Damus
jimbocoin 🃏 · 1d
If you used your ColdCard to generate a seed from March 2021 onwards, it was done without sufficient entropy. This means an attacker may be able to brute force guess your seed and move your coin. It has already happened. It’s an ongoing, live exploit. Only single-sig wallets are known to have be...
Bohemia · 1d
Mk3 v4+ wasn't using enough (any?) randomness. 600btc stolen in a hack of a buncha insecure wallets. Mk4, 5 and Q also aren't using enough randomness but safer than mk3. Still recommended to update signer with what the fix they pushed today and reseed, roll dice for randomness. They didn't fix mk3 -...
The Beave · 1d
TL:DR NVK and co. borked up the code for their cold cards. It didn't use the hardware random number generator properly, leading to seed phrases that are not very secure. The Mk3 is dead in the water. The mk4/5 are suboptimal but need to be updated to work correctly. No update is forthcoming for th...
paulo · 1d
nostr:npub1rp8y3xvzx72zrc350v4f0alvsaclmdhl70jx4ym7rregjstn9mssxhurwe:nevent1qqsxt6lahxeq8h69ne78w6ls394ez5pqycguwrsp89tacwteh7878cczypftfgrkhjammsap4marwdvpdnm5nya3hrdjq2cpezputzl8ltvt6qcyqqqqqqgpp4mhxue69uhkummn9ekx7mqqx54kv