Register and share your invite link to earn from video plays and referrals.

TFTC
@TFTC21
Truth for the Commoner. Bitcoin, freedom, and truth in the digital age. Daily newsletter + podcast. Subscribe.
2.4K Following    116.1K Followers
We've made @bitkey shipping free and next-day by default. Stay safe out there.
Block engineers trace COLDCARD attacker to blockchain services provider. Clay Garrett, engineering lead for @blocks Bitkey, shared that during their investigation of the COLDCARD drain, Block's team identified an unusual pattern in the sweeps that led them to a breakthrough. The attacker used a paid account at a well-known blockchain services provider to query the targeted addresses and perform related activity during the theft. Block contacted the provider directly and their internal logs "matched the suspected workflow with extraordinary specificity, including the number, timing and sequence of requests." Garrett noted there is no evidence the provider knowingly participated in or facilitated the theft, stating it "was supplying its standard services in response to requests that did not reveal their broader purpose." The team is now sharing the information with authorities and will provide further updates when doing so won't interfere with the investigation. This is a significant development as it means the attacker left an identifiable trail through a service that maintains account records, potentially giving law enforcement a direct lead.
Show more
1/ During our investigation of the Coldcard drain yesterday, we identified an unusual pattern in the sweeps. That pattern led us to a hypothesis that has since been confirmed: the operator used a paid account at a well-known blockchain-services provider to query the source addresses and perform other related activity during the sweeps.
Show more
i have used and recommended coldcard for years im sorry this is all incredibly fucked
0
174
2.1K
91
Forward to community
Conner Brown of @bitcoinpolicy urges Coldcard victims not to destroy compromised devices after the firmware flaw that drained tens of millions in BTC. “If you have a Coldcard that was compromised, do not throw away or destroy the device.”
Show more
Hyperscale Data sells 100 Bitcoin, establishes BTC-backed credit facility to accelerate Michigan AI campus.
"Even the smart guys screwed up self-custody. How can we expect anybody will comfortably self-custody after this?" @jamesob on the second-order effects of the COLDCARD vulnerability, why every hardware wallet maker has had a fatal misstep, and why the only categorical fix may be covenants.
Show more
"Security by obscurity is going to zero rapidly." @jamesob and other researchers independently reproduced the COLDCARD vulnerability by pointing an AI model at the firmware history. This is the new reality for open-source security.
Show more
"You screw up one thing, the wrong one thing, and it's toast." @MartyBent and @jamesob on the COLDCARD vulnerability, what it means for self-custody, and why you should be reaching out to anyone you've ever recommended a COLDCARD to.
Show more
Coinbase Chief Policy Officer on CLARITY Act progress: "We've got ethics nailed down, we've got nominations nailed down, we've got a bipartisan bill on the substance, we should be good to go."
Show more
Discussed the Coldcard vulnerability with @jamesob this morning. Brutal 24 hours, but make sure you listen to this to understand what's going on and how to protect your coins if you're out of the loop.
Show more
.@BTCsessions walks through how to safely migrate your COLDCARD seed using dice rolls if you don't have other hardware available. Don't wait.
TFTC 777 w/ @jamesob: "If you're single-sig with no passphrase or dice rolls, you need to drive home and migrate your funds. These wallets are dangling in the wind." We discuss: ⚡ The flaw exposed overnight ⚡ How to check your risk ⚡ Why self-custody still wins
Show more
NVK responds to COLDCARD community. Coinkite CEO NVK published a statement addressing the COLDCARD entropy vulnerability. "I'm sorry and I'm devastated," he wrote. "As a team that has dedicated our lives to securing the Bitcoin held by millions of individuals, businesses, and families, this is our core responsibility, and we fell short." NVK said the company has shipped a firmware hotfix that removes the software fallback path entirely, but stressed it does not fix seeds already generated on vulnerable firmware. "If your seed was generated before the fix, it needs to be individually migrated to a new seed. A firmware update alone cannot do that for you." He urged anyone who knows a COLDCARD owner to help spread the word, noting the company does not store customer information. "We know an apology doesn't return anyone's funds. We know we'll have to earn back our users' trust. That starts with being open and telling the truth about how this happened." NVK closed with a warning to the broader developer community: "AI-assisted code review can now find latent bugs at a speed that is outpacing even the industry's most seasoned experts. If your firmware is open-source or has ever been public, assume it's already being read by attackers and defenders alike."
Show more
COLDCARD Security Update: Coinkite Explains the Entropy Bug Coinkite has published a detailed technical breakdown of the COLDCARD seed generation vulnerability disclosed yesterday. During a 2021 migration to Bitcoin Core's libsecp256k1 library, seed generation accidentally started pulling from MicroPython's software random number generator instead of COLDCARD's dedicated hardware RNG. The bug slipped through because both functions shared the same name, allowing the wrong one to be silently selected during the build process without triggering an error. The Mk3 is the most affected device. Seeds generated on firmware 4.0.1 and later have an estimated effective search space of roughly 40 bits, far below the intended 128-bit security target, and those users should migrate immediately. The Mk4, Q, and Mk5 models mixed in additional entropy from their SE1 and SE2 secure elements, bringing the effective search space to approximately 72 bits, better but still well below the 128-bit target. Users need to update their firmware (Mk3 to 4.2.0, Mk4/Mk5 to 5.6.0+, Q to 1.5.0Q+), generate a completely new seed, and migrate their funds to the new wallet. Updating firmware alone does not fix a seed that was already generated by the affected versions. Even users who added dice rolls or a BIP-39 passphrase during original seed creation should strongly consider migrating unless they are certain they used at least 100 fair, independent rolls. Coinkite acknowledged that AI likely helped the attacker discover the bug, noting they had recently used AI to review their own code and it missed the issue entirely. Full technical backgrounder:
Show more
The first post was the advisory and what users should do. This second post has the technical details: what actually went wrong, why our reviews missed it, the impact across Mk3/Mk4/Q/Mk5, and what we changed. ( current evaluating Mk3 firmware release )
Show more
Former Barclays CEO Bob Diamond tells CNBC the Clarity Act “is really good for the banks.” “The largest, most successful banks are going to benefit from this.” “No one is investing more in innovation right now” than the big banks.
Show more
Coinkite has issued a security advisory for Coldcard Mk3 users. If you generated a seed on a Mk3 running firmware 4.0.1 (March 2021) or later, your funds may be at risk. The issue appears to be related to the device's random number generator during seed creation. Mk4, Q, and Mk5 are not affected. If you used a BIP-39 passphrase on top of your Mk3 seed, Coinkite says the risk is minimal. If you didn't, you should migrate your funds to a new seed generated on an unaffected device. Don't rush. Send a test transaction first, verify the new wallet, then move the rest. More details from Coinkite's investigation are coming. Full advisory:
Show more
@crossbordercap The bear market is a gift if you know what to do with it. The @unchained free field guide gives you 21 actionable steps to stack with discipline and secure your position for the long term.
Show more
What compelled thousands of men to zerg rush the Spanish border on the same day? Who is coordinating this?
Reports are coming in that some Coldcard hardware wallet users are having their bitcoin drained. Multiple known Bitcoiners are confirmed affected. @KLoaec’s working hypothesis is a low-entropy RNG issue, possibly in the secure element, with an attacker using AI to bruteforce and sweep only bip84 (segwit) paths, which would explain the partial thefts. Root cause is still unconfirmed. Could be RNG, nonce reuse, or something else entirely. If you use a Coldcard single-sig setup, check your balances now. If affected, email Coinkite with proof you control the keys.
Show more
"$90,000 into a kid's account becomes $13 million. That's the power of compounding. It goes into the S&P 500 and it can't be sold. It's an unstoppable passive bid." @MelMattison1 breaks down how Trump accounts create a permanent bid under equities.
Show more