NVK knew in 2021. He told Matt Odell.
Login to reply
Replies (48)
This clip is fucking wild 👀😳

Wonder if that was it? 👀
The Spector setup was likely out of date by now. The tutorial may still be around on his website. The main point is that NVK told them there was an issue in 2021, Matt clearly knew about it and also could define what would protect you from it. It all came from 4.0.0 4.0.1 which was the major license change and software change.
The bug in 4.0.0 is this which was fixed in 4.0.1. It had nothing to do with the entropy bug that already existed in 4.0.0
// 4.0.0
bool ckcc_vcp_enabled = true;
// 4.0.1
bool ckcc_vcp_enabled; // defaults false


Yeah. Agreed.
If the above was the only bug why did Odell's guide make make users not vulnerable?
@HODL answer why odell's guide protects users from this then?
@HODL answer why odell's guide protects users from this then?
View quoted note →
His guide at least on werunbtc.com, can still find on archive.org, explicitly said to roll dice 100 times in the coldcard setup tutorial. So his guide would have fixed the entropy bug by providing your own. (Not sure if that is the same guide he had all the way back from 2021)
coldcard
If this is real, it doesn't sound like he told Odell the gravity. As if upgrading would solve the problem. Sad as fuck
Where did the screenshot come from?
Why come to Matt's defense?
Knowingly
If they say from 4.0.1 onwards it's because 4.0.0 was never officially released.
"Version 4.0.0 was built, signed, and tested internally, but its binary was never released publicly. The contemporaneous signing manifest records that internal build and does not indicate public distribution. Firmware 4.0.1 was the first public 4.x binary, so public users were not exposed to this regression."
The entropy bug existed in 4.0.0, I checked the commits. It was not added between 4.0.0 to 4.0.1.
IMO, it seems like he knew. What strange timing to return to X as well.
Oh well, no idols, no heroes.
My understanding is the bug was introduced in 4.0.0
The confusion comes from the fact that since they patched a bug in that version, they removed it from the list of releases instead of keeping it and adding a "THIS IS A VULNERABLE VERSION" disclaimer.
Therefore people see that the first version released after 3.x.x was 4.0.1 and assume that this was where the bug was introduced.
Yes. Seeds created before the dodgy update appear to be fine.
Stay Humble and Steal Stacks
View quoted note →
We don’t know if he’ll learn from this - that’s the problem. He hasn’t said much. So far just covering tracks to dodge the legal bullets. Not a great look.
Yeah, I remember when Specter was the overly complicated wallet that certain people were suggesting to non-technical folks to use. Nowadays, it's Sparrow, which I absolutely love, but I think we should be more careful who we suggest use things like wallets where you can set derivation paths, etc.
Would you be responding to critics who hate your guts when your company is being sucked into a black hole? I agree coinkite's comms are all dodges... But that's what corporations do to keep their executives out of jail. Time will tell.
That's a fair assumption
This exactly. He could even run his sorries by his legal team lol.. but no. Nothing.
In the US this would easily be ruled negligence which will pierce the protections from the LLC or corporation.
Not sure aboot Canada.
He did apologize. In a statement.
You call that an apology 😏
And who are you? Never seen you around here … this NVK?
I'm nobody. New to this bitcoin thing.
As to the statement. I saw remorse. Not rooting for him. He made his bed.
I just saw excuses.
He is not interested in learning from this. He is evil.
Bro stop excusing and enabling evil. You turn your brain off to avoid facing the truth. That's not grace. That's not an absence of arrogance. That's just another form of arrogance. You're not following Jesus correctly. So typical of most Christians. Few.
That's an entirely distinct thing. Law is a subset of morality, and application of the law by trial to impose a punishment must be done with a very high burden of proof in favor of the presumption of innocence, because without doing so, you end up being a criminal yourself, which is strictly immoral (because it is aggressive). I did not make any claim implying in any way that this should be removed for NVK. Are you uneducated in law and ethics, stupid, or just dishonest?
Simply acknowledging that someone is evil (or that they are an aggressor, an even stronger claim) and deciding to ignore them and never give them money again nor any public endorsement of any kind, is a reasonable and perfectly compatible thing to do with grace and with these legal principles.
I just think calling someone "evil" should probably have roughly the same bar as calling someone a criminal. Innocent until proven guilty is how I want people to treat me, so I try to treat other people that way.
By the way, I really love your false trilemma there, it's such a pleasure to converse with nice, rational people like you.
I think we've probably got a quorum
I have verified NVK is what I consider evil. Or maybe you just don't like getting called out when you're wrong and that's the principle you're standing by (along with the Golden Rule - respect for that honestly). But I would prefer to get called out when someone is reasonably sure that I'm being wrong or evil. If you don't embrace that once you've understood this dynamic, then you are effectively choosing to be a worse person. It's not a false trilemma. I'm just correct.
I don't want to burn him. I just want to recognize the reality that's right in front of my face. Anti-reality types like yourself wouldn't care for that I know. Your mind, your delusion.
related :)
If you have a mentality that is assume the best. You can never work in info-sec..
We need to stop listening to these people about how to hold our coins
View quoted note →
agree, that doesn't make sense. i think they did release it: see
but for some odd reason decided to say they didn't. either way, i know this entropy bug was in 4.0.0 and the only coding change in 4.0.1 was what i posted.
X (formerly Twitter)
COLDCARD (@COLDCARDwallet) on X
COLDCARD 4.0.0 Firmware Release🍄⏫
-Bitcoin Core’s “libsecp256k1”+Optmzd SHA256
-Pure-assembly AES256-CTR (faster USB)
-24th-Word Calcul...
I don't need to be perceived as being on the "high ground." I much prefer it down here anyway.
Nor take on the responsibility of Bitcoin self custody and protocol debates.

