Damus
Laser · 1w
How does people not connecting their unlocked Coldcard to a computer prevent an attacker who obtains their unlocked Coldcard from simply plugging it into his computer to leverage the REPL to extract s...
Engineer profile picture
An attacker with physical access to an unlocked Coldcard doesn't need any additional exploit to extract the seed. He can just use the Coldcard at that point.

The vulnerability being discussed may have allowed a *remote* attacker to extract the seed via the USB connection.
1❤️2
Laser · 1w
For Odell to have been able to "steal all" affected funds using the REPL exploit, he would have had to compromise each and every machine with malware that leveraged the REPL. This is an extremely high bar compared to simply sweeping wallets that were generated with low entropy due to the CTO's expl...