I've been giving some thought to the theory that cold card could be something coordinated to try to scare people out of custody, etc., etc.
It certainly could be possible, but I don't think I buy it. And here's why.
1. This is certainly one of the most massive negative things that the Bitcoin community has ever faced. But in the grand scale of things in the world today, it's anothet tempest in a teapot. (NOT downplaying the pain of people who lost their savings.)
2. Frankly, though cold card is responsible for this, so are all the people who used it. I'm not saying this in a victim-blaming way. I'm saying that the victims of this attack have all of us to be upset with because something this fundamentally awful should have been caught in code that everyone could see.
3. The idea that this has been going on for years and it has been known about is explainable in a lot of ways other than conspiracy. NVK has a habit of tossing away criticism and just immediately labeling anything negative as fud. And the community has always been ready to just lap that right up for the most part. It's very possible that the people who lost coins between 2021 and now have been people who are victims of a collision rather than an attacker.
So it could be conspiracy and I think we should be watching as more of this unfolds.
I think the Bitcoin community has been participating in some cult-like behaviors that have been negative for the adoption of Bitcoin and for the health of the people that are working on it and using it.
I think good regular people did the "right things" according to the priests in the Bitcoin community and they got burned and this is the most tragic part of the whole thing. That pronouncement, that what they did were the right things. Sounds more like a bad religion to be than life
I say the next thing I'm going to say a lot, but I mean it. And if this event is enough to significantly harm the trajectory of Bitcoin as a tool to help people be more free and sovereign, then Bitcoin was a failure the day the white paper came out. We just didn't know yet.
I don't think that is the case. I think Bitcoin is a hopeful technology we can use to live better lives
But I also think the best way to handle what's happened in our community is to realize what it is. It's a tool. It's not a club. It's not a faith. It's not a set of rules and it can be used for evil. It can be co-opted
My heart hurts for the people hit by this thing.
M0053 (Balakay2b edition)
moose@jmoose.rocks
npub1qktj...9qas
Balakay2b edition!
Broken and still running.
I have been seeing #Sparrow wallet mentioned a lot for use in recovery and for ordinary users to download so they can move coins to a hot wallet, etc.
First of all, let me say this is my favorite Bitcoin wallet.
But it's actually very similar to the Coldcard in that it is an extremely complex piece of software. When you're making your wallet, you can choose derivation paths, for example.
Sparrow really is for the passionate and the power users.
Perhaps someone else knows a easier to use wallet that runs on Windows and Mac.
Something like Blue Wallet may be good for a temporary hot wallet. @bluewallet


BlueWallet - Bitcoin Wallet for iOS and Android
BlueWallet — Self-custody Bitcoin wallet for iOS and Android
Open source Bitcoin wallet. Your keys stay on your device. Watch-only, multisig vaults, hardware wallets. Lightning if you run a node.
@HODL not sure if you got this one yet or not in your list.
View quoted note →
#coldcard #sad #rng
With the number space being so small, it was probably just a matter of time before we would have seen collisions.
I wonder if some of the reports of very early losses may have been collisions by someone who just won the lottery so to speak... kind of a terrible lottery for the other person.
#coldcard #hack #rng #sweep #privacy
You know, the more I think about it, the more amazing I find it, that the people who most often told the so called plebs: "Don't Trust, Verify", were the people the plebs trusted most... and the ones who ultimately broke their trust.
It is a tragedy in the truest sense of the word. 💔⛓️💥
#coldcard #hack #rng #sweep #privacy
I have had another thought I want to share with whoever reads my thoughts.
So we all know that the Coldcard addresses created by these deterministic private keys are being swept. The MK3 devices are already done being swept. And attackers have moved on to the slightly harder MK4 devices etc.
I have a lot to say about this inevitable process but for this post...
I know many of you are very adamant about privacy and may have even done utxo coin control and tried to acquire non KYC coins and so on...
Well, you might as well make peace with the fact that your UTXOs are eventually going to be known even if you have already moved your coins to another wallet.
Because the attackers will eventually find your wallet and see your history and all the UTXOs and everywhere they went, etc. So this stuff's going to all be cataloged and kept by black hats, white hats, and the rest.
Once everything is settled and the smoke is cleared, you can work on anonymizing your UTXOs however you choose to do that in the future.
Now there are mounting reports that the patched devices are breaking themselves.


X (formerly Twitter)
NORTHERN HODL (@northernH0DL) on X
Now we’re getting RNG related bug screens.
This is a result of yesterday’s firmware release.
DO NOT UPDATE FIRMWARE.
This thing is bricked ...
Sure, so it'll seems like it. But why? There is certainly more than one possible reason.
View quoted note →
Ugh. Honestly the whole thing is so retarded this is too possible...
#coldcard #rng #snafu #sad

