hmmm

7.2K posts

hmmm banner
hmmm

hmmm

@threecnine

☦ #bitcoin only dm for honey saw pilot amateur extra 2A the great schism was a hard fork.

Florida Katılım Haziran 2020
6.5K Takip Edilen1.1K Takipçiler
hmmm retweetledi
Sky
Sky@skysupersonic·
Dear COLDCARD attackers, Congratulations. You successfully found a bug, exploited, and have collectively gathered around 1,500 bitcoin. Now you are sitting on one of the most blacklisted coin stacks in history. It will be nearly impossible for you to exchange for currency or deal with any institution. Every move you make will be highly scrutinized and tracked. Presumably for the rest of your lives, you will be looking over your shoulder. I suggest you plea with CoinKite to return all stolen funds in return for an audit fee of 5% of the loot. This way your work is rewarded and you are able to enjoy the fruits of your labor. Respectfully, hodlers worldwide
English
997
906
11.4K
742.1K
hmmm retweetledi
Orthodox Christian
Orthodox Christian@orthodox_33ad·
Do not say that faith in Christ alone can save you, for this is not possible if you do not attain love for Him, which is demonstrated by deeds. As for mere faith: ‘The demons also believe and tremble’ (James 2:19). — Saint Maximus the Confessor
Orthodox Christian tweet media
English
5
114
913
6.1K
Hoplite Industries
Hoplite Industries@Hoplite_Ind·
At the request of many, we're putting together a single purchase package deal for everything seen here. There are a lot of parts to this, so stand by as it may take a couple weeks to get everything together and ready. What it will include: - IIIA Ballistic helmet - Helmet cover - PVS-14 - HIR-640M thermal - Dovetail mount - Dual bridge - IR strobe - Map light - NOD carry pouch - Active ear pro with mic - Helmet bag The total price will be under $4,000 By the people, for the people 🇺🇸
Hoplite Industries@Hoplite_Ind

Everything in this photo totals under $4000, a relatively low price to pay for superpowers. Night vision (PVS-14), thermal (HIR-640M), IIIA ballistic helmet, dovetail mount, active hearing protection with communications. Only a few years ago, an equivalent setup would have been double that price. We're doing the best we can to make this gear affordable to the citizens who need it. Hoplitegear.com

English
136
180
3.3K
124.1K
Seed
Seed@sesi_the_man·
Ben deserves a lot of credit for this. He has also always been cool about doing video tutorials on @SeedSigner and mentioning the project to others.
English
22
31
452
17.1K
hmmm
hmmm@threecnine·
@Shireh0dl Hopefully they open source before they disappear
English
0
0
0
68
Shire
Shire@Shireh0dl·
I'm very sad and disappointed. Coinkite/ Coldcard wont financially recover from this, IMO. That's what they get for their carelessness/negligence. But what we're left with is a more centralized hww space, with basically no bitcoin only options. This is very bad IMO.
English
34
3
92
4.4K
Matt Carvalho
Matt Carvalho@mattcrv·
Don't roll the dice. Don't add longer passphrases. Skip straight to collaborative multi-vendor multisig. Or use a @Bitkey temporarily. The singlesig era has ended.
English
55
15
289
29.1K
hmmm
hmmm@threecnine·
@giacomozucco Multi sig protected me in this hack but I hate the complexity of it. Unfortunately I have onboarded people to cc who have lost funds. I think the main GOOD is normalizing self-generated entropy. We can't dumb it down more than that anymore.
English
0
0
4
184
Giacomo ShadowUNbanned Zucco
As far as grave-dancing goes, this is my good/naughty list. GOOD: - stressing the importance of paranoid nerd stuff like multi-vendor multi-sig and self-generated entropy (sure: it's complex and scary, and beyond reach for many currently, but when shit will really hit the fan it will be necessary anyway, so it should be seen as an ideal to achieve, not a quirk to mock), - stressing the risk of bitcoin-specific devices over commodity phones or laptops (the former pay the objective advantage of smaller attack surfaces with the disadvantage of more niche and less reviewed/battle-tested code), - stressing the importance of good UX over just tech (even if paranoid nerd stuff was doable on CC, some people didn't bother, while stuff like BitKey, for all the criticisms we may have, makes at least multi-sig a default and as simple as possible), - stressing the importance of full FLOSS (the vulnerability was introduced together with the licence change and fewer people were incentivized to reuse/audit the public code), - stressing the importance of some level of industry honest and peaceful cooperation on education and security standards on top of healthy free-market competition (the signing device space was full of animosity and excessive FUD, which frankly CoinKite was not immune to either, and that didn't help, since some users mistook the early alerts for CC-targeting FUD). NAUGHTY: - shilling custodial exchanges, ETFs and other big KYC honeypots as an alternative (they will also be hacked with frontier LLMs, and even more so than hardware devices, but on top of that they will also get some users kidnapped by thugs buying KYC lists, and EO6102ed by governments), - shilling your own favorite brand of covenant soft fork as an urgent silver bullet (people who didn't care to set up a multi-sig would probably have not cared to set up a non-interactive vault, especially if it was a newer and more exotic feature: again UX and education on what already exists are the priority over introducing new stuff), - shilling shitcoin-enabled competitors because CC was bitcoin-only (the number and size of hacks against generalist and amateurish "crypto" software, even if less impressive than the ones against custodial exchanges, put this episode in perspective: diluting focus to chase token-printing was and remains a bad idea).
English
22
37
174
22.1K
hmmm retweetledi
AMERICAN HODL 🇺🇸
AMERICAN HODL 🇺🇸@americanhodl8·
Podcasters and YouTubers please put out short 5-10 min emergency broadcast episodes today or tomorrow with a technical guest about the coldcard situation. That way we can reach all the people in the audience who aren’t too online twitter people. There are still bitcoiners who don’t know this is happening.
English
49
127
1.3K
52.4K
hmmm
hmmm@threecnine·
@xpugHODL Unfortunately strike will now report those Bitcoin to the IRS and you will have to answer for them forever...
English
1
0
0
134
xpug.HODL
xpug.HODL@xpugHODL·
Now that the dust has settled and I’m not in panic mode anymore… here’s my story. I had previously used a Coldcard MK3 for cold storage. A massive percentage of my Bitcoin I’ve accumulated over the past 8.5 years was in one wallet with numerous UTXOs. I didn’t use dice entropy to generate my seed phrase and my main wallet didn’t have a passphrase, so I was legitimately terrified when I saw the first info about the breach possibilities. I blindly trusted it would be ok when I bought it. Everyone said Coldcard was the best. When I got home from work last night, I told my wife what was going on and went to work. All of my Bitcoin was still untouched. I transferred it all to Strike for the time being. These are scary times for lots of people. Tell everyone you know who has used a Coldcard that it’s time to check up on their balance and transfer their funds somewhere else.
English
41
7
380
45K
hmmm retweetledi
hodlonaut #BIP-110
hodlonaut #BIP-110@hodlonaut·
If you lost your coins, don’t lose hope. Don’t do anything stupid.
English
24
99
853
81.4K
hmmm
hmmm@threecnine·
@COLDCARDwallet Migrate what? If you had coins on mk3 device they are gone.
English
5
2
48
2.9K
COLDCARD
COLDCARD@COLDCARDwallet·
🚨 COLDCARD SECURITY UPDATE [Jul 31, 9:40 EDT] Mk3 4.2.0 is now available. Affected seeds without ≥50 fair, independent, private dice rolls: 👉 Mk3 4.0.1–4.1.9 👉 Mk4/Mk5 <5.6.0 👉 Q <1.5.0Q Update first. Generate a new seed. Migrate carefully. blog.coinkite.com/entropy-techni…
COLDCARD@COLDCARDwallet

🚨URGENT COLDCARD SECURITY UPDATE Read carefully before acting. 👉Mk3 seed generated on 4.0.1+ without ≥50 private, independent dice rolls: begin a careful migration now. 👉Mk4/Mk5 <5.6.0 or Q <1.5.0Q: update first, generate a new seed, then migrate. blog.coinkite.com/entropy-techni…

English
163
128
378
232.4K
hmmm retweetledi
Giacomo ShadowUNbanned Zucco
Exchange-shilling by tragedy-parasites had to be expected, I guess. Still super-cringe to see. Don't send your sats to third-party custodians, financial products and custodial exchanges. They are big honeypots. They have lost users more money than every wallet bug ever in the past, and they will do so increasingly in the future. Self custody. Avoid KYC. Always. Take notes of people leveraging fear and confusion to tell you otherwise: they aren't your friends.
English
11
30
141
11.7K
hmmm
hmmm@threecnine·
Now we know why they fixed Bitcoin twitter/x...
English
0
1
1
43
hmmm retweetledi
Marty Bent
Marty Bent@MartyBent·
RBF'd transactions are on the rise. Assume the Coldcard attack has been widely discovered by many attackers.
Marty Bent tweet media
English
23
31
307
35.9K
hmmm retweetledi
Kevin Loaec 🧙‍♂️🐟
I will post a blog article later today. But TLDR: - it's worse than you think. - Mk4, MK5, Q will get drained. - multisig of Coldcard devices, or multisig where Coldcard signatures are sufficient to reach the threshold are at risk. - MINISCRIPT WALLETS are ALSO at risk, if you use Coldcards where only CC signatures are enough to spend, or to recover. No need to panic, but time to plan a move to new mnemonics/devices in the next few days, if you used a Coldcard in your setup.
English
68
184
843
106.5K