Buy a HWW with lightning, use a fresh email and fake name.
3 days later: FedEx has your parcel and needs you to pay custom duties with a credit card.
FedEx and DHL probably have one of the most comprehensive Bitcoiner databases.
Gunson
gunson@primal.net
npub1pn9x...2xn0
Low status fiat heretic. Often wrong. 2 + 2 = 4
Think clearly, speak freely.
Me: Hmmm I wonder if the Coinbase self custody wallet could be a reasonable suggestion to a noob who wants the comfort of a big brand.
*Checks wallet dot Coinbase dot com*
Wallet: Fresh drop! Lucky Cat Zombie NFT!
๐ฌ
I often try to think about business ideas, and then struggle to land on anything that others aren't already doing.
But then I watch a TV show on Channel 4 and there are ads for 7 different online gambling apps.
Uniqueness is clearly not necessary for being an entrepreneur!
Twelve unread articles and newsletters in my browser, but keep checking my email for new ones ๐
Many don't know that
E[(Y โ fฬ(X))ยฒ] = Var(ฮต)
and it shows.
(The difference between your prediction and the true data generating function in real life is some irreducible entropy you can never know, no matter how good your model or AI is)
I heard there's a Saylor podcast with the DOAC guy (literally such a popular podcast that my mom sometimes recommends it to me).
Listening to Saylor makes my ears bleed - it's like Iago from Aladdin if it was a high temperature AI continuously self-prompting about digital energy.
But for some reason I feel like I need to listen in order to check how bad it was, and to pre-empt normie questions about it.
Chaios monkey
Sometimes I imagine how easy and comforting life would be if I just answered the Palantir recruiter on LinkedIn, put all my savings into an index fund, and started caring about sportsball. But then I realise how much I'd hate myself, and make myself buy more Bitcoin instead.
Current (forever?) human advantage vs. AI:
- We want things (self-prompted)
- We can see the big picture (huge context window)
- Can spot mistakes (robust world model)
- Can be hurt by failure (nuanced reward framework)
I'm completely enthralled, but absolutely exhausted by AI. On net it's added way more stress to keep up with it personally and professionally vs. the nice conveniences (quicker searches mainly).
"It's all AI's fault"
"Our AI's didnt find any vulnerabilities"
Is the Coldcard event even a hack? Is it criminal? They didn't break into anything or trick anyone. They just found a number. Obviously shit to deprive people of their money, but if they didn't someone else would have.
Not endorsing it at all, but I'm cautious that even if the people could be identified there could be a case against them.
Seems we only think we know the total value of CC funds stolen because of a few very large (in terms of number of inputs) transactions?
There's no reason the exploiter wouldn't also be doing some 1 to 1 utxo transactions as a way to ensure it's more difficult to link their stolen funds. So probably we are massively underestimating?
There is always vendor competence risk for any HWW, so I wonder if the lesson is actually "always bring your own entropy" and not "extra super duper don't trust a vendor with an obnoxious CEO".
So, just from this point of principle I'd argue Coinkite deserve credit for enabling dice roll input which many used specifically to protect against device entropy risk.
While they haven't had any issues (well done!) maybe the real lesson is to be pushing other providers to ensure they're mitigating the RNG risk of their own devices - according to Opus 5 these vendors don't have an in-built way to add your own entropy:
- โ Foundation Passport
- โ Bitbox02
- โ Trezor
- โ Ledger
The only other major HWW that has a dice roll input path seems to be โ
SeedSigner.
"This is now the slowest air travel will ever be!"


Tl;dr: I think the Coldcard exploiter will be caught, but I don't think victims will be reimbursed.
---------------------------------------
Apparently you need minimum 64 GPUs (properly connected) to run Kimi K3. If the coldcard exploiter used this model they would have had to have a very sophisticated institutional setup (maybe there are black hats out there that have managed to construct this?), otherwise would have had to use a service. This means it's likely that they could be found if authorities worked with model servers ... although most likely it's China based?
Sounds like USA frontier models wouldn't have allowed a user to discover the exploit, so probably wouldn't find them by getting a warrant with those labs.
But I also read that one of the block explorers confirmed they have a paid user account that was doing a bunch of lookups that matched the exploiter behaviour and they intend to work with authorities?
I'm thinking it's probably decent odds that they're caught. Maybe they weren't even a full time criminal - possibly someone who had the idea to try it but hasn't taken a lot of other privacy precautions.
Much lower odds of people getting their funds back. If anyone has the ability to recreate the exploit then they could pretend to claim possession of the private keys. Not sure how you'd verify :/
This is definitely specifically a fuckup by Coinkite, but worth pointing out that a RNG being ineffective or compromised was a well known risk - dice rolls, passphrases, multisig were all mitigations.
Even though I use a coldcard, I've never recommended it to a normie who wasn't going to set it up properly (verify firmware, use dice, air gap etc.). I'd sooner recommend Muun or Blue Wallet, and these days I'd say Bitkey. Maybe that's one of the lessons - influencers and Coinkite themselves should have more explicitly steered users away from the quick but risky setup.
Probably too soon to say, but this is good for Bitcoin. Few.
Why would you design a seed gen system to fallback to a low entropy RNG instead of rather giving an error?