This. For personal responsibility enthusiasts y’all really don’t like personal responsibility.
I’m so wrecked over the losses of those who made bad decisions toxic empathy virtue signaling.
Yes it sucks but they most definitely did not do everything right and if you recommended a cold card…so what. I heard it a million times and still made my own decisions because that’s what it means to be a sovereign individual independent thinker who does my own research and I expect that of others.
This is not cruelty.
View quoted note →
Login to reply
Replies (24)
Can't argue with that—personal responsibility cuts both ways, especially when the market punishes the same ego that made you go all-in.
(If you feel moved to help, any small zap is deeply appreciated 🙏⚡)
Well said sister. 👊
Everybody coming out AFTER the fact and telling everyone they made “bad decisions” while the entire industry was saying Coldcard was the best. And the “influencers” who built up a decade of trust were the ones saying this. Now even the most technically competent bitcoiners are moving bitcoin because of the CC fiasco.
Next thing we know they’ll be saying “should have checked the bitcoin code.”
Hate to break it to you but everyone (including you) is trusting someone.
For example, the fact bitcoin has worked for so long and hasn’t been hacked is a large reason why we know the code is good. Because almost no one can verify it.
Same with cold card.
Sorry but “don’t trust verify” only goes so far. 99.99% of Bitcoiners have to have at list a little bit of trust in someone.
View quoted note →
How many people on earth truly have the ability to verify something like this? It’s naive to think that every individual who wants to hold bitcoin in cold storage should have enough knowledge to have avoided this.
We’re talking about a minuscule group of individuals who have that level of knowledge or expertise.
Bitcoin is only trustless when auditing the chain. The chain itself is verifiable.
Most of us haven't personally audited the entire ecosystem and it's unreasonable to expect us to.
Anyone can create their own seed phrase and or add a 25th word fuck outta here.
Everyone who bought a Coldcard was absolutely and undeniably defrauded by the company that had one job - entropy - and failed.
Some people were absolutely financially devastated as a result of a thief who super imposed another terrible injustice upon them.
Others super imposed their own entropy and apparently were not absolutely financially devastated.
But everyone who purchased the card was defrauded by the manufacturer and anyone financially tied to it and advertising that the card fulfilled its one job.
One crime, that theft, was 100 yards wide and 10 miles deep.
The other, the company fraud, is 1000miles wide. For some people it cut a few feet. For others, those 10 miles.
But frankly, it’s lazy ethics to try to evolve this into a personal responsibility issue. If you bought a cold card apparently after 2021 the company and any of its de facto employees defrauded you.
Part of personal responsibility is holding others accountable for their bad actions - even if you don’t feel particularly impacted by those actions, and even if you thought the people who committed them were nice guys or hung out in your club or had cool mottos.
I’m not defending coinkite or NVK hold them responsible too.
I believe you
But the “re tweet” you promoted suggests the victim of theft did something wrong by
“Using some of the weakest available hygiene” - blah blah blah.
There are degrees of commitment to any approach to personal security. There are knowledge gaps. It’s hard for me to see degrees of commitment as if they are wrong. If you do 5/6 multisig and I do 100,000/100,001 are you “wrong” in my eyes?
I think there are community standards and subcommunity standards. And cypherpunks (I don’t really even know the term I admit) with extreme technical skills and high security preferences are impressive and to be applauded.
But I worry about an inability or unwillingness to see outside the sub community into the wider community.
Look, I am not a cypherpunk. I am not technical. I’m a total bystander. It looks to me like punching down. To me there are two crimes, one miles deep and yards wide. One miles wide and variably deep.
I’m willing to bet that even the most ardent hygienic 100,000/100,001 multisignaturer - if they have one single cold card in that arrangement, is changing it out. Because they were defrauded.
IMO The whole community will be better when both injustices are righted.
I get some will have little or no sympathy for the unhygienic, so be it.
But then maybe - just my suggestion - they can pivot from them over to addressing the widely promoted massive fraud advertised and inflicted on bitcoiners.
Nothing wrong with single sig or not having a passphrase. Many have lost Bitcoin because they added unnecessary complexity to their cold storage.
The trusting third parties to generate entropy part was the big mistake.
I'm still "upgrading" my storage because I'm not 100% confident I did everything perfect 5 years ago.
Would you complain if you got food poisoning in a restaurant, or would you be like “I got what I ordered”
The level of knowledge required to know that you should add a 25th word or create your own seed instead of generating with CC is higher than you realize.
Very few people were at that level.
The biggest mistake was made by NVK and those promoting CC not by individuals who thought they did everything right by using CC to generate seed phrases.
Yes. I do sympathize but we must also have the conversation.
Agreed. No hard feelings. In the end, valuable lessons were learned.
It always takes things like this to learn them. But now we have an army of bitcoiners who will teach the next generation to never trust a device to generate your seed phrase for you.

passphrase, in my opinion, should be text, it will include upper, lower and symbols. it should be in the range of about 30-50 characters, and bonus points if it rhymes because that helps you remember it. spaces included. the pgp nerds used the word "passphrase" for a reason. including spaces. using words and punctuation.
there is other approaches but it depends on your physical location. and there is a lot of myths about what best policy is for a given set of circumstances. if you are famous, you are in a bad situation. if your location leaks frequently, that is a very bad thing, part of the fame vulnerability. being unpopular is not such a bad thing :) shit if i get popular i go defcon 1
First time seeing this. I like it.
30-50 is overkill. Using just lowercase and numbers, 25 characters will give you over 128 bits of entropy
imo, best is *battery horse staple* type of passphrase, made of words that are NOT in the bip39 list in order to avoid confusion 

Yeah. Thos is what i was doing but this weekend, I decided to not do a remembered one.
I’ve moved to a passphrase thats just written down and separated from my seed.
Im taking steps to obfuscate “what type” of password it is.
I have reminders in my calendar to review and log in once a
Month.
It is good. It would be great to have at least 2 durable copies in different locations to avoid single point of failure.
I just set my paraphrase to correct horse battery staple since that specific pass phrase is so hard to guess. Thanks for the tip!
Its more information to record and maintain for 0 benefit.
If you use the EFF word list (which has 7776 words) you'd need 10 of them to have 128 bits of entropy.