#Coinkite CTO, pretending to be an external contributor, switches out Coldcard's strong entropy implementation for false/pseudo entropy, thus allowing future wallets to be remotely swept.
Plebs: "It's an honest mistake. Python is hard! These things happen."
Peter Gray had an extensive debugging setup for the #Coldcard development process. He even left the USB REPL enabled only days before the vulnerability was shipped, meaning he had been inside the runtime inspecting the state of variables within #Coldcard during their big entropy changes.
Nobody makes the massive entropy changes they did without stepping into an interactive debugger (or automated testing) to see if things are in tact or broken. And guess what? Peter did.
He left the interactive debugger enabled at the time that he shipped the entropy vulnerability, meaning: he must have been inspecting the entropy implementation, and saw that Yasmarang was "defaulted" to as a result of the innocuous "bug" that had been introduced.
#Bitcoin




Plebs: "It's an honest mistake. Python is hard! These things happen."
Peter Gray had an extensive debugging setup for the #Coldcard development process. He even left the USB REPL enabled only days before the vulnerability was shipped, meaning he had been inside the runtime inspecting the state of variables within #Coldcard during their big entropy changes.
Nobody makes the massive entropy changes they did without stepping into an interactive debugger (or automated testing) to see if things are in tact or broken. And guess what? Peter did.
He left the interactive debugger enabled at the time that he shipped the entropy vulnerability, meaning: he must have been inspecting the entropy implementation, and saw that Yasmarang was "defaulted" to as a result of the innocuous "bug" that had been introduced.
#Bitcoin




16โค๏ธ9๐2โฆ๏ธ1โ
1๐ฏ1๐1