This is very detailed postmortem of the coldcard vulnerability correcting the candidate space sizes (they are smaller than previously reported), estimating the probability of collisions among devices, and estimating the cost of sweeping the candidate spaces for each device class under different assumptions.
For Mk3s without passphrases or dice rolls, you can test the sweepability of nearly all candidates for $61 of rented RTX 4090 time ~9 days on a single RTX 4090. In comparison it takes years to do the same for Mk4 class devices even assuming more information is known.
The candidate space for the mk3 is hundreds of thousands of times, and a million times for mk4 class devices, smaller than Block and others published.
And, assuming a fleet of 30,000 mk3 devices and a few other things, they put they likelihood of collisions at 1 in 1,000.
There's lot of bits in here that weren't in the earlier reports for anyone that's a detail devil.
Nice data, but I hate to say it: the writing has that distinctive sloptastic vibe to it, and my aesthetic reaction to it is so bad that I can't bring myself to read the otherwise very interesting analysis. I was especially interested in the birthday paradox section, but paragraphs like:
got me gagging
Knowing the author, he's just a cool French dude who doesn't like writing in English much.
I keep trying to put my finger on what gives away the AI slop, but it's hard to wrap words around it.
There's something about phrases like "worth saying", "worth examining", and rapid-fire lists of numbers and technical terms that you feel like doesn't reflect how a real human processes information...
I experienced the same thing and was unable to read it verbatim. Instead, I
CMD+F'd to the stuff I was curious about, then decoded the slop into human as best I could. I'm confident this is the work of a cyborg, but compared to something human written, it's unreadable in its entirety.My aesthetic reaction is becoming problematic in the sense that I can hardly even use AI for personal use anymore. Like, if I ask it to diagnose a bug in my code, or provide feedback on a paper, if it talks the way these bots talk, I can't even stomach reading it. Opus 5 is the worst offender, IMO. I find Grok 4.5 and ChatGPT 5.6 to be a bit better on that front.
I feel the opposite 🤔
I read all the slop I order myself[1] and I spend hours upon hours every day reading slop. It's probably my #2 activity now, ugh. But whenever someone else's slop shows up on my screen, I cry a tear, and stop reading and most often don't even scan it. I could probably code me a bot to reformat it into something I can embed (which makes it totally unreadable) and prevent loss of information[2] that way.
I do specify output templates though, and when I first tried Opus 4.8 it ignored my instructions and I didn't rest until I got it to not ignore me, also I've largely moved away from Claude because of the endless cockups and regressions ↩
Speaking of information, back in the early 2000s, I designed and lead a team building a system for data quality management at row granularity for a multi-tenant data warehouse. I'm starting to think that I need to build a set of metrics on my big vector databases that culminate into a float that in turn I can multiply
scorewith, so that I get higher quality information out. I don't want to be gaslit by someone else's poor prompt infecting my knowledge base :-/ ↩That's an interesting observation worth examining.