The Bitcoin Experience

18.8K posts

The Bitcoin Experience banner
The Bitcoin Experience

The Bitcoin Experience

@TheBitcoinExp

A #Bitcoin DCA keeps poverty away 🧡 • Memes • #BTCorGFY • Staying humble & stacking #sats through DCA + BTFD is how you store your time & energy in #BTC

Katılım Temmuz 2024
2.1K Takip Edilen2.3K Takipçiler
Natalie Brunell ⚡️
Natalie Brunell ⚡️@natbrunell·
.@FBIDirectorKash you spoke at the Bitcoin conference. Is your agency working to catch the people responsible for the ColdCard hacks that resulted in more than 1300 stolen bitcoins?
English
167
128
2K
165.9K
⏳ Michael Dunworth⌛️
⏳ Michael Dunworth⌛️@MichaelDunwort1·
Everyone learns that security is king. It is much easier to trust that statement than it is to find out from personal experience. Our community today treats security, integrity, and diligence as a second class citizen. This isn’t a moment to run to “exchanges” or handing off accountability of your keys. It’s an opportunity to learn! We all should be learning from this! But farrrrk me. This sort of shit only gets a free pass when the words drown the work. Influencer perceived status should never get a free pass.
English
3
3
22
1.2K
BTC Bro
BTC Bro@BTC_broo·
Thank you to everyone for the kind words and support. I don’t know how or why I got so lucky, but my bitcoin was all there and has been safely moved. I’m extremely relieved but also feel a lot of survivor’s guilt. I made the same exact mistakes as those affected - single sig, no passphrase, autogenerated seed phrase that I didn’t remember. I don’t deserve the luck I just ran into. This entire experience has me rethinking how I’ll distribute my bitcoin holdings moving forward. I’ll likely have a more equal distribution across a multisig setup and select custodians.
BTC Bro@BTC_broo

Moment of truth in about 5 hours.

English
62
1
180
8.3K
The Bitcoin Experience
The Bitcoin Experience@TheBitcoinExp·
All I can think right now is there were people who literally gifted coldcards to their loved ones for Christmas 😐
English
0
0
1
102
The Bitcoin Experience retweetledi
GégéLSMR
GégéLSMR@gegelsmr4·
NVK used open-source code from Trezor to build Coldcard. Then Foundation forked Coldcard’s code to create Passport. NVK got mad and switched Coldcard to a Commons Clause license so competitors could no longer use their code. But because he couldn’t simply relicense the GPL code he took from Trezor, he had to remove and replace it. And during that rewrite, he introduced the RNG flaw. That flaw stayed unnoticed for 5 years because nobody had an economic incentive to spend weeks auditing code they were no longer allowed to build on. His greed caused his downfall. Do I get this right?
English
196
429
3.9K
178.4K
Marty Bent
Marty Bent@MartyBent·
I think horror is the only word I can use to describe the feeling I’ve had since Thursday afternoon. I’m sorry to anyone who bought a Coldcard because of my endorsement. Like Matt, I’ve been on calls and text threads all weekend trying to help people get to safety. Please reach out if you need help.
ODELL@ODELLXYZ

i thought coldcard was the best and holy shit i was completely wrong have been trying my best to help people move for the last two days with no sleep, exhausted, broken, tragic my comms are overwhelmed by people, trying to respond to everyone if you are reading this and think your coldcard setup is fine because dice/passphrase/multisig, strongly consider moving anyway to reduce risk

English
95
41
930
76.2K
Matteo Pellegrini | Club Orange
i spent the whole weekend studying the Coldcard hack IMO the biggest lesson is not that an RNG failed it’s that the wallet silently downgraded to weaker randomness AND still told the user everything was fine
English
72
35
638
33.1K
Tharsanan
Tharsanan@SatoshiMyHero·
@heavilyarmedc If i have a 20 letter passphrase lower and upper case, is it still vulnerable?
English
3
0
2
117
Heavily Armed Clown
Heavily Armed Clown@heavilyarmedc·
Do not assume a passphrase will protect you, most people will almost certainly not choose a secure one. A bip 39 passphrase is just used as a salt in conjunction with the seed phrase to derive a totally new seed. If your base seed is compromised by bad entropy the only thing protecting your bitcoin is a (probably very weak) password. Bitcoin does not have any kind of throttle that limits the number of times an attacker can try to guess passwords. Do not play with this fire, the math is not on your side.
English
4
6
34
3.6K
The Bitcoin Experience retweetledi
Michelle Weekley
Michelle Weekley@michelleweekley·
The thing that makes me so angry is that this didn’t have to happen. There were so many warning signs. But too many people chose tribalism, sponsorship and purity. First of all Coinkite only had a handful of employees, they never employed a full dev team. Instead they were run primarily by an ego maniac who not only refused to cooperate with the larger community but was outright hostile to anyone that didn’t fawn over him. Coinkite was not ISO certified, they held NO standard formal security certifications. Instead demanding that every single user should “don’t trust, verify.” Verification is the very reason tech companies hold certifications. They did no third party audits. This is the part that makes me sick to my stomach that anyone was ever recommending them. And they had no bug bounty program. If you know anything about software, anything at all, those are three HUGE red flags. Furthermore NVK himself aggressively went after his competition. He registered a long list of domains and squatted on them so Seedsigner couldn’t use them. See @sesi_the_man He pivoted his “open source code” to new licensing that is "source available" instead of FOSS. See @zherbert It seems the bitcoin community wrote this all off because… those products made themselves available for other use cases? Even if Coldcard had been secure, it should have never been pushed onto normies with limited technical abilities. “Anyone can roll dice.” Sure. But should someone who has never even heard the word entropy be required to securely create their own? Absolutely fucking not. There are way too many things that can go wrong. And clearly, a lot has gone wrong. Do better. Godspeed.
English
84
94
879
45.9K
wale.moca 🐳
wale.moca 🐳@waleswoosh·
I can't keep my BTC on centralized exchanges because they might go bankrupt or freeze withdrawals. I can't keep my BTC in hot software wallets because my laptop might get hacked. I can't keep my BTC in cold hardware wallets because there could be a bug on the manufacturer's side that exposes my seed phrase. I can't deploy my BTC in DeFi because there's like a new eight-figure hack every month. So where am I supposed to keep my BTC?
English
4K
583
10.1K
1.3M
ODELL
ODELL@ODELLXYZ·
i thought coldcard was the best and holy shit i was completely wrong have been trying my best to help people move for the last two days with no sleep, exhausted, broken, tragic my comms are overwhelmed by people, trying to respond to everyone if you are reading this and think your coldcard setup is fine because dice/passphrase/multisig, strongly consider moving anyway to reduce risk
English
233
118
1.8K
187.4K
⏳ Michael Dunworth⌛️
⏳ Michael Dunworth⌛️@MichaelDunwort1·
They are (napkin numbers) Probably a team of <16 people. Likely 1/3 this but being generous. Social media elevated their perceived status. I would guess they have maybe $500k-$1M )max max maxxxxxx). They aren’t a real product social media inflated it. Nobody likely to get much. It’s not a Binance/coinbase level platform with capital reserves to help out customers. 😔
English
2
0
10
405
BTCCLUB
BTCCLUB@ausbtcclub·
Will ColdCard compensate those who lost funds?
English
7
0
8
1.2K
₿ Isaiah ⚡️
₿ Isaiah ⚡️@BitcoinIsaiah·
@olvelez007 @COLDCARDwallet They didn’t notice a critical bug for 5+ years, but you trust them with a quick bug patch that they threw together in a few hours? Sorry but that’s crazy.
English
2
0
40
527
Oliver L. Velez ⚡️ Bitcoin Intelligence
🚨 I lost what almost anyone would call a ton of bitcoin to this very sad event, so trust me. I'm in no mood to be generous. But, "Throw away your Coldcards" now, may not be great engineering at this point. The current firmware has the fail-closed guard that many other devices in the industry still don't have. A Mk4 on 5.6.0, the new upgraded firmware, is now more scrutinized than any competitor's device — every serious researcher spent this week reading that codebase. Discarding it for an unaudited alternative may not be the upgrade you think it is. The answer is structural: multi-vendor multisig. One vendor being wrong should cost you one key. Rotating to a different single vendor just moves the bet. My remaining 2 Sats.
English
135
41
636
62.2K
⏳ Michael Dunworth⌛️
⏳ Michael Dunworth⌛️@MichaelDunwort1·
Hey @saylor may you please let your mega audience know that there is a vulnerability for people to look out for. Help share awareness. It’s important to lots of people in the community! Thank you!
English
15
9
127
10.1K
The Bitcoin Experience
The Bitcoin Experience@TheBitcoinExp·
Weird question, but are any good actors out there, who have the technical skills, in the process of sweeping funds from coldcards in an effort to get them before bad actors do? I mean, get them yourself so that you can then return them to the true owners, before they get robbed
English
0
0
0
68
TexasBTC_FTW
TexasBTC_FTW@Kurt_Kokain·
Why can’t I just look at the 2048 word list and just randomly pick 24 words? It doesn’t seem that hard.
English
80
3
194
73K