IDK about you, but I'm still stacking #bitcoin
unit
count@nostrplebs.com
npub1mdgx...j2aj
artist, ephemeral moment capturer, sojourner - bitcoin freedom fighter
from CoinKite X Account
To all Coinkite users and the entire Bitcoin community,
To all Coinkite users and the entire Bitcoin community,
I'm sorry and I'm devastated. Our team is heartbroken about yesterday's news.
As a team that has dedicated our lives to securing the Bitcoin held by millions of individuals, businesses, and families, this is our core responsibility, and we fell short.
If you know anyone who owns a Coldcard, please make sure they see this. Some affected users may not be watching social media right now, and every hour matters. We do not store customer information, and would appreciate all assistance in reaching affected users.
If you generated a seed using a Coldcard wallet, move your funds now, using our updated best practices, before reading further.
We take full accountability for the firmware bug and we offer our sincere apologies to those affected. We continue to work 24/7 to understand and fully scope the extent of the issue.
What we're doing today:
We've shipped a firmware hotfix that removes the software fallback path entirely. This protects new seeds going forward. It does not fix seeds that were already generated on vulnerable firmware. If your seed was generated before the fix, it needs to be individually migrated to a new seed. A firmware update alone cannot do that for you.
We will publish a full technical writeup of how the bug entered the codebase and why our own review process didn't catch it once we've verified every detail. We would rather be accurate than fast on the technical postmortem, even though we know people want answers now.
We will publish updates at as we learn more. We do not have full attribution or scope of the issue yet, and we won't speculate until our full technical evaluation is complete.
We are committed to working with affected users who want to pursue a police report, insurance claim, or their own investigation. We will provide a written incident summary specific to your loss and any transaction data we can share. We are cooperating fully with the on-chain investigators and any law enforcement agency that opens a case.
We know an apology doesn't return anyone's funds. We know we'll have to earn back our users' trust. That starts with being open and telling the truth about how this happened.
To every other developer: we believe this is a sober reality of the new AI paradigm. AI-assisted code review can now find latent bugs at a speed that is outpacing even the industry’s most seasoned experts. If your firmware is open-source or has ever been public, assume it's already being read by attackers and defenders alike.
We started Coinkite because we believed in Bitcoin and in people's right to hold their own keys. We remain committed to doing everything going forward in the best interest of the Bitcoin project, the industry, and our users.
nvk,
coinkite
COINKITE Blog
COINKITE Blog
Stay up to date with Coinkite — COLDCARD, Opendime, Tapsigner, Blockclock. Firmware releases, security research, and Bitcoin cold storage.
X is beyond garbage, they now have a daily post limit on free X accounts


Betrayal is a Motherfucker
People have their motives, and they're not always good
View quoted note →
I'm just gonna say it
It's not out of the realm of possibility that NVK secretly rugged the bitcoin out of users wallets
The code could have been purposely obfuscated
Get the bitcoin by any means necessary
Coldcard Mark 3, 4 and 5
A Mark is the targeted victim or intended victim of a fraud, swindle, or manipulation attempt.
And, just like that no one gives a flying fuck about bip-110
Good thing NVK designed the Coldcard with a Shoot Here Target on the Secure Element
NVK talked so much shit about other hardware manufacturers, and he also helped decide what dev/project got funding thru opensats
The Ledger hack doesn't seem so bad now does it
Fyi: Bitcoin is designed to be a push system, not a pull system
Same applies with Trust
View quoted note →
Remember when NVK was shitting on the Bitkey, and how insecure that multisig hardware device was?
I member
I'm not trusting the dice 🎲 manufacturers, the only way I know, I'll get real soild entropy is manufacturing the dice 🎲 myself
Coldcard the most secure Bitcoin Cold Storage Device
Secure Element
Micro SD Transfer
Running it complete off of a battery
Non of those security features mattered
Why!?!
Because the Random Number Generation was almost non existant
We were blasted with: if the device has shitscoins it's opening you up to hacks
Over and Over again
Bitcoin Only Firmware is the best and most secure 🤣😂
Whelp, that marketing narrative is dead 😂🤣
People are secretly cheering at NVK's misfortune
And, I don't blame them
The way NVK publicly treats people
Tell me I'm wrong?


When there's no where else to go, set the destination to Bitcoin
View quoted note →

