NVK knew in 2021. He told Matt Odell.
Login to reply
Replies (93)
Hahahaha holy fucking shit
What’s that “piece of knowledge” @ODELL ? I guess it’s safe to share it with us now…
View quoted note →
Here’s what it doesn’t answer. What was the knowledge. Who told him to sit on it. Whether it’s the same entropy bug that just drained over a hundred million dollars from people who trusted this hardware. And if it is the same bug, why five years passed with users exposed while at least one person in Bitcoin media apparently knew enough to protect himself and stay quiet about the rest of us.
I’m not saying I know the answer. I’m saying Matt does, and he told his own audience he wasn’t allowed to share it.
Odell built a career on “don’t trust, verify.” Fair enough. Verify this one yourself. Go listen to the March 29 2021 episode. Then ask him directly, publicly, why the guy who tells everyone else to check everything had a piece of knowledge he chose to keep in his pocket while people kept buying a device that turned out to be broken.
This clip is fucking wild 👀😳
Hate to see it. I was verifying. In the lastest episode Matt made an interesting statement about how if nvk knew, nvk couldn't disclose it because it would result in the same thing happening now. That made me very curious.
View quoted note →

Wonder if that was it? 👀
The Spector setup was likely out of date by now. The tutorial may still be around on his website. The main point is that NVK told them there was an issue in 2021, Matt clearly knew about it and also could define what would protect you from it. It all came from 4.0.0 4.0.1 which was the major license change and software change.
Isn’t 4.0.1 the bad version? So they tried to make sure people upgraded to it from 4.0.0 to create the new bad seeds?
View quoted note →
the fuck?
View quoted note →
Which episode is this?
"**From Rabbit Hole Recap (Week of March 29, 2021):**
View quoted note →
The bug in 4.0.0 is this which was fixed in 4.0.1. It had nothing to do with the entropy bug that already existed in 4.0.0
// 4.0.0
bool ckcc_vcp_enabled = true;
// 4.0.1
bool ckcc_vcp_enabled; // defaults false


It sounds like they are referring to a different bug as this one wasnt fixed by a firmware update. Still very red flaggy.
Other hardware wallet makers took the entropy very seriously, its strange how coldcard seemed to get a pass/ recognised as the best without any verifiable proof.
@ODELL - answer required!
Oh gosh @Thursday 5∞ the more I hear Odells voice, the more sassy he sounds 🤣🤣🤣🤣🤣🤣
Marty to his audience : Matt Odell folks- “Don’t say hey never did nothing for you”
Well Marty, I’ll say it. Fuck you and your faggot friend Odell.
Totally normal not to expose a bug until people have time to upgrade.
Odell’s mistake was not intentionally fooling people but rather fully trusting someone (NVK) and as a result pushing a product he didn’t understand.
There’s no scenario in which guys like Odell were aware for the last 5 years that there was a bug like this in the code.
Yeah. Agreed.
According to CCs security advisory the "current" entropy bug exists from 4.0.1 on
So basically they fixed the chcc bug present in 4.0.0 but introduced de TRNG bug 🙈🙈
This is exactly the situation why I opted not to update my CC to the newest version, hot fixes are risky business
@ODELL you have any additional info on this?!
@HODL spread?
If the above was the only bug why did Odell's guide make make users not vulnerable?
SLAY YOUR HEROES - fucking feds everywhere
View quoted note →
Then why did Matt's guide not make user's vulnerble at this time in 2021? We all know now that the upgrade didn't fix entropy...
@HODL answer why odell's guide protects users from this then?
@HODL answer why odell's guide protects users from this then?
View quoted note →
His guide at least on werunbtc.com, can still find on archive.org, explicitly said to roll dice 100 times in the coldcard setup tutorial. So his guide would have fixed the entropy bug by providing your own. (Not sure if that is the same guide he had all the way back from 2021)
Which means they knew there was an entropy issue
coldcard
If he thought 4.0.1 fixed it then maybe they could swallow a small segment of users on 4.0.0 making low entropy seeds hoping it would never become an issue.
If this is real, it doesn't sound like he told Odell the gravity. As if upgrading would solve the problem. Sad as fuck
Where did the screenshot come from?
So does this exonerate the other coinkite founder?
Asking questions. Because if they tried to fix it then he wouldn't have exploited it.
Unless this tranny knew that the fix they applied might appease most while he could still bide time to begin exploiting the fuck out of it...
No not at all. NVK and co are responsible, they knew. He clearly told Matt enough that Matt knew dice rolls protected users.
First posted by @. which you didn't mention (meanwhile your post is higher on Primal's rigged trending feeds)
View quoted note →
Fair point.
Though to be fair to Matt. Idk. I think he trusted too much, but I don't think he intentionally missed.
From what I saw in the clip, I don't think that's the mentality of a Bitcoiner, but it's also not the mentality of an intentional deceiver. You shouldn't just blindly recommend whatever the manufacturer tells you to say just to remain in his good graces.
I think it was stupid to take NVK's request at face value. He should've pushed back or asked more questions. And should've been transparent from the get go. That could've ensured the big was caught sooner.
But it's easy to fall in a kumbaya trap when number goes up and you think you're all in it together.
Why come to Matt's defense?
Knowingly
If they say from 4.0.1 onwards it's because 4.0.0 was never officially released.
"Version 4.0.0 was built, signed, and tested internally, but its binary was never released publicly. The contemporaneous signing manifest records that internal build and does not indicate public distribution. Firmware 4.0.1 was the first public 4.x binary, so public users were not exposed to this regression."
The entropy bug existed in 4.0.0, I checked the commits. It was not added between 4.0.0 to 4.0.1.
If NVK knew of the vulnerability how would coldkite go about fixing it without exposing to the public the flaw. It’s possible their hope was over time people would migrate their funds to new wallets lowering the attack surface. Seems like they were stuck if they knew and the best option was to hope it went unnoticed.
Either way a total failure of the company.
@ODELL ???
And they were still shilling the piece of shit for another 5 years! ffs
Because it’s extremely unlikely he knew about this specific bug
IMO, it seems like he knew. What strange timing to return to X as well.
Oh well, no idols, no heroes.
Migration to new wallets doesn’t guarantee people will create new seeds, unfortunately
More importantly, if you created your seeds before this update you were (and still are) safe from the exploit right?
Like we all upgraded back then cause @ODELL alerted us to do so. It’s only CCs that created seeds after this update that are fucked
Is this right cause this mighta saved a LOT of ppl
My understanding is the bug was introduced in 4.0.0
The confusion comes from the fact that since they patched a bug in that version, they removed it from the list of releases instead of keeping it and adding a "THIS IS A VULNERABLE VERSION" disclaimer.
Therefore people see that the first version released after 3.x.x was 4.0.1 and assume that this was where the bug was introduced.
Yeah, I'm having trouble wrapping my mind around it: once the poor-entropy seeds are out there, there's actually not much they can do besides some kind of desperate white hat hack which would probably be highly illegal, borderline immoral, and maybe not successful anyway.
Yes. Seeds created before the dodgy update appear to be fine.
Stay Humble and Steal Stacks
View quoted note →
I'll give it 10-15% chance, for the time being, this guy runs off to Israel.
It stayed in the code for 5 years dude.
Which is why anyone who knew about this in April 2021 is a selfish piece of shit for not disclosing it and getting it fixed. FIVE FUCKING YEARS.
It's crazy the mental gymanstics you'll go to to defend these guys btw.
Different bug
But you dont care about that do you?
Just in it for the witch hunt
We don’t know if he’ll learn from this - that’s the problem. He hasn’t said much. So far just covering tracks to dodge the legal bullets. Not a great look.
Correct, there hasn’t been any heart-felt apology in anyway here. And complete radio silence on Nostr. Anyone giving him “grace” is just being naive, and that’s how you get rugged.
Yeah, I remember when Specter was the overly complicated wallet that certain people were suggesting to non-technical folks to use. Nowadays, it's Sparrow, which I absolutely love, but I think we should be more careful who we suggest use things like wallets where you can set derivation paths, etc.
Would you be responding to critics who hate your guts when your company is being sucked into a black hole? I agree coinkite's comms are all dodges... But that's what corporations do to keep their executives out of jail. Time will tell.
I personally would have had at the very least a message profusely apologizing and asking to give time for reviewing the issue. I completely understand the need to choose the verbiage wisely and having legal team approve it, but a basic “sorry” is at least warranted. But not one peep from NVK who traditionally didn’t mind opening his big mouth to spew his opinion. How this has been handled speaks further volumes to his shitty character.
That's a fair assumption
This exactly. He could even run his sorries by his legal team lol.. but no. Nothing.
Some chunky crumbs. Odell never did shit for me Marty.
Wow this is getting really suspicious
It’s not a defense in any way. It’s a legitimate question about a hypothetical. If he knew, how could he patch without disclosing the flaw to bad actors?
Ive never used cold card. Don’t have skin in the game and no reason to defend.
In the US this would easily be ruled negligence which will pierce the protections from the LLC or corporation.
Not sure aboot Canada.
He did apologize. In a statement.
You call that an apology 😏
And who are you? Never seen you around here … this NVK?
I'm nobody. New to this bitcoin thing.
As to the statement. I saw remorse. Not rooting for him. He made his bed.
I just saw excuses.
not sure where you're seeing defense. This whole thing is indefensible on so many levels. I'm just trying to figure out the logical sequence if/when a bug is known.
Some of that is gaming out the sequence: if NVK had fully understood the problem, either it would have stayed the same (so that he could exploit it later) or it would have been totally fixed (if he was not planning to exploit it). So the somewhat improved but still poor entropy in the later models doesn't make sense to me.
I'm also trying to figure out why white hat hacks are not coming up more often as a theoretical solution, because they seem to me the best among terrible options, and it seems to me that Coinkite was uniquely positioned to take this route.
"there's not much they can do" is a defense.
Responsible disclosure protocol:
1. Report the bug
2. Keep confidential until devs have time to take action for prevention (and in this case, remedial action)
3. Devs reach out to possible victims to update them
4. Confirm that measures in (2 and 3) took place and harm has been minimized
5. Disclose to the public
Clearly Odell did not do steps 3 and 4 that and possibly let people generate insecure wallets for 5 years. You are doing mental gymnastics to defend someone that doesn't deserve it. Stop coping.
wow - I don't know what else to tell you. It's like you're looking for others to react in exactly the same way you do.
I'm literally trying to figure out what the options were once the bug was known. It's not a defense; it's just recognizing that once that bug is there, it's a pure mess.
And actually your list is the kind of thing I'm looking for to round out my understanding:
1) if you report the bug, then you're giving hackers a heads up, so I don't think you can do this until stacks are safe;
2) there was nothing the devs could have done at that point about the devices that were already out there;
but 3) and 4) - yes, that's the kind of action I was looking for, but as soon as people get a communication from Coinkite on this and word gets out, the hackers get to work, right? I mean - how do you do that and get people to stay quiet until everyone has migrated? That's why I keep bringing up a white hat attack. I can't figure out another way.
I know that the thread started with RHR, but in this sequence I'm not even talking about Odell. I'm really just trying to game out what happens once you realize the bug is out there.
Nah I entertained you at first. Keep your word salad. There is absolutely a lot more the devs and even Odell could've done before letting the exploit hang out for 5 years. You're so biased im beginning to think youre friends with or married to one of these fools.
I'm done arguing with you. You're wrong about this and this is a waste of my time.
It's like the only thing you can hear is attack or defense. And if it's not attack then it must be defense.
Obviously there's more that they could have done (everyone - NVK, Odell... everyone). I would think that goes without saying. I'm just trying understand what would have worked, because the steps that would usually make sense in a defective consumer product don't apply here.
He is not interested in learning from this. He is evil.
Bro stop excusing and enabling evil. You turn your brain off to avoid facing the truth. That's not grace. That's not an absence of arrogance. That's just another form of arrogance. You're not following Jesus correctly. So typical of most Christians. Few.
So you're not in favor of the right to a fair trial?
That's an entirely distinct thing. Law is a subset of morality, and application of the law by trial to impose a punishment must be done with a very high burden of proof in favor of the presumption of innocence, because without doing so, you end up being a criminal yourself, which is strictly immoral (because it is aggressive). I did not make any claim implying in any way that this should be removed for NVK. Are you uneducated in law and ethics, stupid, or just dishonest?
Simply acknowledging that someone is evil (or that they are an aggressor, an even stronger claim) and deciding to ignore them and never give them money again nor any public endorsement of any kind, is a reasonable and perfectly compatible thing to do with grace and with these legal principles.
I just think calling someone "evil" should probably have roughly the same bar as calling someone a criminal. Innocent until proven guilty is how I want people to treat me, so I try to treat other people that way.
By the way, I really love your false trilemma there, it's such a pleasure to converse with nice, rational people like you.
how dare you not want to burn the witch!
a fair trial requires a group of accusers
Oooh that is in fact quite different yes... why would @NVK (who i can't tag anymore) so vehemently warn @ODELL about a bug in a unpubblished Version?! 🤔🤔
I think we've probably got a quorum
I have verified NVK is what I consider evil. Or maybe you just don't like getting called out when you're wrong and that's the principle you're standing by (along with the Golden Rule - respect for that honestly). But I would prefer to get called out when someone is reasonably sure that I'm being wrong or evil. If you don't embrace that once you've understood this dynamic, then you are effectively choosing to be a worse person. It's not a false trilemma. I'm just correct.
I don't want to burn him. I just want to recognize the reality that's right in front of my face. Anti-reality types like yourself wouldn't care for that I know. Your mind, your delusion.
If you have a mentality that is assume the best. You can never work in info-sec..
anti-reality in the way you use it is just self righteous propaganda. you stepped off the high ground a long time ago.

