pull down to refresh

I still do. However the hack is unacceptable. Someone could follow the directions to a T, doing everything exactly like they are supposed to and still lose their savings despite perfect off-chain security. It is unacceptable.

Bitcoin is competing against houses and gold atm, and those things do not get hacked.

What others are unwilling to admit is that the bug-apocalypse is just beginning, the AI tools are relentless, merciless and unforgiving and they find bugs that humans cannot. This is likely just the beginning of crypto-bugs and apparently bitcoin isn't immune either.

Bitcoin is competing against houses and gold atm, and those things do not get hacked.

They can get "hacked" in other ways. Nothing is foolproof. Let's wait and see what really happened to this user and what the point of failure was.

reply

Friend it wasn't the user. It looks like a failure of the ColdCard hardware RNG which means that thousands, maybe 10s of thousands of users are effected. Using the RNG's entropy for a seed phrase means it can be brute forced, and if that's true a lot of addresses are now vulnerable.

reply
114 sats \ 1 reply \ @optimism 30 Jul

"unacceptable"? What are you saying?

You have no choice than to accept it because it happened 21h ago and there is not going to be a rollback. What is needed is a path to safety, a post mortem, infrastructure to structurally improve whatever weakness this turns out to be. More safeguards.

reply

"What is needed is a path to safety"

That's nice to say but it's hard to tell users that when they have stacked sats and suddenly they wake up and they're all gone. The number of users affected could be much, much higher if I understand the twitter analysis right. A lot of people won't move their funds, or they'll move them wrong or make a mistake or they wont have another hardware wallet or won't even know about the hack before their funds are gone. For all we know the entropy on the Coldcards is highly compromised.

I personally didn't lose a sat (thank goodness) because i 'manage risk' across multiple devices but that's a lot to ask of people to use multisig when Coldcards were supposed to be 'safe enough.' Of course there isn't a rollback but IMO the magnitude of something like this shouldn't be papered over either.

If we're being really honest AI makes gold look good - it is permanently offline and the best way to improve bitcoin is to be transparent with ourselves.

reply

this is the same old adage of blaming the money when a bank gets robbed, no its the institutions and software/hardware that are 'protecting' it.

Coldcards used to be standard, no way after this fiasco

reply

I think you are right about that. So of we think that this is going to be more common, I wonder what we tell users? Be even more paranoid? Not terribly helpful advice.

reply

no single point of failure.

reply
126 sats \ 1 reply \ @Scoresby 30 Jul

I think it is pretty easy to overlook SPOFs.

I feel pretty good about my own setup, but I am going over things again because there are so many places where I could have let something slip in.

reply

Before I got an enormous bill to pay a few months back... I used a singlesig coldcard. Joke's on the attacker cuz I spent it all.

reply