Register and share your invite link to earn from video plays and referrals.

Kevin Loaec ๐Ÿง™โ€โ™‚๏ธ๐ŸŸ
@KLoaec
@wizardsardine CEO ๐Ÿช„๐ŸŸ. โฌ›๐ŸŸจ ex Breaking Bitcoin and BoB. @btcazores @revaultdev @lianabitcoin
799 Following    11.6K Followers
PUBLIC SERVICE ANNOUNCEMENT: A phishing email impersonating "support-liana" (we don't have such emails) is circulating. It seems to target people very broadly, even outside of Bitcoin. Be aware of phishing, do not enter mnemonics on the internet (nor on the real liana, for that matter).
Show more
Instead of shitting on NVK and co, please make sure your fellow bitcoiners are OK. Contact the ones are your local meetup, those you know are physically around you, etc. They may have lost EVERYTHING, and they need human support, from people who understand. They won't manage to get help from non-bitcoiners, who just see it as monopoly money, or "was being lucky, now unlucky". This situation is so fucking sad. Thousands have lost everything. You might save a life today.
Show more
We are just launching a tool for Liana users (and other wallets) to easily send their transactions through Slipstream (out of band, for Miniscript and Multisig wallets affected). This may still have some bugs/issues, please send feedback. This is running entirely on your browser, not on our servers.
Show more
Ass CEO hat: "You should all have used what we've been building for the past many years. @lianabitcoin . You would not have lost your bitcoin then, even with no dice rolls. Liana is free, open source, and quite easy to use. "
Show more
By NOT rolling dice, you did NOTHING WRONG. You never were expected to roll dice or add a passphrase. Human generated entropy, even of great quality like dice, is LOWER than device generated entropy. The problem is, the device you bought to do that job was not doing it. Same as if you bought casino dice but they only roll 6s. Not your fault. The quoted tweet below is explaining why. How to protect yourself in the future, against a BUG in a signing device? The solution is not dice, that code could have been buggy too. The solution is MULTI-VENDOR MULTISIG. Any type of bug or attack in one device, you are still protected. Entropy, Key derivation (from dice for example), Signing (nonce), Malicious cryptographic library (Key exfil), Supply chain attack (physical RNG not random, not a code issue), etc, etc.
Show more
Here is our blog post. - Section 1 is for Liana users, and anyone interested in "game theory" of descriptors and Miniscript/Taproot/Segwit. - From section 2 its our Post-Mortem of Coldcard. TLDR: It's worse than you think. Even users who have a safe mnemonic (dice rolls) have BROKEN FEATURES on their Coldcard.
Show more
0
38
477
173
Forward to community
It's happening. Mk4, Mk5, Q are now actively drained. Breaking an Mk4 is HARDER than breaking a weak passphrase, so your Mk3 "passphrase protected" are at immediate risk (if less or around 32 bits entropy).
Show more
0
71
962
226
Forward to community
PSA: I AM GETTING REPORTS OF NEW SWEEPS. MORE ATTACKERS ARE CURRENTLY DRAINING WALLETS. GET YOUR COINS OFF COLDCARD NOW (if MK3) OR SOON (if Mk4, 5, Q)
0
22
490
113
Forward to community
I will post a blog article later today. But TLDR: - it's worse than you think. - Mk4, MK5, Q will get drained. - multisig of Coldcard devices, or multisig where Coldcard signatures are sufficient to reach the threshold are at risk. - MINISCRIPT WALLETS are ALSO at risk, if you use Coldcards where only CC signatures are enough to spend, or to recover. No need to panic, but time to plan a move to new mnemonics/devices in the next few days, if you used a Coldcard in your setup.
Show more
0
69
849
185
Forward to community
My current hypothesis for the Coldcard theft. 1- The issue: - Low entropy RNG, either in a library or secure element/chip itself. Could be a limited batch or a specific firmware. - Probably affecting the mnemonic, even if the theft is weird/confusing. - Thief knows about the RNG bug, but not about Bitcoin. 2- The attack - Attacker asked an AI to craft a script to bruteforce and prepare a sweep. - AI ONLY TRIED bip84 derivation paths - AI ONLY TRIED A LIMITED NUMBER OF DEPTH This is why we only see Segwit being stolen, and sometimes partial wallets instead of full wallets. If i am correct: - The funds of partially affected wallets ARE AT RISK or further drain - The funds of other type of addresses ARE AT RISK when the scan looks for them too. If I am wrong: - WHY only bip 84? - WHY partial sweeps? Could be some very rare bug happening in very specific cases, but looking at the chain it's hard to guess what it could be. Some weird derivation bug happening only in CC, at bip 84 paths?
Show more
Alright I'm convinced THIS IS NOT A DRILL. It is a small minority of users, not everyone. We DON'T KNOW what the attack is. Could be RNG, could be NONCE, could be something else. We DON'T KNOW if it affects only single sig with no passphrase, or if it's a different layer. Use multisig, preferably multi-vendor.
Show more
I'm hearing a potential issue with some Coldcard wallets being drained. I will not FUD, but would like to get at least reports of trusted people. Can my followers, who own a CC, generated the mnemonic on the CC, and use it as a single sig check their balance and report if it's gone. Hopefully a nothing burger, but gonna do my job here.
Show more
Making Miniscript (and multisig) more user-friendly often comes from industry-wide efforts. We have 2 bips being worked on now, if you work on wallets please review!