Howdy there, partner! Welcome on into the Stacker Saloon.
Saddle on up to a stool and spill the beans about your day, fire away with them questions, or let loose and give us the lowdown on your wild and woolly life. We're all ears, so don't hold back!
We're open round the clock, so mosey on in whenever you please!
🏷️ Hey, it's Spending Sunday!🏷️ Hey, it's Spending Sunday!
What Have You Bought with Bitcoin this Week?
Bonus sats if you found a killer deal!
Share it at #1538215
My condolences to anyone impacted by the CC exploit.
On the bright side, this will reignite discussions on proper security practices and a review of trust models. This will be infinitely more fruitful than quantum, MSTR, BIP-110, etc.
Also, I think this could have been a lot worse. The attacker seems to have taken no trouble in hiding their tracks and has consolidated a large number of stolen funds into a handful of addresses within a very tight time window, making the attack obvious. A more subtle method would have been harder to trace and diagnose, leading to more stolen coins.
Onwards and upwards. Stay safe during this interim period where legacy human code is torn down and rebuilt by AI super intelligence. We will harden over time.
__@_'-'
Bitcoin seems bad in the same way that socialism seems good.
What it sells is the idea that everything will be alright and you don't have to worry if things go wrong.
That's a lie; the suffering is worse, but it feels good. Bitcoin mistreats you, but it's honest: it rewards those who do right and punishes those who do wrong...
What would you reccomend to Trezor and Ledger holders after this? Create stronger passphrases?
Because as fas as I see it, no device is secure over the time, just Entropy.
So the creating a new seed phrase has the same probability than your current one.
Just a very strong Passphrase would be the most secure way.
User generated entropy via dice rolls / coin flips seems like it should be the standard going forward, although care should be taken with this approach too. It's fairly trivial to verify that the HWW is generating the appropriate seed phrase from a given dice roll input.
Passphrases are nice for duress / dummy wallets, but they are only as good as the method chosen to generate them.
Bitpain enters the second stage of grief:
source
"the mullet of hardware wallets"
that's a new one
https://twiiit.com/AutismCapital/status/2083669141832315372
Mainstream people are talking Bout the coldcard vulnerability now.
source
https://twiiit.com/AutismCapital/status/2083669141832315372
I finished the last of our jumbo jug of taco bell sauce. My wife is going to be peeved....
I was listening to SNL, and I don't agree with you guys that this bug was nuanced and "anyone could have made this mistake"
Seed generation security is the #1 reason for a hardware wallet to even exist. If you can't figure out a proper test for the #1 objective of your product existing, you've done something wrong, end of story, no further nuance required.
Furthermore, it's not like this bug only manifests under certain hardware configurations or circumstances. It's literally just a flaw in the code logic. I don't think we can let them slide with a "could've happened to anyone".
my instant reaction was yours as well, but after listening to the guys for the past two days i changed my mind on it
Im fairly certain trezor has something built in to make sure something like this doesn't happen when generating seeds, some kind of entropy check. Either them or their CTO posted about it on twitter a few days ago but I didnt read it fully.
Could not have happened to anyone. Could have happened to me though.
I know you mention how you didn't catch it, but it wasn't your full time job to audit ColdCard's firmware. It should have been caught by any reasonably competent process of testing, IMO.
I'm not saying it is a reason to let them off the hook. But, I am saying that in my past this could have been me. I have since learned to protect my own work better. And when I test a PR I always check this.
What I had not learned until now is to also game out every macro in a manual source review of software I depend upon. I used to skim build system and deps. This is clearly a dumb tactic; big fat learning point. Embarrassing even.
As a user of said software that has actually used it to protect his cold stash for a couple of years, and then again after a reroll... I am extremely disillusioned with my own reviewing capabilities and concurrently emboldened to spend even more time on review. Because all that would have saved me if it were still in use would have been gaming dice I reluctantly rolled while I felt it was something tinfoil.
That's a humble take, and you're right, if I was solo coding it's definitely something that could have slipped me by (not that I would ever code anything security related in C let alone put it into production).
But this was a company that sold a product... they should have had a lot more redundancies in place and eyes looking at this all the time..
As someone that started a career coding (and later managing other that code) secure systems mostly in C, I must disagree with the first sentence, haha.
I fully agree with the second sentence.
Could have only happened to 'sovereign individuals' who are in reality gullible herd following sheep.
You probably think Trumps invasion of Iran on behalf of Israel and Big Oil is justified and that he's winning.
SNZ updateSNZ update
Sorry y'all, I’ve come down a little sickly today. I won’t imagine I’ll finish the zine today, but hopes are high to publish tomorrow
800 days ago I got back to chesscom
What is your obsession?
sudoku is mine
where do you play it?
IOS app with ads unfortunately. but I employ dark mode to make the experience better
btw 800 days is wild
I remember the time when I was able to pay once and have an app without ads, now they want monthly subscription
what about streak, yeah, it blows my mind how much time have passed and how many things have happened since
try again here, let's @chess d4
@chess d5
still doesn't work
Bitcoin Calendar: August 2026
It’s time to retire the trucker and put on the COWBOY!! 🤠
YEEEHAWWW!!
Let’s see if I get any “What’s SN” stops on the street and in public places
Yeehaw!
https://xcancel.com/TomerStrolight/status/2083525927309320202#m
MK4 now looks like are getting drained
anyone with any LLM can reproduce the attack. if you choose your keyspace wisely you can be forever famous in the villain hall of fame.
Or, you could sweep them and try to return lost funds to credible claimants.
I can initialize a coldcard with a seed I reverse engineered. There is no credible claimant.
It's possible to establish more points of evidence than that, though.
Yes, one. Source of funds and the attestation that you did per travel rule that this was your wallet, and in case of swept change, KYC purchases that have a 3rd party log.
Which can be faked and attacked. The risk of fucking that up and paying the wrong claimant is insanely high.
Let's say a wallet was funded by exactly one transaction from coinbase and no other transactions are associated with the address.
You don't think a highly credible claim could be established for that situation?
Sure. But what if I front-run your claim? I think you're underestimating the liability you get from preventively confiscating someone's coin and then asking for evidence in order to return it.
If you took my property and then put conditions on the return that prior to your actions were not imposed on me then that is a big big big problem, like shotgun KYC.
It's August 1st. This might be the craziest month ever for bitcoin related stuff?. Cold card mess continues, damus relay is permanently shut down, BIP 110 fun, ecash hard fork. What's next?
What I don't like about all this is that I cannot help but feel that we're collectively focusing on the wrong things. Instead of managing risk, we're quickly falling back to the abhorrent culture of blame game.
The question isn't who did what. The question is how to move on and make a better, safer future. The endless spinning is wearing me down mentally.
Luckily, 2 causes for mild optimism:
These do give hope. But I fear that more is needed. And more action.
I don't know, it seems all like noise. Bitcoin itself didn't change tho?
closer to xmas some great opportunities to build your stack up.
only acquire and use btc if you want to be part of the peaceful monetary revolution building an alternative to zionist engineered fiat debt slavery.
https://m.stacker.news/150508
Maybe off-topic, but I'm curious how this person could make sure he or she won't get caught when try to use the stolen coins in the future, since it's a large amount and all eyes are on it? Knowing everything is linked and transparent...
Increased chance of getting caught because they used a paid account at a commercial explorer. Thanks to @Scoresby bridging the elmosphere: #1537340
Part of me feels like this person either wants to teach people a lesson not to trust any commercial hardware wallets, or this is a setup to create FUD to scare people away from self-custody their Bitcoin.
Same feeling
if you want to teach people a lesson, you take 1 utxo, not drain. And do a press release.
Instead, the pattern suggests malice (even though we should not assign malice first) combined with some incompetence. You could be right though.
anyhow, the FUD is def there now.
yes, we're quick to fall back into familiar patterns of bullshit while for others their world is smoldering, we didn't address any root causes and we have no plan for the future.
I read some posts that keep saying those using cold cards are doing everything right, yet the coins are still being drained. To be honest, trusting a commercial hardware wallet / depending on others isn't doing things right to begin with.
I feel many people are in panic mode now and not sure whether they should still self-custody their coins.
I agree. I think it's just uncomfortable to say the victims did something wrong, even though that's obviously true.
It's more like, they tried to do the right things but didn't check all of the many complicated boxes and ended up getting got.
Key word
trust. I made this mistake myself. Because despite reviewing this exact software, I was assuming/trusting that there would be other, smarter, people also looking at it and finding different things. That didn't cover this case.Bottom line, having a shitton of influencers recommend something and no one finding this and saying "hold up" is also a failure. It is a secondary failure but if anything, this episode is showing how screwed we are.
I'm having trouble sending zaps here again. 🤔
Try connecting different wallet
I did, working now:) anyone having issue with their rizful wallet?
As early adopters we need to accept occasional outages will occur.
We are literally building a new monetary system!
Coinos is 99% reliable and very low fees.
I find it the best LN wallet for SNs.
By using LN frequently we help the network grow stronger.
248th Cowboy Plunda Drop in the @saloon
Howdy cowboy! Come on in!
Use that fancy LN wallet you got and login into plunda.co and git you some loot! Get a shot at some coins🪙 Box of loot🎁 or an arcade token!
Use the below voucher code to collect!
IMAPPN2QGYYXTo redeem Click here
Got questions? Reach out to the sheriff @plunda
also, nearly 250 drops. crazy!!
165 days to till I reach a full year of dropping loot in the SN saloon! First I did ecash for a year now doing plunda. I think we got some stackers interested!!
One feature to think about is allowing folks to give away coins. I still don’t know to list coins or give them away for free.
After the 365 days are done it would be cool to have the ability to drop a coin in the saloon to give away for free.
yeah i agree, giftng coins is already half built along with the loot upgrade, it's super all encompassing that update just.such a hig feature. once i finally pick it up again I'll break it down into bite sized chucks and relase it bit by bit - otherwise it'll never get finished.
and minor correction, only 117 drops to a full year!
Geyser is having issues with my loot buy!!
Guess my buy is too big for the swap?
Maybe I can buy directly in Plunda?
yeah should be good to deposit into plunda and swap your gaming chips for other loot. but mystery box stock is still set to 0, i need to increase the stock. i can do this tomorrow!
And some elite boxes please!
added a lil stock just now fyi ✌️✌️😎😎😎
haha I can’t add
have been doing a bunch of DIY at plunda HQ but I'll be listing some more coins soon, hitting that 3000 coins milestone, and getting a progress video out to go over the roadmap for the rest of the year!
Coin of the Day:
that's a nice one!
safe way?
How to Securely Create a Bitcoin Seed Phrase in 9 Simple Steps
#1537532
Someone tried to prompt inject the COLDCARD attacker agents
Unfortunately for the creator,
listunspentdoesn't showOP_RETURNutxo because those aren't... spendable.Can you imagine if someone releases something in a few years, and that kind of prompt actually works? Hahaha, that would be epic!
FWIW, I had a situation where I was bot-reviewing a library where someone uploaded
.claude/skillsfiles inside a diff I pulled and my review results got influenced by that... a little over 5 months ago. I recently ran into this again but now there was a neat message along the lines of "ignoring these files because they're in review scope, not origin repo".I still had issues with Qwen where instructions and source code got mixed up though, also in the latest version I tested. So for some LLMs this may still work.
It's happened to me with some simple things I've done here for my daily work; when you start doing vibe coding, with a connection or other tools, a lot of residual files are left behind, and if you don't really have a background in programming, that can affect your code, and it can be very dangerous.
I'm renting an awesome car at an awesome dirt cheap price, the Peugeot 208 GT. It's only been a week and I already got hit lol, leaving a not-so-little dent with scratches 💀
Oh no! If you are renting, do you still have to carry insurance, or does the rental company cover it?
I felt sorry for the guy that hit me because it was genuinely a mistake, he was trying to reverse from its parking spot but didn’t see me coming from the other street. Also his car was already in a pretty bad shape.
The thing with Hertz is that you pay the damage even if they recoup everything via insurance.
So I didn’t give Hertz infos about him or his car, just a detailed story about what happened. It didn’t make sense to make him pay in addition to what I have to pay myself anyway.
edit: now, if it was my car it would've been a completely different story lol
LND BitcoinLND Bitcoin
LND is the way. Rep the implementation that runs the Lightning Network.
Get yours at https://swag.btc.pub/product/lnd-bitcoin/
The Making of the War on Iran. . . Over 70 years of US Imperialism behind the current war.
https://m.stacker.news/150516
Thank you to all the crowd following wannabe sovereign individual clowns who used Coldcard.
You have created a great buying opportunity for me. Thank you.
I told you many times - learn to build your own cold storage.
Its fucking easy.
But you ignored.
You listened to the rentseeking parasites who touted Coldcard.
Parasites and traitors like NSA mole @DarthCoin
Maybe now you will make the effort to learn how to build your own cold storage.
Or maybe not.
Up to you.
https://electrum.readthedocs.io/en/latest/coldstorage.html
https://m.stacker.news/150492