 button press variancer in user behavior before generating the seed You should still promptly remove funds from mk4,mk5 and Q.










