If youโre using a signing device (hardware wallet) you already have two things: the signing device itself, and some other software wallet.
It is not a big lift to upgrade to 2-of-2 multisig where one is the device and the other is your software wallet.
But this simple set up protects you from any single vendor bug. #Bitcoin
jimbocoin ๐
npub1v9qy...9q3h
The SUPERCYCLE guy.
A hardware wallet has ONE JOB: to protect your seed material from leaks during use.
A lot of people were using their devices for more than that, to their detriment. #Bitcoin
#Bitcoin #memestr


Listen, if youโre leaving ColdCard due to this issue and switching to Bitkey, just know that you havenโt changed your risk posture towards this class of issue.
Youโre still trusting someone else with your seed generation. #Bitcoin
PSA: Iโm available for podcast appearances if anyone needs someone to explain of the problem, describe mitigations, or discuss entropy generation approaches. ๐ #Bitcoin


Today in #Bitcoin


In Bitcoin, ownership is what you KNOW. You either know the keys and can move coins, or you donโt.
So, how do you KNOW that nobody that you has your seed? The only way is to generate it yourself.
If you trust ANYONE ELSE to generate your seed material, then you DONโT KNOW that no one else has it.
Therefore, you MUST generate your OWN ENTROPY in order to KNOW that itโs safe. #Bitcoin
Your signing device has one job: to protect your seed material from leakage during use. The ColdCard has not failed in this.
People were trusting their ColdCards for an additional job: generating entropy. That was the mistake.
It does not help that wallet manufacturers encourage using the devices for entropy generation. #Bitcoin
View quoted note โ
For people freaking out, here are a two relatively quick mitigations that donโt require any new hardware:
1. Using your existing ColdCard and seed, you can set up a passphrase. This acts like an entirely separate wallet on the same device. You can then sweep the coins to the passphrase sub-wallet.
2. Using your existing ColdCard and seed, set up a 2-of-2 wallet using that device and a software seed using Sparrow or Blue Wallet. Your attacker would have to both exploit the ColdCard vulnerability AND hack your software wallet to move those coins.
Stay frosty out there. #Bitcoin
NOT YOUR KEYS, NOT YOUR COINS.
NOT YOUR ENTROPY, NOT YOUR KEYS.
#Bitcoin
View quoted note โ
#Bitcoin #memestr


If you roll the dice and put them in the machine to produce your seed, youโre STILL TRUSTING THE DEVICE.
How do you know that those dice rolls yield THAT seed?
Youโre out here thinking youโre paranoid using dice with a hardware wallet. Iโm telling you, you are NOT PARANOID ENOUGH. #Bitcoin
Worried about your #bitcoin seeds?
Shuffle up and deal your own. https://jimbojw.github.io/seed-picker-solitaire/seed-picker-solitaire.pdf


Where were you in 1994? #asknostr
โAlexa, renew my passport.โ
โThe faux-young boomers feel betrayed, forced back into the labor pool, but unable to cope with the implant-accelerated culture of the new millennium, their hard-earned experience rendered obsolete by deflationary time.โ โAccelerando by Charles Stross, p. 147 #quotestr

