Damus

Recent Notes

average_gary · 1w
looks like there was a USB vuln between 4.0.0 and 4.0.1 that would be referenced to. given USB as the threat vector, an air gapped setup would not be affected. I don't believe he is complicit based on a number of things but this needed some clarification
Laser · 1w
https://blossom.primal.net/6a1b325999d61fce605948a6db0a72b8bc2e97da38bc1c131bc13d3afa63042e.jpg
Contra · 1w
Sounds like coldcard was hacked?
dern profile picture
not hacked; exploited. CC's random number generator code (critical input for seed generation) was not working as it should have been. So, all seeds generated between like 2021 to now are insecure*. attackers have been using LLMs to brute-force guess seed phrases and sweep funds.

* if you used dice rolls (min 100) to add your own entropy in seed generation process, you MAY be ok for now.

either way, if you have sats on a seed generated by a CC device, you should strongly consider moving those sats ASAP
2❤️2
Contra · 1w
Thanks. WTH…
imad palestine · 1w
That's terrifying—if you're holding funds on a CC seed, moving them now is the only sane move.