Oliver L. Velez ⚡️ Bitcoin Intelligence

37K posts

Oliver L. Velez ⚡️ Bitcoin Intelligence banner
Oliver L. Velez ⚡️ Bitcoin Intelligence

Oliver L. Velez ⚡️ Bitcoin Intelligence

@olvelez007

Bitcoin Macro. Structure. Signal. Reports on Sundays. Essays every other Tuesday. AIx™ • Weekly Analysis • Free ↓

Florida, USA Katılım June 2009
1.3K Takip Edilen60.3K Takipçiler

2026 Yıllık Özeti

@olvelez007 hesabının Twitter yılını gör

Oliver L. Velez ⚡️ Bitcoin Intelligence
Thoughtful piece, Joe. I agree with your biggest conclusion: multi-vendor multisig is the standard. I've believed that for years. Last week's loss I took didn't change that. It reinforced it. Where I see it differently is the conclusion that this strengthens the case for institutional custody. I don't think it does. It strengthens the case for better self-custody. The argument for institutional custody ultimately rests on one assumption: That you can always leave. Historically, that's true...right up until the moment it matters. Mt. Gox. Celsius. FTX. Different institutions. Same ending. The freeze is never announced beforehand because announcing it creates the run. Today's custodians are unquestionably stronger. BlackRock isn't Mt. Gox. Fidelity isn't Celsius. I completely agree. But that's a difference in institutional quality. It isn't a difference in the nature of the relationship. With self-custody, final settlement is something you own. With institutional custody, redemption is a service someone continues to provide. Those are fundamentally different things. The ETF case goes one step further. You don't own the right to redeem Bitcoin. You own the right to sell shares for dollars while markets are open. That's price exposure. Not settlement. The deeper contradiction is this. You argue that self-custody is too difficult for most people...then conclude that multi-vendor multisig is the answer. I agree with the answer. Which means the problem wasn't self-custody. It was single-signature concentration. Across three waves... Across 4,585 drained addresses... Not one multisig wallet has been reported compromised. Not one. Sometimes an event doesn't destroy a principle. It exposes where we stopped fully applying it and where it needs to be strenghtened. My remaining 2 sats.
English
1
0
4
210
Joe Burnett, MSBA
Joe Burnett, MSBA@IIICapital·
This was possibly one of the worst weeks in the history of Bitcoin. Many people believed they had done virtually everything right. They bought a respected hardware wallet, generated their seed offline, followed established best practices, and still lost significant amounts of Bitcoin because of a vulnerability affecting @COLDCARDwallet seeds generated on or after March 2021. The vulnerability went undetected for 5+ years. I think this will permanently change confidence in self-custody. Over the years, I experimented with many different hardware wallets. I intuitively never trusted any one of them enough to store a serious amount of Bitcoin. These are all startups manufacturing small $200 devices that people use to secure life-changing amounts of wealth. Most users have never audited the code. I have never audited the code in sufficient detail. I do not have the time or technical expertise to independently verify every component of a device, its firmware, its entropy generation, and its supply chain. There are also many potential points of failure. The software could contain an accidental bug. An insider could intentionally introduce a vulnerability. A supplier could compromise part of the device. A firmware update could create an issue. The random-number generator could fail in a way that almost nobody notices. Everyone purchasing the device is signaling that they may eventually store significant wealth on it. That makes the entire hardware and software supply chain an extremely attractive target. Something like this always felt inevitable. I have always believed that attempting to store a meaningful amount of Bitcoin on your own requires multi-vendor multisig, with keys generated independently using different hardware and different software. The keys should also be stored in different physical locations. One device should be able to be completely compromised without causing you to lose your Bitcoin. Even with that architecture, I have always felt some level of uncertainty. I have also owned MSTR, ASST, GBTC, and IBIT in significant size. Self-custody is an incredible tool, but its risks were clearly greater than many people understood. I believe self-custody will survive, but it has permanently changed. The current wave of Bitcoin adoption is happening through ETFs, treasury companies, and institutional custodians. It is largely coming from people who have no interest in becoming experts in private-key generation, hardware security, firmware, backups, inheritance planning, and physical storage. That makes complete sense. Securely holding your own keys is so complicated that even the experts building these devices failed to prevent this vulnerability, and the broader technical community failed to detect it for 5+ years. Free markets naturally produce specialization. Bitcoin remains an incredibly valuable tool. Most people who lack deep expertise in securely generating and protecting private keys will outsource that responsibility to people and institutions that specialize in it. For someone who wants direct sovereignty over a significant portion of their Bitcoin, the standard should be multi-vendor multisig. If you are uncomfortable with that, use an institutional-grade custodian. A large amount of Bitcoin secured by one key generated by one hardware wallet carries far too much concentrated risk. I think that is where Bitcoin custody is heading. The obvious concern is that institutional custody could eventually concentrate too much Bitcoin in the hands of large firms. That would create censorship, seizure, and confiscation risks. However, Bitcoin’s portability and settlement properties provide the critical check and balance. Anyone can spin up a wallet and demand that their Bitcoin be sent to them. Settlement can happen globally, quickly, and cheaply. A person can move from counterparty exposure to direct ownership in a matter of minutes. Gold never had that property. Most people did not hold physical gold. Their gold sat in a vault somewhere. You could not rapidly move the gold from New York to Tokyo. You could not easily demand immediate global settlement into an asset you could personally verify and hold. Gold’s lack of portability and the inability to quickly demand physical settlement helped cause it to fail as money. Bitcoin solved that problem. You can leave a custodian, acquire actual Bitcoin, spin up a wallet, demand settlement, and move your wealth into cold storage. You always retain the ability to remove counterparty risk. That optionality is what matters. Bitcoin gives every person the ability to hold their own wealth. It gives every person the ability to exit a custodian. It gives every person the ability to demand final settlement into an asset they can personally control. That ability to hold your own keys is what keeps custodians, governments, and financial institutions accountable. It is one of the fundamental properties that makes Bitcoin work. I think we may look back on this moment as one of the darkest periods in Bitcoin’s history. Coins have been lost. Confidence has been shaken. Many of the people with the highest conviction in Bitcoin have been forced to reconsider assumptions they once viewed as guaranteed. I also would not be terribly surprised if this marked a turning point. As long as Bitcoin itself remains secure, the failure of one custody method does not invalidate the underlying monetary system. It forces the market to develop better tools, stronger standards, and more resilient custody architectures. It is often darkest before the dawn. This week may ultimately mark the end of one era of Bitcoin custody and the beginning of the next major wave of Bitcoin adoption.
English
192
204
1.5K
202.7K
Eder
Eder@21allegro·
@olvelez007 @ShawnDexta Not unique, but probably the best. Longest track record, no KYC, multi vendor.
English
2
0
2
66
Oliver L. Velez ⚡️ Bitcoin Intelligence
🚨 I lost what almost anyone would call a ton of bitcoin to this very sad event, so trust me. I'm in no mood to be generous. But, "Throw away your Coldcards" now, may not be great engineering at this point. The current firmware has the fail-closed guard that many other devices in the industry still don't have. A Mk4 on 5.6.0, the new upgraded firmware, is now more scrutinized than any competitor's device — every serious researcher spent this week reading that codebase. Discarding it for an unaudited alternative may not be the upgrade you think it is. The answer is structural: multi-vendor multisig. One vendor being wrong should cost you one key. Rotating to a different single vendor just moves the bet. My remaining 2 Sats.
English
137
42
640
63.3K
Eder
Eder@21allegro·
@ShawnDexta @olvelez007 You're missing that there is a product like Casa, that hits all those points. Multisig, multi-vendor. Can't compare the security with a single seed+passphrase.
English
1
0
2
86
Eder
Eder@21allegro·
@Life_of_Pleb @olvelez007 Have you heard of Casa? The only collaborative custody with multi vendor capability and no KYC. 20$/month.
English
1
0
0
33
Kevin
Kevin@jkpgamer·
I went through this when I lost everything in 2014... For 6 years I stopped self custody. Took me until 2020 to start taking it seriously again. I left everything on Coinbase until then. I moved to multisig 1-2 years ago. There will be a period where people leave in 3rd party but self custody will always be king. We just need to evolve and keep learning why new security solutions are always changing.
English
1
2
19
1.3K
Oliver L. Velez ⚡️ Bitcoin Intelligence
As many of you know, now, I lost Bitcoin in the Coldcard incident. I have more standing than most to declare self-custody a failure. I won't, because it isn't what happened. Look at the numbers in this post. Every one of those custodians was reputable right up until it wasn't. The ones that look like the safe choice today are simply the ones still standing, and we are being asked to conclude that from inside the survivorship bias, before the next one fails. What failed last week was not self-custody. It was single-signature concentration. Across three waves and 4,585 drained addresses, not one multisig wallet has been taken. Not one. The people who structured their holdings so no single key could spend walked through an attack that recomputed private keys at will. Self-custody is not ONE THING. It comes in layers. One seed on one device controlling EVERYTHING is self-custody. A 2-of-3 across three manufacturers is also self-custody. They do not carry remotely the same risk, and last week only told us about the first. The lesson isn't "give your keys and your wealth to someone else, another man to hold." It's that no single component: no manufacturer, no device, no custodian, deserves to sit beneath everything you own as the only thing that has to be right. Build so that one failure is survivable. That's the whole answer, and it was the answer before last week too. I ignored it.
🇦🇺Luke Mikic- The 9-5 Escape Artist🇵🇪@LukeMikic21

🚨After spending 9 years in Bitcoin, I hate to admit it, but I was wrong.🚨 SELF CUSTODY IS DEAD 1,300 Bitcoin was stolen from Coldcard, so now I'm putting all my Bitcoin in BlackRock and Coinbase. The track record of centralized institutions is great. 📉FTX stole 100,000 Bitcoin in 2022 📉Voyager - 65,000 Bitcoin in 📉Blockfi - 75,000 Bitcoin in 2022 📉Celsius - 235,000 Bitcoin 📉Quadriga - 60,000 Bitcoin 📉Mt Gox - 700,000 Bitcoin in 2013 📉Genesis - 150,000 Bitcoin 📉3AC - 175,000 Bitcoin I am absolutely flabbergasted at the amount of people proclaiming self custody is dead. Yes, what happened to Coldcard was horrible, but PERSPECTIVE is everything! NOT YOUR KEYS NOT YOUR COINS

English
45
26
307
34.8K
Oliver L. Velez ⚡️ Bitcoin Intelligence
I agree with most of what you're saying. Multi-vendor multisig is the stronger long-term answer. I've believed that for years, and it's how the overwhelming majority of my Bitcoin has been secured for a long time. Where I disagree is on dice rolls being an illusion of security. They're not. The entire point of dice is that the process is auditable. You can hash the exact sequence offline and verify that it produces the same seed. A hardware wallet's random-number generator is different. You cannot independently audit it. That's precisely why this flaw survived for years without anyone knowing. Those are fundamentally different failure modes. And in this incident, the distinction mattered. Coinkite's own advisory says that seeds created with sufficient independent private dice rolls are not considered at risk from this specific RNG failure. That's not an illusion of security. It's a mitigation for exactly the failure mode that just surfaced. Where I completely agree with you is that dice don't replace good architecture. They complement it. Multi-vendor multisig protects against one manufacturer being wrong. Independent entropy protects against trusting one manufacturer's entropy in the first place. Those layers stack. I was one of the larger victims of this incident. But not because I believed single-signature was the best long-term architecture. Quite the opposite. The overwhelming majority of my Bitcoin has been sitting for years in two separate multi-vendor, multisignature cold vaults. The wallet that was compromised was originally intended for a much smaller role. My mistake wasn't believing in the wrong architecture. It was allowing that single-signature wallet to grow well beyond the purpose I had designed it for before sweeping those coins into long-term storage. That doesn't excuse the loss. It simply explains why I came away believing more strongly in layered architecture, not less. If that wallet had also been created with sufficient independent dice entropy, this particular failure mode would very likely have been eliminated as well. To me, the lesson isn't dice or multisig. It's dice and multisig. My 2 sats.
English
4
0
31
2.5K
Bit Paine ⚡️
Bit Paine ⚡️@BitPaine·
I’m sorry, but it needs to be said: the dice thing is retarded. Not just because it’s shitty UX, either. Objectively, a correctly functioning and implemented cryptographic TRNG is a MUCH better entropy generator than asking a typical user to perform and encode 100 - or any number - of dice rolls. You can have imperfect or deliberately biased dice, a rolling surface that produces correlations, recording the wrong face, omitting or duplicating a roll, consciously or unconsciously rerolling unusual runs, exposing the written roll sequence, using an incorrect base-6 conversion, introducing modulo bias, entering fewer rolls than believed… etc. A TRNG can generate far more raw entropy, much faster, with less procedural error. The ONLY thing the dice roll is a hedge against is an incorrectly implemented TRNG - ie the exact flaw that the cold card had. But if you accept that you need a hedge against HWW entropy generation, then you need to ALSO accept that the procedure with which the wallet converts the dice roll into a seed is equally as likely to be flawed or malicious as the TRNG implementation. So your hedge against the wallet malfunctioning is only a partial hedge of one part of the failure mode; you are still vulnerable to any and all other possible flaws that the wallet might have. The only thing that can hedge against all possible flaws that a wallet might have is multi-vendor multi-sig. In this case, the dice would have protected you, but there are myriad other possible failure modes in which the dice would not have protected you -so either you implement multi-sig, in which case rolling dice is redundant, or you don’t, in which case there’s still multiple failure modes that you are exposed to, and no possible way to control for them all. Like the coldcard itself, it provides only the illusion of security. Similarly, a passphrase can either be remembered - in which case it is insufficiently high entropy to matter - or it needs to be written down, in which case IT MIGHT AS WELL BE ANOTHER SEED AND ATORED STORED ON ANOTHER DEVICE.
English
75
11
226
42.3K
Oliver L. Velez ⚡️ Bitcoin Intelligence
The point is fair and worth stating precisely, because it changes what victims should be recording — not whether they should keep the device. You're right that a signature from the compromised key proves less than it normally would. Once the seed is reconstructable, anyone who has reconstructed it can produce that signature. It stops being sole proof of ownership. That's worth knowing. But it doesn't become worthless. It becomes one item in a set: Chain history is the backbone. The affected addresses received coins over years, from sources that trace back to KYC'd purchases, exchange withdrawals, or counterparties who can attest. The attacker and his addresses have none of that. He appeared at 01:36 UTC on July 30 and never held those coins before. Purchase provenance. My Coldcard order confirmation from Coinkite, dated March 2021, with an order number. That ties a specific person to a specific affected device. Timing. A legitimate holder can typically show the wallet was watch-only in their own software, on their own node, before the sweep. The thief cannot produce a wallet history that predates his own arrival. Contemporaneous reporting. A support ticket, a police report, an IC3 filing —all timestamped before any recovery attempt exists. And the signature, which is weak alone but corroborating alongside the rest. So keep the device and the seed. The cost of keeping them is a drawer. The cost of destroying them is discovering later that a frozen exchange balance required something you threw away. Where you're right, and it's the useful part of your post: don't stop at the seed. Build the full record now — chain history, purchase documentation, wallet software history, timestamps, and a report filed with authorities before any recovery process exists. Nobody should be under the impression that a signature alone settles it. That's a genuinely useful correction. Speaking from personal experience here, unfortunately.
English
1
0
6
958
Michael Scott
Michael Scott@Michael64930226·
Hate to throw salt into a fresh wound, but it's going to be a lot harder than that to prove those coins were yours. Remember, anyone can generate that seed now. Anyone can claim ownership. You'll need KYC Exchange showing purchase, then moving to the affected addresses, then being swept to one of the thief's addresses.
English
3
0
5
1.1K
Tim Lamb
Tim Lamb@theretailbull·
I’ve had all my bitcoin stolen while away on holiday. It was on a Coldcard MK3. I was led to believe this was really secure. It was recommended by experts including @saifedean. I also had the seed on a metal plate, hidden away. When I got news of the hack on Friday I didn’t know what to do, whether to fly home and leave the family holiday or not. Not until Saturday evening did I get the idea to ask my neighbour with the house key to find the seed for me. Sunday morning I led the neighbour on an expedition around the house, restored the wallet, and it said zero bitcoin. I asked another friend to check on my software in the house. Zero. It was all drained Saturday afternoon before I’d had the idea to get someone to find the seed. This 2 bitcoin was supposed to be to give to my 2 children to give them a good start in life. Makes me tear up to think of it. This comes as a terrible blow. The timing was so unlucky with being away, or I would have moved it in time. @Coinkite, if there was any fairness, you would have to pay us our money back. I just hope the US authorities find the culprits and the stolen bitcoin and return it to us. @americanhodl8 @ZynxBTC
English
452
282
4.4K
474.5K
Steven in Vegas
Steven in Vegas@nllv_comm·
@olvelez007 When you gotta get Grok to back up your post it means you did not read the room correctly.
Steven in Vegas tweet media
English
1
0
0
367
Jameson Lopp
Jameson Lopp@lopp·
Entropy is your friend.
Jameson Lopp tweet media
English
65
207
1.2K
130.2K
Bit Paine ⚡️
Bit Paine ⚡️@BitPaine·
“two secure elements, but we use neither of them”
Bit Paine ⚡️ tweet media
English
17
55
1.1K
22.2K
Oliver L. Velez ⚡️ Bitcoin Intelligence
For anyone else in this situation. My DMs are open. Anything I can do to help will be done. And no, there is no payment for anything I can help you with. This is not a time to be charging anyone fees for anything. You've paid enough.
Oliver L. Velez ⚡️ Bitcoin Intelligence@olvelez007

I'm so sorry. I was hit too — same device, same week, and reading this brought it all back. The part that stays with me in your account is the timing. You were with your family. You found out Friday, you were working the problem by Saturday evening, and it was gone Saturday afternoon. There is no version of that where you moved faster. You were not careless and you were not slow. You did what this entire community told you to do. Coldcard was the consensus recommendation — I recommended it too, for years, on the merits: Air-gapped device, metal backup, seed offline and hidden. Every layer you could verify, you verified. The one layer you could not check was whether the randomness was sound when your seed was created. There is no test for that. You trust the manufacturer, and that trust cannot be falsified from the outside. That is the layer that failed, and it was theirs to get right. Three things worth doing, whenever you have the strength: Don't destroy the Coldcard or the steel plate. The seed is worthless as a secret now, but if any of these coins ever reach an exchange and get frozen, proving ownership means demonstrating control of the original keys. Keep both. DM Alex Thorn at Galaxy Research (@intangiblecoins). He has publicly asked victims to come forward and committed to answering every message. Attacker addresses are being identified specifically because victims speak up, and he's sharing them with authorities. Your data helps people who don't yet know they've been robbed. File with your national cybercrime unit. Most of the stolen coins from the main waves are still sitting untouched in attacker addresses. That's not nothing. Two bitcoin for your children is not an abstraction and I'm not going to pretend the money doesn't matter. It does. But you're still their father, you still know how to save, and you have years. What was taken was the stack, not the discipline that built it. If you want help with the reporting or with rebuilding when you're ready, my DMs are open. 🙏🏽 May God bless you and your family during this difficult time.

English
15
6
139
10.5K
Noonien Soong
Noonien Soong@mlcarldev·
@olvelez007 So now we need three devices from three different vendors to keep our coins safe. The fucked-up state of Bitcoin. Plus the morons with the chain split. Prices lower than 40K are incoming. Cheers.
English
1
0
2
615
Oliver L. Velez ⚡️ Bitcoin Intelligence
Ths more I read this the more pissed off I become. As one of the largest losers in this sad, unfortunate debacle, I find this apology almost insulting. The fundamental problem was not AI inventing a new attack. It was a basic, long-standing failure in the randomness path that their own reviews and testing missed for five years. FIVE FRIGGIN YEARS! Presenting the company as a victim of advanced tooling and AI, while its users face irreversible losses is just out right low, IMHO. My heart aches and goes out to all the people and families impacted and destroyed by this. They did nothing wrong for five years and this is their payment. 😢
Oliver L. Velez ⚡️ Bitcoin Intelligence tweet media
English
61
39
532
19.5K
Oliver L. Velez ⚡️ Bitcoin Intelligence
@p_s_i_o_n_i_c If have to agree with this. What I am saying is that of all single wigs now, there is no one better vetted at this point. That is a fact. Most think other vendors don't have this problem. Bad assumption.
English
0
0
5
764
psionic
psionic@p_s_i_o_n_i_c·
@olvelez007 A 2 of 3 multi-sig using three hardware wallets from three different vendors is the way to go. But coldcard shouldn't be one of those three vendors at this point.
English
1
0
5
826