Register and share your invite link to earn from video plays and referrals.

Nick Neuman
@Nneuman
Reinventing the Swiss bank for the sovereign individual | CEO & Cofounder of Casa @CasaHODL.
1.5K Following    12.9K Followers
It sounds like Mk4, Q, and Mk5 are also vulnerable in a different way than Mk3. Slightly less problematic than Mk3 but still not great to keep using. If you're using single sig Coldcard at the moment you should move your assets to a different wallet (multisig, exchange, other HWW) to be safe.
Show more
Interesting security post about real experience using Mythos Yet I yearn for the days of reading important posts that aren’t written by an LLM
Cloudflare's security team spent the last few weeks testing Anthropic's Mythos against fifty of our own repositories. What we learned about offensive AI, why faster patching is the wrong reaction, and what the architecture around vulnerabilities has to look like next.
Show more
A massive security improvement you can make TODAY to protect yourself: We are seeing many clients get their emails compromised over the last couple of weeks. Big increase in hacker activity. The compromise is usually from password reuse + no 2FA, or it’s from a fake Google phone call that tricked them into giving it up. Your email is often the key to your life! Do yourself a favor and take 5 min to change your email password to a unique one + add 2FA **TODAY!**
Show more
The competitive product dynamics of frontier models is wild. One model release can be a banger, and then if you mess up the next release everyone floods to your competitor. GPT-5.5 is a banger and tons of people leave Opus 4.7 because it’s mid. OpenAI could mess up on 5.6 and send everyone back to Opus 4.8. And even harder, the quality of the output isn’t really fully under the labs’ control. There is uncertainty that even the model creators have of what comes out the other end. Thinking about how this is much different than the last era of software product development, where once you have a core of a great product, it’s actually pretty hard to mess it up. You have to make a lot of bad decisions over a long period of time. Otherwise the product keeps working well. Just very interesting to watch from the outside (and participate in as a customer)
Show more
Social engineering has gotten even more rampant this year. Didn't think it was possible for it to get more frequent, but it has. Farms of people doing this crap. Don't answer the phone from unknown numbers! Those people are not trying to help you!
Show more
We did a security focused hack week this week, came out of it with 4 amazing new security features that Casa clients are going to love. Will be launching in the next week or two - keep an eye out 👀 Speed is way up, augmented by the AI dev infra we've been building
Show more
This is an interesting approach for protecting old coins without needing to move them to new addresses. Requires alignment and people taking action ahead of time, but an approach like this significantly changes the arguments around BTC property rights issues.
Show more
Millions of BTC could be vulnerable to quantum computers Bitcoin may someday need to sunset those addresses, but that could force a public migration Today we published a design to let that migration be costless and silent: Public Address-Control Timestamps (PACTs) Link in 🧵
Show more
We are very happy that today Apple issued a patch and a security advisory. This comes following @404mediaco reporting that the FBI accessed Signal message notification content via iOS despite the app being deleted. Apple’s advisory confirmed that the bugs that allowed this to happen have been fixed in the latest iOS release. You can read more here: Note that no action is needed for this fix to protect Signal users on iOS. Once you install the patch, all inadvertently-preserved notifications will be deleted and no forthcoming notifications will be preserved for deleted applications. We’re grateful to Apple for the quick action here, and for understanding and acting on the stakes of this kind of issue. It takes an ecosystem to preserve the fundamental human right to private communication.
Show more
0
104
6.2K
1K
Forward to community
Joining @RoxomTV shortly! Will talk about fake wallet apps stealing your seed phrase, centralized acquirers going ham buying BTC, and making sure you don't lose your bitcoin when you die
Looking forward to reading this
Wow. This is why part of our Private Client offering is hardening clients’ cyber security outside of just Bitcoin. Your core email accounts all need to be lock tight, use passkeys or password managers so you don’t reuse passwords, add 2FA. Password reuse is a huge vulnerability people ignore because it’s annoying to fix. Well it’s much more than annoying to have someone break into your house because they used your leaked password to log into DoorDash and track your ordering habits.
Show more
Solid reporting here on a string of wrench attacks in California back in December. Attackers used data leaks to find their target's weak and reused email/password combos. Then they logged into apps like DoorDash and Uber Eats to identify home addresses, ordering habits, and more to set up real world attacks. Your digital security is extremely important to protecting you in the real world. When I've spoken to wrench attack victims in this situation, they have a pretty similar story: they didn't know all this was out there for attackers to find. You probably don't know the full extent of where you're exposed either. It's important to be alert and situationally aware of threats in real time (like looking for suspicious activity on your delivery apps such as getting logged out), but you should also be proactive now! So here are some things anyone can do and what I recommend for high net worth and prominent figures: 1. Use a password manager like 1Password to generate new and unique passwords for every online account. This sounds annoying, but it's actually great because it autofills everything for you. Go from memorizing many passwords, to just memorizing one master password. They'll even tell you if one of your passwords shows up in these data breaches. 2. Sign up for @optery, which helps identify and remove data about you and your family online. You can use code BEAUSECURITY for 20% off at checkout. 3. Create good home security habits. Don't let strangers in your home under innocent excuses ("can I have a glass of water?" or "my pen isn't working for you to sign for this package, can I come inside and get one?") Provide instructions for all delivery drivers to leave packages and food outside of your front door, never let them inside. Brief your family/roommates about these threats 4. Invest in your digital security. If you are high net worth, a doxxed (or even "undoxxed") influencer, an executive, consider a digital privacy and/or threat monitoring service. I recommend @BiscayneSecure who are a boutique security firm of ex-Feds that help HNWIs with this intersection of digital and physical security Don't be a victim, take matters into your own hands If you're not sure where to get started or what's right for you, shoot me a DM. Always happy to get folks on the right track and help you evaluate where you're actually at risk.
Show more
Join us for a conversation about quantum risks that will be about facts. Learn about the latest research and what we can do as a community to address the risk. We'll keep the FUD in check! 😉
The biggest companies in our industry are all racing to build some flavor of the "Everything Exchange". Stocks, crypto, perps, prediction markets, trade, trade, trade. Casa is not particularly interested in enabling new ways of gambling in our increasingly nihilistic society. Maybe that means we will have a smaller business in the short term, but I think it also gives us a better chance to have a big business in the long term. And of course, it means we get to build something that we think is actually good for the world. If you aren't doing that, what's it all for anyway?
Show more
Irony is undefeated- the UK is banning stablecoin self custody, while Stripe is launching MPP enabling AI to use self hosted wallets all over the internet. If you try to regulate new tech with old rules, you’ll cut off any chance at your country benefitting from innovation.
Show more
As I talked about last week on @RoxomTV, we should view bitcoin as a different type of hedge asset than gold. It is a geopolitical risk hedge, and it's much more useful than gold is for that purpose.
Bitcoin is safety when it matters most.
Helpful guide to setting up a robust email privacy system