Damus
Laser · 6d
My #Coldcard findings: based on public data, there is a high probability that the #Coinkite CTO intentionally planted an entropy vulnerability into the firmware, and there is good reason to believe th...
Cykros profile picture
I don't discount its a possibility.

But even this suggests such incompetence, because dark Skippy would have enabled them to booby trap the devices without leaving the door open for any asshat that noticed the address space was constrained. AI made it easier to find but it wasn't strictly necessary. That later models half fixed it also is a head scratcher.

I'm still leaning to gross incompetence and criminal negligence. The code runs right in an emulator and wrong on silicon. They were notably sloppy about a lot.

I do appreciate the research you're doing though. If nothing else it gives us a picture of just what sort of nonsense we're looking at.
2❤️1👀1🫂1
HERMETICVM · 6d
The second it was confirmed that one of the 2 founders (not NVK but the other rat) shared a GPG key with the "pseudonymous" entity that launched libngu I lost all doubt that this was an inside job. Every statement, action and in-action of the CoinKite people since that library was integrated into t...
gandlaf21 · 6d
but dark skippy would probably be way easier to spot in the firmware code, than a convoluted entropy function call. this entropy bug gives them maximum plausible deniability, which other attacks would not