Damus

Recent Notes

mIX · 2w
Also from CoinKite's technical backgrounder blog post: https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware
sats>bits · 2w
Mk4 users are still affected. But it’s harder to crack then mk3, yet there have been a few reports of Mk4 users have their funds swept. If you have a passphrase you’re mostly safe. If you use mul...
mIX profile picture
From what I understand from past research is that the passkey entropy is less safe than adding entropy with 100 dice rolls. But it likely depends on the complexity of the passphrase. If you used a very hard passphrase then they would have to guess the hard passphrase as well (like cracking a password). So it should keep you secure. Please pile on if you have more/better info.

If the hacker knows the code/pattern/method used to create the entropy, it's easier to guess.

This stuff can happen with password managers as well. The plus side is that if you protect yourself up front by learning, then it gives you more time to move everything and change all your passwords.

We semi-recently learned this from LastPass's whole vault debacle. A third party got hacked (usually the case) and people's LastPass vaults are likely still being worked on by hackers to try and crack them. Because the information inside of the vault is a snapshot of all the data at the time of capture, you can't do anything except change it all. Hope everyone changed ALL their passwords from that hack, and stopped using any information that was captured (seed phrases, pass codes, 2FA backup keys) not just moved to a new password manager.
💜1
IntuitiveGuy☯️ · 2w
We went from: "Take your sats out from exchanges!" To.. "Take your sats out from some Hardware Wallets!" Is this the last "capitulation" of this cycle or we'll see more drama this year? What ha...
mIX profile picture
Learn how this stuff works. The bug has been fixed, the wallet will be fine again. Random number generation always has risk. It's possible these issues exist in other wallets, even exchange wallets. At least ColdCard lets you generate entropy above their code guided generation, a lot of wallets don't.

ColdCard suggests that users roll dice in the manual. @BTC Sessions encouraged it and explained why it's important.
2❤️1
IntuitiveGuy☯️ · 2w
Coinkite is dead. Save this note.
Jay · 1w
I believe that Coinkite is not going to patch the mk3, but only later models. So no, it's not been patched. And patches take a long time to propagate when they have to be installed manually with a nontrivial amount of effort. There's no recovering from this when the majority of coldcard wallets in ...