Damus

Recent Notes

su-do profile picture
The fact that we do _not_ need an hardware wallet, was the lesson learned from the
@COLDCARD
shitshow.
Today is
@Trezor
, tomorrow it will be someone else.

You do not need an hardware wallet if you are just hodling.
su-do profile picture
I'm sure many of you have seen these two posts side by side in your timelines.
Well, look at them again and cry while you reflect on the thousands of man hours wasted by these larping drama queen #bip110 assholes.
This attack on bitcoin has been no joke.
Learn from it.
I have.

su-do profile picture
Those ~70 bits make a real difference.
They push bruteforcing from “trivial” (MK3) into “painful but still theoretically possible.”
The entropy remains weak, just not catastrophic.
Has anyone actually cracked an MK4 using a seed that was generated on the device itself (not imported)?
su-do profile picture
After a full dive into Mk4 today:
Mk4 keys are not enumerable like Mk3 keys at all. Thanks to the reseed, it’s basically impossible to bruteforce them even, if they have weak entropy.
When correctly set up, the private keys are so secure that they remain effectively uncrackable,
su-do profile picture
About the Mk3 draining, attackers can choose different "cones" to look into for wallets to hack.

The weak Yasmarang RNG value is determined by a small state (pad + chip/mixer skip history).

A "cone" is just a hypothesis about that history, e.g: first boot vs later login vs weird PIN session.
Each cone is a slice of skip/space.
Wrong cone → almost no hits.
Right cone → mnemonics become enumerable.

That’s why wallets can still sit unexplored in other cones.

The attack can go on for years and still find utxos
su-do profile picture
I remember Jimmy Song writing, on the first day of Ordinals: “The first one that forks loses, and they (the spammers) will surely fork.”

What I’m witnessing three years later feels like a lysergic experience.

People I once thought were smart now look like completely unhinged madmen.
su-do profile picture
After carefully analysing and testing the
@COLDCARD
rng bug, I am quite sure the attacker(s) knew about the bug already and spent weeks if not months to enumerate some vulnerable wallets. The whole enumeration did not take 3 days (the delta between Kimi K3 release and the attack)
1
BuyTheDipperPines · 3d
But if the wallets only had an entropy of 30 to 40 bits, which you can easily enumerate in hours on a regular PC, i wonder why it took 3 days to hit all unprotected wallets (e.g. my wallet without passphrase, where I left some dust behind, got swept only on Monday morning, 3 days after the initial a...
su-do profile picture
Instead of buying dice on Amazon, go to your local boardgames store.
These guys will have amazing choice, dice that FEEL (and look) great, and they don't need to know where you live.
Support your local game store.
2
teemupleb · 5d
Yes. Support local entrepreneurs instead of public companies. Plus there might be some cute cashier and you can FEEL those dice together before you make your purchase decision.
paula halloway · 5d
Craig has been an incredible crypto mentor, teaching me discipline, strategy, and smarter decision-making. With his guidance, I grew my $19,500 investment to $134,000 in just two and a half weeks. I’m grateful for the knowledge and support he provided throughout the journey. Anyone considering lea...
su-do profile picture
mistakes by 110ers: arguing nodes control protocol changes and miners will capitulate. subtly wrong. the economic users control the protocol, via the market. they transmit their views by transacting with their economic nodes. 1000s of nodes with no economic use have no influence.
1
Baerson · 6d
Then why did core spin up thousands at the last minute?