The logic doesn’t hold. If reproducing the theft would “help attackers,” then we’re being asked to trust claims we can’t verify, which is the opposite of how Bitcoin security works. Engineers can disclose a vulnerability without publishing an exploit path, and they can demonstrate failure conditions without enabling theft. Right now we have assertions, not evidence. “Trust but don’t verify” isn’t a security model — it’s a social request.

Replies (1)

I fucking lost coins on a device that never touched the internet…this is a real fucking vulnerability Thank god I was able to save some sats that were still in the wallet (do not really understand why they only sweeped one of the utxos if they had the keys to sweep all?) and most of my stash is in a multi vendor multi sig but if you have any coins on any cold card device I would move it immediately out of an abundance of caution