Student Of Things
5.6K posts

Student Of Things
@studentofthings
Freedom focused cognitive dissonance creator.
Virginia, USA Katılım March 2022
2.3K Takip Edilen1.9K Takipçiler
2026 Yıllık Özeti
@studentofthings hesabının Twitter yılını gör

@Convertbond MSTR and ETFs are drawing investors away from the core promise of Bitcoin. I know Bitcoiners who would rather have yield than sovereignty. It’s not hard to understand, but Bitcoin’s promise isn’t broken.
English

@presel_ I reported a rusty bolt but it wasn’t worth my time to check every rusty bolt after not getting an acknowledgment.
English

@studentofthings I found a crack in the dam but I didn’t report it because they never paid me for when I told them about the rusty bolt on the bridge.
English

@DBonatOliv It was just in my notes on a VM that I closed and didn’t touch for months.
English

@studentofthings To whom did you publish it?
English

@PabloSabbatella I wrote about it here.
digitaloperatives.com/2023/07/29/bug…
English

This is huge. Someone found Coldcard bug 11 months ago.
I have been saying this for a long time now: most bug bounty programs (if they even exist) work like shit and they are incentivizing incidents and black hats, rather than protecting users.
Student Of Things@studentofthings
Just confirmed, I found the Coldcard RNG bug 11 months ago and never reported it because they didn’t acknowledge me on the first one I reported.
English

@RealbitcoinMD Well, I assume any research you do hand in hand with a AI company to gets shared with national actors. 🤷🏼♂️
English

@studentofthings If you did post it on Reddit or linked in, it probably helped AI find it in the first place. The main takeaway here is that Coinkite as a company whose wallets held at least $2 Billion dollars of Bitcoin was as professional as the dudes in Mall Rats.
English

@fermentedfranco @cguida6 @LukeDashjr Correct, as I stated in the OP, I didn’t report that bug or any other to them because they didn’t credit me for the first one… So I went on to other research/effort where the vendor cares about security. But again, each would have required human effort to validate.
English

@cguida6 @studentofthings @LukeDashjr Yes, they stated critical if "an attacker gains physical or indirect access to the device".. No mention of RNG
English

So just to be clear, you are upset that you discovered a vulnerability. You didn't even understand and nobody gave you credit for it?
If you understood it, you should have done a lot more after the company didn't respond to you.
Seems to me like you were farming bug bounties using AI and didn't grasp what you had
English

@w_s_bitcoin @BlockUnmasked Who is this dude btw claiming he found it but did not report it
Student Of Things@studentofthings
Just confirmed, I found the Coldcard RNG bug 11 months ago and never reported it because they didn’t acknowledge me on the first one I reported.
English

In 2024, victims came to us with bitcoin missing from Coldcard wallets. No malware, no phishing. We traced it to weak seed entropy and filed reports with the manufacturer and multiple agencies. Two years later: $38M swept in 25 minutes.
blockchainunmasked.com/post/coldcard-…
English

@DBonatOliv I did in fact try that on the one I published. Went nowhere.
English

@studentofthings You should have denounced them publicly. People would've saved their funds, but they would still be afraid of using their products again, because of their false advertising. A person is responsible for the truth they find. By not making it public, you allowed this to grow larger
English

@studentofthings @kliberaali fyi, they released firmware 4.2.0 for mk2 and mk3 models (after getting ridiculed for not doing so), you still state that there is no update

English

@CosmicXXX1984 Certainly possible when a user says “go find ways to make money”.
English

@studentofthings Well in the future, if not ethically contained, when the AI eventually becomes self aware, it will act in it own best interest and steal the BTC, currecies, assets, Classified Information, Top Secret compartmented highly sensitive highly valuable global changing whatever.
English

@mochammadrafi27 We use all kinds of models. I’m starting to lean more heavily on open weight models because of the privacy and less nanny-state vibe.
English

@tayvano_ @MonNomEstSed @_Gendy_ And everyone else now can see the reasons why researchers don’t disclose their work. Not only no credit, but animosity. You could have analyzed Coldcard, why didn’t you do it? 🤦♂️
English

@studentofthings @MonNomEstSed @_Gendy_ Yeah and you appear to be an autistic, selfish fucking prick doing victory laps when thousands of people are actively losing literally hundreds of millions of dollars
English

@hraqhraq @JoeCarlasare I have been meaning to checkout both. I do know that Joe Grand (legend) has been working with Trezors and helping understand the vulnerabilities though. The one thing I don’t like about either is that you can buy them from Amazon. That’s a MitM attack waiting in the mail.
English

@studentofthings @JoeCarlasare Did you find anything in Trezor or Ledger?
English

@CosmicXXX1984 What far too few are curious about is what does your AI do with bugs it helps to discover. 🙋♂️
English

@studentofthings What this tells me, this bug once found, was allowed to exist & it is my opinion that a covert operation involving large nation state/banking players was at the heart of this op. Let millions in BTC accumulate over time & then rugpull those opposed to legacy finance capture.
English

@SteevoNorris No, I believe the dice rolls entropy implementation on the Coldcard is fine. I validated Seedsigner's yesterday as well.
English

@studentofthings Did you found any vulnerabilities about about adding the dice rolls to the RNG ?
English
@studentofthings karşılaştırmaları
@convertbond vs @studentofthings @presel_ vs @studentofthings @dbonatoliv vs @studentofthings @pablosabbatella vs @studentofthings @realbitcoinmd vs @studentofthings @fermentedfranco vs @studentofthings
Kendi karşılaştırmanı oluştur 


