Yeah the total losses aren't near as bad as something like FTX but in some ways this is definitely worse morale-wise. When people lose money on an exchange going under we can feel bad but say "you should have known better than to keep your money on an exchange" but these people were doing what they were told was right. These were their offline keys. We look like fools and all the things we have said look retarded. But hopefully it's like a plane crash and the errors made extensively studied by the industry so self-custody becomes much stronger in the end.
yes exactly I agree. I’m grateful Bitcoin only wallets exist. I’m grateful there’s others besides Coinkite. but they were the best ones. #SlayYourHeroes
this sucks. it’s the hw wallets that got me to buy in the first place. I was NOT gonna store on a hard drive
when Luke Dash Jr got 200 bitcoin stolen that was INSANE cuz he’s such an expert. but he didn’t use hw wallets!
an ironic thing on “bitcoin only” firmware and wallets is that sometimes it means there are less eyes on it. hypothetically general crypto wallets like ledger and trezor can have more eyes on software updates
I think the attacker is just grinding out low entropy deterministic seeds from the bad RNG but and then scanning to see if there are any funds there
Yes, that much I gather. How do we know which transactions are that? (Such that we can arrive at the number 1131 BTC or whatever and show them publicly?)
This shows no drains since 7/31 but idk if that’s still true
I was wondering about a tracker.
1200 Bitcoin is a LOT! Obviously not fatal from a money standpoint
But it’s fatal for us in the bitcoin community believing in NYSNYC and self custody
It was already a major leap to get ppl to take self custody. So many just buy on Robinhood or the ETF
Sure multisig is the way, but I can’t reasonably expect ppl to do that it was enough to get them to buy a ledger
We’re 17 years in we’re not going anywhere we already have the ETF. I hope this makes us stronger but ughhhhhhh. Worse than FTX or Mt Gox imo!
Yeah the total losses aren't near as bad as something like FTX but in some ways this is definitely worse morale-wise. When people lose money on an exchange going under we can feel bad but say "you should have known better than to keep your money on an exchange" but these people were doing what they were told was right. These were their offline keys. We look like fools and all the things we have said look retarded. But hopefully it's like a plane crash and the errors made extensively studied by the industry so self-custody becomes much stronger in the end.
yes exactly I agree. I’m grateful Bitcoin only wallets exist. I’m grateful there’s others besides Coinkite. but they were the best ones. #SlayYourHeroes
this sucks. it’s the hw wallets that got me to buy in the first place. I was NOT gonna store on a hard drive
when Luke Dash Jr got 200 bitcoin stolen that was INSANE cuz he’s such an expert. but he didn’t use hw wallets!
Multivendor multisig is the way to go but that’s incredibly difficult and complex instructions for someone new with no technical knowledge to follow.
Bitkeys are a good intermediary option but honestly everything has tradeoffs. Diversifying custody setups is probably best practice.
Good pod on cc hack: https://open.spotify.com/episode/2KGd4RGaOSO7f8hLGnkSD7
I’ll listen to this later!
yes it’s like trezor sells a bitcoin only Safe 5. a middle ground between being non-Bitcoin only, but still offering a bitcoin only option!!
Coinkite had so much support. this is so sad.
ledger rekt itself tho because the new firmware gives the company a backdoor to ur seed which is insane.
an ironic thing on “bitcoin only” firmware and wallets is that sometimes it means there are less eyes on it. hypothetically general crypto wallets like ledger and trezor can have more eyes on software updates
not NYKNYC...?
S is for "seed," I suppose??
my typos strike again!
*NSYNC Bye bye bye bye bye butcoin
Presumably this includes legitimate Coldcard owners moving their coins to new addresses to save them, as there is no way to distinguish?
I think it’s driven by where the funds are getting transferred to
Stupid, basic question: how do we/they know which tx are from coldcards...?
There a specific marker in some transactions of the thief?
I think the attacker is just grinding out low entropy deterministic seeds from the bad RNG but and then scanning to see if there are any funds there.
Potentially when someone spends to the mempool it might flag a UTXO as being a target to look at too. Idk all the technical specifics tho
Yes, that much I gather. How do we know which transactions are that? (Such that we can arrive at the number 1131 BTC or whatever and show them publicly?)
where funds were swept to. Number is a minimum floor estimate. Likely more
https://coldcard-watch.vercel.app/methodology.html
Aha, so basically attacker "revealed" himself by consolidating...?
yea, I think there’s a ton of individual attackers now tho too since anyone with compute can do it
Here is from the methodology section of the website.
If anything, I think they may be undercounting.
It would be interesting to see a sankey to if they get consolidated into one utxo. Or if they enter lots of coinjoins next.
https://twiiit.com/bradytc_/status/2083331338522820667