pull down to refresh

if you want to teach people a lesson, you take 1 utxo, not drain. And do a press release.

Instead, the pattern suggests malice (even though we should not assign malice first) combined with some incompetence. You could be right though.

anyhow, the FUD is def there now.

reply

yes, we're quick to fall back into familiar patterns of bullshit while for others their world is smoldering, we didn't address any root causes and we have no plan for the future.

reply

I read some posts that keep saying those using cold cards are doing everything right, yet the coins are still being drained. To be honest, trusting a commercial hardware wallet / depending on others isn't doing things right to begin with.

I feel many people are in panic mode now and not sure whether they should still self-custody their coins.

reply
To be honest, trusting a commercial hardware wallet / depending on others isn't doing things right to begin with.

Key word trust. I made this mistake myself. Because despite reviewing this exact software, I was assuming/trusting that there would be other, smarter, people also looking at it and finding different things. That didn't cover this case.

Bottom line, having a shitton of influencers recommend something and no one finding this and saying "hold up" is also a failure. It is a secondary failure but if anything, this episode is showing how screwed we are.

reply

It is pretty rough that none of us managed to spot this before it was exploited.

I like to think that if I had really serious amounts of Bitcoin to secure, I'd pay some auditor to examine all the pieces of my stack. The reality seems to be as you say that we were all content to trust that someone else was doing that checking. That's bad.

For myself, I am realizing I need to get much more serious about using the tools to check on the tools I use.

reply
For myself, I am realizing I need to get much more serious about using the tools to check on the tools I use.

It can be a dayjob so be careful what you wish for.

More important: what made some coldcard users secure despite using the vulnerable hardware?

reply

Adding other layers of security.

Yes, and perhaps time is better spent trying to remove single points of failure.

But it smarts a little when such a famous and "reputable" product had such a glaring problem...and none of us were able to say, wait a minute...

reply
Adding other layers of security.

I'd suggest: doing the dice rolls. That's truly what helped. Multisig only buys time.

228 sats \ 1 reply \ @Kruw 1 Aug
For myself, I am realizing I need to get much more serious about using the tools to check on the tools I use.

From my own experience contributing to Wasabi, there is a lot more low-hanging fruit than most would like to admit.

reply

Agreed! Often hard getting it merged (in general), but you can at least compile your own with your hotfix.

reply
228 sats \ 1 reply \ @Natalia 1 Aug

I usually avoid using whatever influencers recommended, especially with an affiliate link. BIG red flag.

reply

Good practice!

I generally am not even exposed to these except for what stackers link and I take the time for, but I think that there was a huge podcast/influencer driven inflow of new Bitcoiners since.. I'd guess covid?

Kinda sad if you got sequentially rekt through ftx, then one of the lenders and now coldcard. Every time you "did everything right" according to the most authoritative source you've got. If you can't review code, you get rekt easily. If you can, you must do it to at least make informed-ish decisions and even then, you still may not escape.

I wish I wasn't an anon and that making podcasts would make me happy, because there is so much to discuss.

reply

I agree. I think it's just uncomfortable to say the victims did something wrong, even though that's obviously true.

It's more like, they tried to do the right things but didn't check all of the many complicated boxes and ended up getting got.

reply

Hmm, even now, in their advisory, coinkite is explicitly calling the dice rolls optional. Literally the only thing that ended up giving durability to their users.

We're of the wrong mindset.

reply

It's a false dichotomy to think either coinkite or the user must be entirely responsible.

It's possible for both to have not done everything they should have. Listing the dice rolls as an option still gave users an opportunity to look into why they might want to do that and they either chose not to look into the option or decided it wasn't worthwhile.

reply

I didn't do everything I should have. I didn't spot the error and I didn't file a disclosure.

reply

I'm not blaming people for not doing the dice rolls. Most likely, I wouldn't have either. I'm certainly not blaming you for not catching the mistake, although I get why that might be weighing on you.

My point is pretty straightforward: it's not correct to say they did everything right. There were choices made during setup of their devices that both were the wrong choices and could be reasoned to be the wrong choices before hand.