Alex Waltz's avatar
Alex Waltz
npub1pu5p...pn0a
Bitcoin Researcher & Filmmaker. | My latest discoveries: https://1stbitcoinminer.com/
Alex Waltz's avatar
raw_avocado 18 hours ago
If you ever recommended a ColdCard and don't know how a HWW works, how about you shut the fuck up and don't make recommendation for some time. All these dumb takes about always multi-sig always dice rolls, always passphrases. STUF up you are a moron that lost people money.
Alex Waltz's avatar
raw_avocado 18 hours ago
nvk is currently deleting tweets about the block clock "knock off" This is upestting me so, I mean so fucking much.
Alex Waltz's avatar
raw_avocado 19 hours ago
There is not 1 single compelling evidence that this was a backdoor. CoinKite fucked in a major way, and there are MANY red flags, but all are explained by sloppy practices and incompetence. People who were not sucking off nvk are not surprise by the low standards. I get that people are angry and want an explanation, and the backdoor explanation will make you feel better as coinkite conspired against you, but this is an emotional way to think. The reality is you listened and trusted people who are clueless and don't have even a basic understanding of how Bitcoin works. All the trust was strictly based on social dynamics and 0 verification. It is easier to claim backdoor than to admit you are a bad judge of character, as that would mean you COULD have somehow avoided this somehow. Backdoor makes it feel unavoidable, which sorry to say it was not. 1) there is no way to make a backdoor like this an get away with it. this adds permanent damage, and when it gets out you are done, reputation burned for life. 2) don't say they did this for money because the cost vs. benefit makes no sense, too much risk for not that much reward. business was very successful, they had too much to lose. 3) if you do this for money when bug gets out others will also attack it so you are competing with other hackers 4) look at the fucking code, it a typical mistake that happens in this type of things. the lack of review and using social status to push away scrutiny from project is why it was not caught You did absolutely NOTHING wrong in using single sig and not rolling dice. The understanding between coinkite and user is that they provide secure key generation, which is industry standard and works if you have the right internal practices and correct way of doing business.
Oh my, I even asked nvk how they tested the entropy on 2021 image
One of the most epic moments in Bitcoin's history. (btw, recreated this in photoshop, since nvk deleted the tweet) image
SeedSigner image community after the ColdCard vulnerability was confirmed.
Alex Waltz's avatar
raw_avocado 2 days ago
Dear podcasters & influencers, Don't feel bad for not looking at the firmware, it's absurd to expect that from non-hardcore technical people, when even the hardcore ones did not look. Don't feel bad for recommending the ColdCard to people, you were told by multiple people this is a solid product, you operated under the assumption that "smart" people are honest and did their due diligence. Don't feel bad because you got paid to shill ColdCard, that is an honest business deal, nothing wrong with sponsorships. What you should absolutely feel bad and guilty about is whenever you saw nvk doing shitty things and you turned your head around, because you thought he will stop sponsoring you, it may affect your chance of getting a grant, or the wider group will think you are not one of the cool kids for talking back at nvk. Or whenever someone brought a criticism to nvk and you joined in discrediting that person or making stupid comments to signal your alliance to nvk, instead of at least saying hey maybe he has a point. If you did this, you were a coward and you have directly contributed to people losing money. This is NOT a RNG, self-custody or AI failure. This was a lack of scrutiny on very IMPORTANT piece of software that does VERY sensitive operations. Every time anyone tried to poke at ColdCard or even just ask questions nvk would always dismiss them, call it FUD and attack their character. Nvm the absolute abysmal attitude he had against competitor, who now still acted like gentlemen despite this generational dunking opportunity. Everything someone did to push scrutiny away from this project has directly contributed to this disaster. Bitcoin transactions are irreversible, and you can't change the past, so no point in beating yourself over it, at the end of the day there is not 1 single person that did this, it was pretty much everyone. The one thing you can do that will have a positive impact forward, is to tell the truth and when you see someone not doing that, make sure to point it out. If you read this and decide to go after people who promoted CC you are a dickless loser, and are only going to make this very mad crisis even worse. We can't start yelling at each other in a few weeks, when we won't have anything to talk about anyway.
Alex Waltz's avatar
raw_avocado 5 days ago
Guys this is not a CC vulnerability, it's a boating accident recovery feature.
Alex Waltz's avatar
raw_avocado 5 days ago
The search range for a CC(Mk4/Q/Mk5) seed is ~2^32. This is the first difficulty Bitcoin started with. So finding 1 CC seed is as hard as finding a Bitcoin Block in 2009. (practically times a few other variables)
Alex Waltz's avatar
raw_avocado 1 week ago
Looking for someone to record a voiceover for a Bitcoin commercial. Gig pays.
Alex Waltz's avatar
raw_avocado 1 week ago
All the problems we ever had in Bitcoin, come from the fact that someone was not told they are stupid early enough.
Alex Waltz's avatar
raw_avocado 0 months ago
That time Gregory Maxwell sent 21M bitcoins to himself.
Alex Waltz's avatar
raw_avocado 1 month ago
Because of LLMs the reproducibility of software should have gotten better. 1) they can help you make your software reproducible 2) they can verify even convoluted builds, by setting up environments etc Did it?
Alex Waltz's avatar
raw_avocado 1 month ago
There seem to be some new private emails from Satoshi with Nicholas Bohm. Why this article does not link the sources? Very bad practice, not making it trustworthy? hat is the sources of these emails that make us trust they are the real ones?
Alex Waltz's avatar
raw_avocado 1 month ago
1. say what you mean 2. mean what you say 3. work hard