Register and share your invite link to earn from video plays and referrals.

_Checkmate ๐ŸŸ ๐Ÿ”‘โšกโ˜ข๏ธ๐Ÿ›ข๏ธ
@_Checkmatey_
Helping navigate #Bitcoin#'s volatility Newsletter Onchain Analyst @_checkonchain Charting Suite
1.4K Following    131.8K Followers
Your proposed fork didn't achieve rough consensus. Instead of reflecting on why your proposal failed, you blame the referee, and the rules of the game, claiming a shady cabal has designed them to work against you. You wanted to play chess by reverting the two pawn moves forward rule. The majority signalled that they did not want to play with those rules. The obvious result is nobody outside your little clique sat down to play your version. The problem isn't with the existing rules of chess, nor those who currently enjoy playing by them. The problem is that your proposal for changed rules was unappealing, and the attempt to force feed it to us didn't land...at all. The new plan seems to be forking into some mutant form of checkers. Best of luck with that.
Show more
Bitcoin Red Team Update: We have been working around the clock, with ~$20,000 of spend up to this point across different services. Funding is secured, I appreciate all the gestures for donations but it is not necessary. The bill is taken care of. We have done over a dozen disclosures up to this point, with 150 repos scanned. The hardest part is coordinating to get things to the right people (thank you @danielabrozzoni for the help) I have a first pass on a bitcoin red team agent harness which only requires an @opencode zen api key, makes it easy for us to use K3 for the actual heavy lifting and then GPT Sol + Fable/Opus + GLM5.2 for supporting documentation. While it is powerful, having found critical issues, I would view this as only version one. There is a lot of iteration I'm looking forward to improving on. Our goal is to open source the harness so it can be pointed at internal repositories for insights so the hardening of defenses can go deeper than the code which is made public. We also have been connected with OpenAi for some help so I could manage getting the @OpenAI Cyber Harness running as well (thank you @lylepratt ). Its a much more expensive scan, but well worth it for load bearing portions of the bitcoin ecosystem and has already yielded good results. Goals for tomorrow are scale in processes and systems so we can do a better job and automating full end to end functionality to get humans out of the loop for the heavy lifting. The first mile (requests/staging) and last mile (handoff of reports) are the choke points right now. Thank you @stutxo @callebtc @benthecarman @thesimplekid and so may more.
Show more
0
189
2K
228
Forward to community
My latest piece reflects on the emotional journey Bitcoiners have experienced over the last 3 days. There is a lot of triage work left to do, and even more rebuilding afterwards. It's important to appreciate the emotional hit, and then bounce back.
Show more
My latest piece reflects on the emotional journey Bitcoiners have experienced over the last 3 days. There is a lot of triage work left to do, and even more rebuilding afterwards. It's important to appreciate the emotional hit, and then bounce back.
Show more
I have spent over $10,000 scanning 100+ bitcoin ecosystem related libraries looking for vulnerabilities with Kimi K3 running as quarterback. Myself and a small "Red Team" have found multiple serious vulnerabilities impacting the ecosystem. They vary in scope severity, but this is a call to action. For any critical tier vulnerability that was identified if I was able to immediately demonstrate a POC (proof of concept), I have already responsibly disclosed to the maintainers. HERE IS HOW YOU CAN HELP ME IF YOU ARE NOT TECHNICAL: - please share with me any repository that is on github that I can scan, we want to cast a wide net. It takes a few moments for you to link github accounts, we'll take it from there - if that project does not have a SECURITY.md make an issue asking the dev to list one IF YOU ARE TECHNICAL: - If you are a maintainer or contributor to a project, I may have already scanned your repo, hit me up I'll share the results, if not I'll add your project to the list. - If I can trust you to do larger review to start looking through this stuff to give me more eyes let me know. AI Has forever changed software development. Tomorrow marks 1 week of Kimi k3 being live in open weights. We are going to accelerate.
Show more
0
280
2.5K
434
Forward to community
We are currently in a golden hour right now. The golden hour in medicine is the first 60 minutes after a life threatening event to the body. What is done in that hour can set the course for life or death. THIS MAY BE LIFE AND DEATH FOR YOUR BITCOIN IF YOU OR SOMEONE YOU HAS USED A COLD CARD Q MK3 MK4 MK5 OR Q REACH OUT TO THEM People with MK4/MK5/Qs are still recovering their bitcoin despite having an insecure device. THE TIME TO ACT IS NOW IF THIS IMPACTS YOU OR SOMEONE YOU KNOW, YOU NEED TO GET YOUR BITCOIN OFF SINGLE SIGNATURE COLD CARDS THAT USED THE DEFAULT ENTROPY NOW
Show more
The most common question I am getting right now in the fall out of the news of COLD CARD MK3, MK4, MK5 and Q having compromised entropy, is: "Rob, what would you do right now if you were in my shoes? Where would you send your bitcoin to be safe?" I will share with you my list of what I would do, but first, there is AN URGENT SECURITY ADVISORY IN THE BITCOIN ECOSYSTEM. Below is my personal assessment of the situation. If you or someone you know: Uses an MK3, MK4, MK5, or Q in a single signature OR A multi signature wallet where the cold card devices can move the funds on their own (Example, 2 cold cards and a Ledger). Please continue reading. You may be in danger. If this does not apply to you, keep on reading if you like, but you are not impacted by this issue. If you are still here, there are three identified mitigations that protect you at the moment. They are all different forms in which you may have brought your own entropy. A: DICE - This is done by either rolling dice from the start, or adding dice rolls to the generated seed phrase. At least 50 dice rolls would be my threshold at 128 bits of entropy. OR B: PASSPHRASE - You used a passphrase of sufficient entropy (128 bits). 128 Bits of entropy pass phrase examples include RANDOM combinations of the following: - 12 BIP 39 seed words. - 10 common words in the english language - 25 mixed lower case letters and numbers - 20 if you use ASCII characters Note on pass phrases: This does not include the same word 12 times, 10 words in a sentence, etc. This combinations of characters/numbers OR words should never have been seen or spoken before in the total sum of all human knowledge and experiences. It needs to be RANDOM for it to be entropy. OR C: EXTERNAL ENTROPY - Your seed phrase was derived entirely outside of the cold card ecosystem. (It was imported into the cold card, not generated on it) Now, if you are still reading, and you do not have any of these mitigations in place, you need to move your funds. The urgency of circumstances are as follows: TIER 1: AS SOON AS POSSIBLE Scenario A: If you are in a signature wallet with an effected device, and did not use any of the mitigations listed above. You need to move funds right now. Find someone to help you, any moment your funds can be stolen. Scenario B: If you have an N of N (eg 2 of 2, 3 of 3, etc) multisig of just cold card devices that did not have mitigations listed above (dice and/or passphrase). Attackers will be grinding all of the combinations of compromised keys. They know all your seed phrases. You are compromised. It is just a matter of time for them to assemble the puzzle pieces together and steal your funds. If this scenario is you, I will have more below on how to mitigate risk when broadcasting your transaction. TIER 2: URGENTLY If you are in a single signature wallet with an effected device, and you used either less than 50 dice rolls OR a pass phrase less secure than what I shared above. The entire security of your bitcoin is reliant on how much of Dice AND Passphrases you applied to your wallet. Attackers know your seed phrase. Your entropy from dice or pass phrase is the only thing protecting you. Did you add a pass phrase of 'bitcoin'? You are basically in tier 1. Did you use 6 words? You are not at tier 1, but you aren't safe. You need to make plans to move funds quickly. TIER 3 SOON, BUT IMPORTANT CONTEXT: You have a multi signature wallet where the compromised devices have sufficient ability to move the funds. An example is a 2 of 3 multisig where you have 2 cold cards and another signer. The issue with Tier 3 is that an attacker may have already figured out your insecure seed phrases. This means when you broadcast your bitcoin transaction, an attacker in theory can then steal your funds. NOTE: IF YOU ARE IN THIS SITUATION, AND YOU HAVE REUSED ADDRESSES, ALL REUSED ADDRESSES PUT YOU RIGHT BACK AT THE TIER 1 MOVE RIGHT AWAY YOUR FUNDS ARE AT RISK AT THIS VERY MOMENT You should look into finding a way to use the @MARAFoundation_ slipstream service, which uses a private mempool. This means that by the time an attacker could see your attempted recovery, it is already in a block and not possible for them to steal funds. TIER 4: KEY ROTATION. This is where you have an insecure cold card(s) in your multisig quorum, and you know that the other keys in your quorum are not impacted by this bug. If there is a MK3,MK4,MK5 or Q in the quorum, BUT they either: 1. Rolled sufficient dice (50 min) 2. Have a strong pass phrase (as defined above). 3. Used entropy not sourced from the device, they are not impacted by this bug in the Cold Card (see notes earlier on mitigations). You are in a position where a minority of your keys are compromised. Funds are safe, but you are at reduced security. Make plans when you are able to remove the compromised device from your wallet. Now. With that security advisory out of the way, back to the question, what would I do in this situation? Below is just my opinion, but you should not rely on only my opinion, you will have to make your own choices based on what you feel is best for you. I want to be clear, if you are not on this list. It is not that I think your product/business is bad, insecure or at risk, I am directly answering the question of what I would do. This is my personal judgement given my decade of experience in bitcoin. First, a disclaimer: My bitcoin is at my company @AnchorWatch. I have full skin in the game in that if I'm offering a custody solution, there will never be another place I store large amounts of bitcoin long term for myself or my family, and it will be this way as long as I am here. I was the first bitcoin that went on our Trident Vault platform. If the day ever comes, I will be the last bitcoin to leave the platform. The years of what we built at AnchorWatch were for exactly moments like this. Avoiding catastrophic risk of ruin scenarios. We offer 2 products: 1. Our Flagship Product where you as the customer can hold 1 or 3 keys, and we act as a cosigner. We leverage bitcoin native smart contracts which allow for your bitcoin to have different ways it can be spent across time. 2. Multi Institution Custody, where we let you distribute your keys across 3 institutions of ourselves, @bitgo and @CoinCorner. 2 of the 3 institutions must sign off on the transaction, and you have to present a Yubikey signature before withdrawing to mitigate deepfake and compromised accounts. For both products as, since we are a cosigner, we are able to enforce rules like whitelisted addresses, and velocity controls (how much bitcoin can you send how often). You can even disable the send button on the platform if you so choose! We also offer 1:1 insurance backed by Lloyd's of London. If you want to learn more about what we do, hit up @_joerodgers or @BeccaAmilee to learn more, or check out our website. Now with that out of the way, places where I'd leave my bitcoin (besides @AnchorWatch) in no particular order: Custodian: I'd trust my life savings at @River under a duress situation. This is one of those times. @Leishman and the entire team at River are elite operators. It is my favorite bitcoin services business in the market today outside of my own. They own their own custody infrastructure, and at times like this, you want those who have extreme ownership and control over how their customer's money is being managed. @River does monthly proof of reserves, and you can turn on the force field feature which will freeze withdrawals of bitcoin. They have a world class custody team as well, and are making improvements regularly with a larger upgrade that has been planned for a long time, happening later this year. Collaborative Custody: 1. The @Bitkey is an incredible product with an elite team of engineers supported by the @BlockEng organization. They have exceptional bitcoin developers across @spiral_xyz and @CashApp teams who deeply understand Bitcoin. @jack has been a long time believer in bitcoin who has built an organization that has no peer in the resources they have not just understanding bitcoin, but building on bitcoin. You can pick it up a Bitkey at best buy today! I do want to add a disclaimer that all keys are managed within the Bitkey ecosystem. The Bitkey team has gone to great lengths to keep things secure, but in light of recent events, I want to call that out. At the moment, the Bitkey is my only exception to a purist ideal of multi vendor multisig (more below). 2. @CasaHODL - @Nneuman and @lopp have been on top of this incidence response, and have built a very clean user experience to let people be safe. You can either use a 2 of 3 or 3 of 5 multisig with a great mobile app. Casa is the best UX for soverign collaborative multisig that exists in the market today. 3. @uncahined - Unchained pioneered the collaborative custody model and the multi institution custody model. They have been working around the clock trying to support customers and have even been able to use slip stream going the extra mile on short notice to keep customers bitcoin safe. Self Custody: I have spent close to $5k on LLM tokens over the past 24 hours scanning over a hundred bitcoin related repositories. As of now, I have seen no vulnerability that has me concerned about any hardware device outside of the Cold Cards. Even so, you can't be sure. So I would follow the @mflaxman "Bitcoin 10x security guide". Its how I held my bitcoin before I founded @AnchorWatch, and even though the guide is 6 years old, the principles are timeless. I would remove his suggestion of using the cold card and replace it with any other hardware wallet. I would replace the cold card with a @Ledger at this time if it were my decision. You can pick up a Ledger up at Best Buy in the US. Michael pioneered multi vendor multisig as a concept, and if you want a fully sovereign solution, as of today there is no better mental model on how to think through this, he has advanced tabs to further increase the security. For his cold card guide he fairly calls out the added benefit of rolling dice, which would have saved you today. I think the future is combining the tech we use at @AnchorWatch to move beyond the single signature/ multi signature paradigm of custody, with the principles of @mflaxman's 10x security guide and the support of collaborative custody. More on that later, but I would check out @lianabitcoin from @Wizardsardine as well, they offer a fully open source wallet that enables these more advanced smart contracts and are security researchers in the bitcoin ecosystem. With that, I'm going to get back to work. I will post a followup reply if I have additional information or any corrections or clarifications to make.
Show more
0
134
1.3K
310
Forward to community
The last 48 hours have been some of the hardest I've experienced in Bitcoin. I've been putting out fires nonstop: helping people migrate funds in a panic, talking them through impossible situations, and breaking every protocol I'd normally insist on because there simply wasn't another option. I've had people so overwhelmed they couldn't even type their own seed phrases. They split them across Signal, Telegram, and email in multiple parts just to get through the migration. Together we moved hundreds of bitcoin under immense pressure. And we're nowhere near done. There are still hundreds of people with Coldcards in single-sig setups. We still don't know how far this entropy issue extends on later models. Even confidence in older hardware has been shaken, and many people are migrating out of caution. So I'm asking for one thing: If you're knowledgeable and you have a few hours to spare, please help. Help people verify their setup. Help them migrate safely. Help answer questions. Help those who have just lost life-changing amounts of bitcoin. Sometimes they don't need technical advice firstโ€”they need someone to calmly guide them through the next hour. I've seen wallets containing double-digit BTC balances drained. It's heartbreaking, and I sincerely hope those responsible are identified and brought to justice. What disgusts me is seeing people use this as an opportunity to score points, dunk on others for using or promoting Coldcard in the past, or somehow drag the conversation back into the endless Knots vs. Core and spam-filter debates. This isn't the time. People are hurting. Some have lost years sometimes decades of savings. Be the person who helps, not the person who farms engagement. Please help.
Show more
Now is the time to save peoples money. The people who are trying to cause drama will not be looked back on kindly when the dust settles. Get everyone off the sinking ship. We have the rest of time to talk about shared learnings.
Show more
We are in a narrow window where one post (on any social media network) can save someone's life savings. If you or someone you know is holding Bitcoin on a MK3, MK4, MK5, or Q - REACH OUT TO THEM! I've spoken to multiple people who were aware of the cold card issue, but when I pressed them, realized they were not 100% certain they were safe and have now changed their weekend plans. Shoot a text, send a DM, do a wellness check even if you think that person has their stuff figured out. Act as if your life savings were at risk. You are actively engaging in harm reduction if you just make a post.
Show more
0
21
438
131
Forward to community
For those self-custody bitcoiners who are also scrambling amid this Coldcard issue, you can take some comfort in knowing the larger community is working together quickly to find solutions. In the last few hours, @V4BTC, @_Checkmatey_, @Rob1Ham and so many more have put out detailed videos on how you can improve your situation. Times like these are VERY tough but it's good to see everyone putting company loyalties aside to help fellow bitcoiners. We will grow from this. Onward!
Show more
G'day folks. I've issued a free post regarding the very unfortunate Coldcard incident. For anyone with a platform and customers, please do your best to notify them. I have had many clients not on X reach out saying this was the first they'd heard of it
Show more
When the smokes clears from this Coldcard situation, remember the people who leaned in and gave their time and energy to help others. @w_s_bitcoin, @MrHodl, @without_rulers, @PortlandHODL, @Rob1Ham, @brian_trollz, @rot13maxi, @miketwenty1, @phjlljp, @coinjoined Thank you ๐Ÿ™๐Ÿป
Show more
You can actually keep using coldcard just generate new phrase on trusted device. Send the funds to the new phrase. Load the new phrase into coldcard. Check it works and then delete it from the other device. You don't need to buy new hardware because of this.
Show more
Practical mitigation step if you're on a Coldcard and worried about the security issue - MIGRATE to a strong passphrase setup. Example, select 7 words randomly from the bip39 word list, use that as your passphrase with a new setup. Migrate coins from old setup to the new passphrase one. Make sure you write down your new seed words + 7 word passphrase. This will give you some breathing room while you think about next steps. bip39 word list:
Show more
Folks who generated their seed with a Coldcard post 2021, please review this thread. Stay calm, focus, and take action.
If you have bitcoin residing under a single key that was generated on a Coldcard Mk3 between 2021-2023, and you - did not incorporate dice rolls - do not use a passphrase - do not use multi-sig I would advise moving funds as soon as possible.
Show more
If you have bitcoin residing under a single key that was generated on a Coldcard Mk3 between 2021-2023, and you - did not incorporate dice rolls - do not use a passphrase - do not use multi-sig I would advise moving funds as soon as possible.
Show more
0
124
1.7K
408
Forward to community
GOOD MORNING BITCOIN STILL HAS UNTHINKABLE ASYMMETRY, BUT IF YOU DON'T THINK IN TRILLIONS, YOU MIGHT NOT SEE IT COUNT YOUR BLESSINGS