Damus
BlessedBovine profile picture
BlessedBovine
@BlessedBovine
My heart is heavy for all those who lost any of their precious time and energy to the ColdCard entropy failure. It's devastating to see people talking about losing the entirety of their time and energy from the past X years - long before I found the Bitcoin space. So many pioneers that forged the path ahead and built amazing educational platforms and spaces. They provided me with all the tools necessary to enter into the Bitcoin space with such a strong conviction in the future of what Bitcoin could bring to society.

This is my first Bear Market. The falling USD price hasn't really bothered me. Thanks to the amazing Bitcoin Pioneers' tales of how bad things had been in the past Bear Markets combined with the lack of changes in the fundamentals of Bitcoin. I have stayed grounded in "∞/21M" and, to paraphrase @hodl, leverage won't magically make you an OG." This current ColdCard debacle is the first time I've been extremely uncomfortable to be a part of the Bitcoin community.

To preface the next part: I have zero, zip, zilch, prior experience in cryptography, coding, or other software skills.

I, like many others, spent a significant time trying to educate myself on different hardware wallets before we took our Sats off an exchange. To be honest though, much of the technical jargon was lost on me. One thing did stand out to me though, ColdCard seemed to have the best (anecdotal) hardware wallet. I particularly liked the Q for it's QR scanner and full QWER keyboard. Knowing that most Sats are lost due to user error, I felt the Q provided ample tools to help verify, send, and receive Bitcoin transactions while minimizing user error.

We're all told, "Don't trust. Verify." I did the best I felt I could, short of learning how to code myself to review CoinKite's code. I reviewed as much as I could on the reputation of the devices and feedback from people that had used them. For all intensive purposes, the Q felt like it would provide the best user experience for my wife or heirs if something happened to me, and give them the highest chance of success.

I did not expect that I'd see ColdCard have a failure so catastrophic as to screw up the single most important part of the security, generating a secure 128bit private key. When I saw the warning go out from some of my fellow Nostriches that there was a vulnerability in the MK3 series my heart started racing. Did it go beyond the MK3? Were my wife and I affected? I started reading as much information as I could. Keeping up with every detail as more and more UTXOs were drained and more info was breaking. Then I saw it, MK4, MK5, and Q were all sub 128bits of entropy. I had accidentally exposed my wife and I, and all our future generations, to the vulnerability. To say my heart dropped into my stomach would be an understatement. I didn't know how long it would be before the hostile attackers were finished with all the MK3 wallets and started on the MK4/5/Q. I did know that I needed to update things quickly but smoothly. A problem quickly arose as I realized our security setup was so difficult to access in the event of a true emergency, like this, that I may not be able to move a single sat in time. The amount of time from the initial incident to when I was first able to even look at the public addresses of our sats took far too long. I felt more and more sick the more time passed without knowing if we'd already been rugged. When I was finally able to check our UTXOs, there was not a Sat out of place. Not yet anyways. I knew we weren't out the woods yet. Even though I'd accessed our Xpubs for the Sats, it would still take quite some time before I could gain access to our keys. The only things keeping me calm was that we had used a passphrase (that I later learned was too weak), and my wife. As soon as I had access to our private keys, I wrote out a checklist. The checklist provided myself a step-by-step guide to make sure that I did things as cleanly and orderly as possible, to minimize potential missteps in a complete migration to new keys. I rolled 100 independent dice to generate our new wallet. It took me 32hrs from the time I learned of the vulnerability to the time I was actually capable of accessing my cold storage and generating the new seeds to sweep our sats to. The only reason I managed to do it in 32hrs was that my emergency contact was able to meet me half way. Without the emergency contact, our sats would've been exposed for at least another 12hrs.

I'm incredibly humbled and grateful that our sats are safe. I understand how incredibly fortunate we are to have been able to keep what small amount of Sats we've been able to stack, because it may not be a lot to most people, but it is a lot to us. I feel like I'd prepared for all the attack vectors, but I never expected that the entropy of a non-tampered with hww would be the one that got closest to compromising our sat stack. What a sobering and panick inducing experience.

As a pleb without a background in cryptography or technology, I really took the generation of seed phases for granted. Never again. Rolling my own entropy, and diversifying our hww from now on. Which will be difficult, because the Q was a big purchase, one I thought would be worth the investment. Oh how wrong I was.
43❤️2👍1💟1🤙1🦬1
The Bullish ₿itcoiner · 3w
So relieved to hear this. Live to fight another day. Stay blessed brother. 🙏
Burrows · 3w
Its sad that the people who are all losing in bitcoin are the people who made it valuable. And the banks and politicians are the winners.
Essencial · 3w
Goosebumps reading your text!! Thank you for writing this! Many of us probably were feeling exactly like this! Little sleep these days...Breathing through and stay awake and vigilant.
xlh155 · 3w
Just add a passphrase with at least 128 bits of entropy (use a password manager to generate). That way if the seed phrase generation is borked then you are still protected by the equivalent of a 12 word seed phrase.