pull down to refresh
I'm more just wondering what that screenshot is supposed to say. It looks like a diff but can't read any of it.
Right. Instagibbs was able to regenerate an affected wallet’s seed by using a firmware-reset Coincard. The only necessary input was the number of button pushes on the device. I have seen someone state that the wallets were generated just with 17 bits of entropy and maybe the date, which is trivial to traverse programmatically.
that's actually crazy
This is a very very massive hack. But of course the stackers know that.
My guess is that the 'real' hacking is just beginning.
A low-entropy passphrase is not good enough because a '25th word' is a joke to brute force it's basically like not even having one. And a lot of people won't know about the hack, and now that the whole world is looking for it all the those seed phrases are toast. Next the hackers will be using low-entropy '25th words' with low-entropy seeds just GPUs to rainbow-tables.
A lot of cold card customers will be waking up confused as to what happened.
Not to mention a lot of people don't have access to the HWW or they are at work or traveling or whatever so they can't just move things. Plus they need a safe seed to move it to. Plus my guess is that anything in the mempool... will only draw attention to vulnerable seeds which will be brute-forced by hungry hackers.
Twitter is saying the bug potentially effects mk3 mk4 and Q devices.
afaik