Anton

380 posts

Anton banner
Anton

Anton

@pepeepep42

Katılım November 2019
645 Takip Edilen88 Takipçiler

2026 Yıllık Özeti

@pepeepep42 hesabının Twitter yılını gör

Anton
Anton@pepeepep42·
@design_sats Funny thing — yesterday the latest address that eventually got drained showed up in my DB before the hacker got to it. About 30 minutes later the funds were gone
English
2
1
1
354
Anton
Anton@pepeepep42·
@jurbed “One good audit” is exactly how RNG bugs survive for years. You can audit the design, not prove entropy from a random-looking output. Dice aren’t Stone Age - they’re an independent entropy source. And storing the passphrase next to the seed defeats half the point.
English
0
1
2
283
Mars
Mars@Marsmensch·
All mostly accurate. Adding a tad bit more detail since I happen to have this info open right now: The fallback read UID[31:0], which ST assigns to X/Y coordinates. Wafer and lot identifiers occupy the remaining 64 bits. The full 96-bit UID is unique; the X/Y word is not and CAN REPEAT across wafers and lots. The code calculated pad = UID_low32 XOR SysTick. An attacker can enumerate all possible 32-bit pad values without knowing either input separately. RTC state, earlier RNG calls and (on later models) the secure-element reseed also affected the end result. Therefore a UID list is not mathematically required to enumerate this one component. Physical proof will be incredibly hard but possible. Stronger evidence would combine the original device, a trusted pre-incident ownership record (with counterparty), plausible generator state and a reproduced wallet public key. st.com/resource/en/pr…
English
2
1
7
790
Coinjoined Chris ⚡
Coinjoined Chris ⚡@coinjoined·
The white hack drains have begun. I'm conflicted about this.
English
46
14
216
36.6K
Anton
Anton@pepeepep42·
@darosior The hardest part is proving who the actual owner is afterward. If that can be solved properly, a whitehat sweep can make sense - but it’s still extremely thin ice, both ethically and legally.
English
0
0
0
224
Antoine Poinsot
Antoine Poinsot@darosior·
A widespread "whitehat sweep" here would be actively harmful. I understand this comes from a good place, but you are making things worse.
English
10
5
74
6.9K
Anton
Anton@pepeepep42·
I hope this sets a good precedent and leads to a proper recovery process. During my research I found some pretty fat vulnerable wallets before the black hats did. I was sitting there wondering if I should drop an OP_RETURN with my contact info... but then how do you even verify the real owner? By the time I made up my mind, the black hats had already cleaned them out.
English
1
0
4
1.4K
Anton
Anton@pepeepep42·
@coinspect I reproduced it too. Happy to compare address sets and assumptions privately if that helps.
Anton tweet media
English
1
0
2
198
Coinspect Security
Coinspect Security@coinspect·
During the weekend we kept testing variants of the COLDCARD generator and alternative paths from each seed. Our numbers and address sets still do not match public blockchain analysis reports. If your team has reproduced the attack, please reach out so we can compare findings and understand what we may be missing. Attributing all these movements to one vulnerability without strong evidence is risky. Other exploits could be hiding in the noise.
English
4
2
11
2.7K
iced
iced@IceCubicless·
@Derivatives_Ape Why do I keep seeing morons arguing that it is not theft
English
1
0
4
1.2K
Derivatives Monke
Derivatives Monke@Derivatives_Ape·
Is the ColdCard “exploit” even theft lmao? All they did was generate the right private keys. Anyone could have done so.
English
117
14
854
130.4K
Anton
Anton@pepeepep42·
So if you come home and find 1000 BTC sitting on your table, whose BTC are they? Lmao. Someone generated valid private keys, and some of them happened to control existing UTXOs. That’s an uncomfortable edge case for the whole “whoever controls the keys controls the coins” philosophy.
English
0
0
3
439
Juraj Bednar🏴💛🌘
Oh god, please stop with the ridiculous dice rolls. What is this stone age? A good, well audited wallet will generate good entropy, passphrase contributes to the entropy and you want passphrase anyway (if nothing else, just write it down next to the seed).
English
24
3
120
14K
Anton
Anton@pepeepep42·
@design_sats This isn't the original hacker anymore. Looks more like AI-assisted script kiddies sweeping ranges he never bothered to scan. The barrier to entry is pretty low now — you can hack together a generator for this vuln in an hour.
English
2
0
1
72
Andrej designSats
Andrej designSats@design_sats·
He sent $43k to what seems to be a exchange. Fingers crossed he will be greedy and dumb. 3KMmeqPeQcngyTehdfSwsGqvxfU7J7qtc8
English
5
0
47
9.6K
Anton
Anton@pepeepep42·
@raw_avocado Bullish on Bitcoin. The Coldcard incident is just another step in the ecosystem's evolution. We had brain wallets once
English
0
0
1
30
Alex Waltz
Alex Waltz@raw_avocado·
It's strange how in Bitcoin most people get more dumber over the years, even though they have more experience.
English
18
1
47
2.8K
Anton
Anton@pepeepep42·
@notgrubles just tell the police the devs kindly left a deterministic Yasmarang fallback in the firmware instead of the hardware TRNG
English
0
1
8
1.2K
grubles
grubles@notgrubles·
What do I need to do to report the coldcard related theft?
English
15
1
78
29.2K
Anton
Anton@pepeepep42·
@nvk The post-hit batch contained 379 unique source candidates, 2,119 > distinct derived addresses and 5,591 post-hit records. 35 source and 95 derived addresses overlap the published victim dataset; a few > derived candidates currently show non-zero balances.
English
0
0
3
62
Anton
Anton@pepeepep42·
@nvk Each state produces 256-bit entropy → 24-word BIP39 → BIP44/49/84 addresses, checked against 1,407,213,375 historical HASH160 records. On an RTX 3090, the end-to-end rate is ~290k–338k candidate seeds/s
English
1
0
2
120
Anton
Anton@pepeepep42·
@JoeNakamoto Natural evolution of the Bitcoin ecosystem under increasingly powerful AI. We saw this with brainwallets: weak entropy eventually gets cracked. User-generated physical entropy, like dice rolls, is the ultimate backstop. Otherwise, every RNG remains a trust assumption.
English
0
0
0
86
Joe Nakamoto ⚡️
Joe Nakamoto ⚡️@JoeNakamoto·
what's the tl;dr on the coldcard debacle? how are people losing funds?
English
50
0
44
30.4K
Anton
Anton@pepeepep42·
@BitBoxSwiss You use five built-in entropy sources, but have you considered supporting user-supplied entropy, like dice rolls? Even if every internal source were compromised, the added physical randomness could still keep the funds safe.
English
2
0
4
1K
BitBox
BitBox@BitBoxSwiss·
BitBox is not affected by the recent RNG vulnerability that affected one of our competitors. More details coming soon.
English
16
51
592
28.6K
Anton
Anton@pepeepep42·
@PraveenPerera @CoineliusX Bad RNG has always been a ticking time bomb. First Ill Bloom, now this. Kinda wild how it all seems to correlate with the rise of SOTA AI models. Feels like we're only scratching the surface
English
0
0
0
28