We’re not forking
Ok we’re forking but it’s only a temporary fork
Ok it’s not temporary but it’s a majority fork
Ok it’s not a majority fork but we have miners support
Ok we don’t have miners support but it won’t cause a chain split
Ok it will cause a chain split but it won’t be permanent
Ok it will be permanent so we’re changing the mining algorithm
Show more
We’ve entered a transitory phase in cybersecurity where all assumptions and paradigms are being shattered and forced to adapt to the new reality of AI being able to perform in hours what previously required weeks of work from teams of highly trained experts.
Show more
We are just launching a tool for Liana users (and other wallets) to easily send their transactions through Slipstream (out of band, for Miniscript and Multisig wallets affected).
This may still have some bugs/issues, please send feedback.
This is running entirely on your browser, not on our servers.
Show more
The cloud is just someone else’s computer
The exchange is just someone else’s self custody
@BritishHodl Where do you think exchanges store their Bitcoin?
In a magical non self-custody solution?
If you’re only in Bitcoin because you think it’s a good investment and the price will go up, please just buy the ETF and ignore everything else.
But if you’re here for true freedom and self sovereignty, there’s no alternative to self custody.
Show more
Ass CEO hat: "You should all have used what we've been building for the past many years.
@lianabitcoin .
You would not have lost your bitcoin then, even with no dice rolls.
Liana is free, open source, and quite easy to use.
"
Show more
Liana is probably the best wallet out there for long term self custody, and the recent events should be a wake up call for everyone to try it!
Plus
@KLoaec and the
@lianabitcoin team did an incredible work during this current crisis! 🙏
Show more
Hey
@kloaec, you’ve done a great job helping people over the past few days, but can you put on your CEO hat for ONE SINGLE post?
You spent 4 years of your life on Liana, which is literally designed to mitigate risks like this, and many people don’t even realize that.
So please, please do one shill post before going back to helping people in the short term.
My equity thanks you, and so do future Liana users who can rest easy the next time around.
Show more
Multi vendor multisig is the best way to avoid single point of failure.
By NOT rolling dice, you did NOTHING WRONG. You never were expected to roll dice or add a passphrase.
Human generated entropy, even of great quality like dice, is LOWER than device generated entropy.
The problem is, the device you bought to do that job was not doing it.
Same as if you bought casino dice but they only roll 6s. Not your fault.
The quoted tweet below is explaining why.
How to protect yourself in the future, against a BUG in a signing device? The solution is not dice, that code could have been buggy too. The solution is MULTI-VENDOR MULTISIG. Any type of bug or attack in one device, you are still protected.
Entropy, Key derivation (from dice for example), Signing (nonce), Malicious cryptographic library (Key exfil), Supply chain attack (physical RNG not random, not a code issue), etc, etc.
Show more
It’s important to note that the Coldcard hack was the absolute worst case scenario when it comes to self custody.
Just about any other possible attack would’ve required at least some user action, physical device access, etc. and would’ve likely been much more limited in effect.
Non random seed is the worst case scenario, not an “average” vulnerability, and while scary it is extremely unlikely we will see such severe cases happening for self custody, even as AI keeps improving.
Show more
Here is our blog post.
- Section 1 is for Liana users, and anyone interested in "game theory" of descriptors and Miniscript/Taproot/Segwit.
- From section 2 its our Post-Mortem of Coldcard.
TLDR: It's worse than you think. Even users who have a safe mnemonic (dice rolls) have BROKEN FEATURES on their Coldcard.
Show more
If I could give only one #
Bitcoin# security advice it'd be this:
DON'T USE SOMETHING YOU DON'T FEEL COMFORTABLE WITH.
When holding Bitcoin, more often than not, you are your worst enemy.
Test, learn, and gain confidence playing with small amounts first - then move real funds.
Show more
As a general recommendation, it doesn’t matter if you keep Bitcoin on a cold wallet, hot wallet, or even an exchange, you should always do at least one test transaction in and out to make sure you are familiar with the full flow.
A wallet hack or a bank run on an exchange can always happen, and it’s important to know how to exit quickly.
Show more
After 5 years, I finally learned how to send money from a ColdCard. It was complicated, tedious, and took hours.
I honestly wish I didn’t have to learn under these circumstances.
Show more
If you think the point of holding Bitcoin is to get 10% annual returns you know absolutely nothing about Bitcoin
Yes the fuck it is. Good luck convincing a normal human being who's not a virgin nerd that you need an open sourced wallet, symmetrically weighted casino dice, 100 minimum rolls, metal plate, 35 chars long passphrase & an air gapped Linux computer just to get 10% annual returns.
Show more
We wasted years of focus on the stupid BIP110 spam nonsense instead of making Bitcoin self custody safer with on chain covenants.
It’s time to finally refocus the energy on bringing a covenants soft fork.
Show more
If your long term solution for Bitcoin security is custodians and ETFs then what’s even the point of Bitcoin?
Without self custody Bitcoin is pointless.
We handed out Coldcards (MK3s and Qs) at HRF events in 2022 and 2024
The attendees have been contacted with urgency to migrate funds
Self-custody is still the way
Bitcoin is about being your own bank, not giving your money to a bank
The mission continues 🫡
Show more
Our lead developer
@KeithMukai has actually been dipping into his own bitcoin savings to continue work on SeedSigner, and our lead maintainer
@newtonick works on the project pro bono as well. If you get value from
@SeedSigner consider sending them a few sats via:
(Note: I am intentionally not included in the donation workflow)
Show more
I will post a blog article later today. But TLDR:
- it's worse than you think.
- Mk4, MK5, Q will get drained.
- multisig of Coldcard devices, or multisig where Coldcard signatures are sufficient to reach the threshold are at risk.
- MINISCRIPT WALLETS are ALSO at risk, if you use Coldcards where only CC signatures are enough to spend, or to recover.
No need to panic, but time to plan a move to new mnemonics/devices in the next few days, if you used a Coldcard in your setup.
Show more
A simplified explanation of the Coldcard issue.
When you set up your Coldcard it generates a secret - the words it tells you to copy and keep safely. Turns out it was choosing those words in an easily predictable way (instead of randomly), meaning it’s easy to guess which words a Coldcard would choose.
Since it’s easy to guess your secret, anyone can know it. This secret is the key to your Bitcoin - meaning anyone who guesses the secret has as much ownership of the Bitcoin as you do, and can steal it to a wallet they control.
Show more
With a vault, we could have a single key wallet with delayed transactions, giving enough time to sweep funds to a multisig/ trusted custodian/ social recovery.
We need better self custody.
ok well this is a great time to start talking about vaults enabled through op_ctv.
No one has an objection on ctv besides “what if there’s something better”. Well, this is what we get
If I could give only one #
Bitcoin# security advice it'd be this:
DON'T USE SOMETHING YOU DON'T FEEL COMFORTABLE WITH.
When holding Bitcoin, more often than not, you are your worst enemy.
Test, learn, and gain confidence playing with small amounts first - then move real funds.
Show more