Damus
Engineer · 2w
An attacker with physical access to an unlocked Coldcard doesn't need any additional exploit to extract the seed. He can just use the Coldcard at that point. The vulnerability being discussed may ha...
Laser profile picture
For Odell to have been able to "steal all" affected funds using the REPL exploit, he would have had to compromise each and every machine with malware that leveraged the REPL.

This is an extremely high bar compared to simply sweeping wallets that were generated with low entropy due to the CTO's exploit. This is what would allow all affected customer funds to be indiscriminately stolen.

Considering this discussion took place only days after that entropy exploit went out, and the REPL flag was patched before the actual release (meaning it didn't even make any sense to have Odell deliver some big PSA)... it is far more likely NVK was referring to the entropy issue.
🎯1