Yes, things fucking suck right now. Something that should've never happened has happened, and is still happening as I'm typing these lines. The consequence? Innocent, hard-working people are getting rekt. Life savings gone. No recourse, no undo button, no number to call. Just an empty balance and utter disbelief. Hard to think of something that's more devastating. The draining of funds won't stop any time soon either. Yes, it's not a full systemic failure and things could always be worse, but a LOT of people have used and are still using coldcards. People are on holidays right now, or in hospitals, or on a different continent, having no access to the key material that's potentially compromised. Unable to sleep, unable to do much other than pray, panic, or drive to the next airport. If they know about the current catastrophe at all, that is. I was barely able to sleep the last 3 nights. Not because I'm personally affected by said catastrophe (which I might be, I don't know yet, stepping into airplane tomorrow), but because I could've done more. I wrote about entropy and this particular failure mode in the past. I tried my best to educate people on randomness, and what a private key is, and how to use bitcoin without getting rekt. But I stopped, and a lot of the newer people are unaware of these issues and I feel like I failed them. As a bitcoiner, as an educator, and also as a regular person. As someone who has some technical understanding of how the various moving parts fit together. I've always felt a strong duty to educate others and help them understand, and I failed to fulfill that duty. I decided to stop writing and educating. I deeply regret that decision. It's hard to overstate the damage done. To me, bitcoin has always been about the separation of money and state, or more precisely: the separation of money creation and man. If humanity has a way to print money it will always find reasons to print money, period. Gold was seen as the tears of the Gods since men can't make more of it. Without a natural money like gold, society collapses. Always, like clockwork. Bitcoin has civilizational-level importance because of this. It represents a return to a natural money that lies outside of human influence, corruption, and fallibility. A lot of bitcoiners understand this, either implicitly or explicitly, and thus every time bitcoin fails in big ways or small, their soul hurts. It fucking sucks. My hope is that bitcoin will be stronger for it in the end. "What doesn't kill you makes you stronger," is something my dad used to say often. I'm not sure if it's true for people, but I'm pretty sure that it's true for bitcoin. We should all be more humble going forward, or at least I hope that we will be. And more kind, that would be good too. If you have any capacity to reach out to people and help them get through this mess please do. People are scared, and confused, and panicked, and don't know what to do. A helping hand and a calm voice will go a long way. And regarding the civilizational-level importance I've mentioned above: bitcoin will only be able to fulfill its promise if people hold their own keys. If that's not the case, bitcoin will just be another tool in the money printer's toolbox. That's why it all sucks so fucking much. A gaping wound in bitcoin's very soul, and the bleeding hasn't stopped yet.

Replies (119)

I can turn this into audio for the thread — goes live once 595 sats land here. One zap or many.
There’s not much more you could have done. Only nerds understand or care about entropy. No amount of writing or video or podcasts would have fixed that.
Demonstrably untrue. People have reached out to me to let me know that some of my writing is responsible for them adding dice rolls or generating their keys offline by other means, and they are not in danger right now because of it. Including non-technical people. Including people that are 60 years and older. Understanding randomness isn't that hard. Driving a car is way more difficult than flipping coins or rolling dice for 20 minutes.
XMRun's avatar
XMRun yesterday
You are talking about separating money from state. That is not possible when the money is not fungable. I.e. fully transparent. #Monero fixes this and still lots of Bitcoiners refuse to admit this. They will learn it eventually the hard way.
XMRun's avatar
XMRun yesterday
The state(s) will tax the shit out of Bitcoiners and if they simulate a boating accident, they will go to jail. Sad but true. Transparancy will hurt people.
thank you for your kind words. Things really suck i still feel the shock and panic. I hope better days are ahead but at the moment im in the mood that it gets worse before it will be better.
Five's avatar
Five yesterday
Well said, in a way we should all feel responsible. Safe travels!
XMRun's avatar
XMRun yesterday
I agree this whole situation is a total disaster. However what Gigi mentioned is not possible if with money that is not fungable. It is an impotant misunderstanding
The whole thing is so fucked up. I looked at coldcard too, and it was a very promising option. Luckily I went with bitbox gut my HW 😮‍💨 I don't think dice or coins are the answer. Would these keys not have been secure with a strong passphrase? I mean you could use the bacon bacon... Seed with a strong passphrase and be secure, right?
This tells you a lot about this community tbh. Just larping all around. You have to now roll a casino dice and do the math? If you are a cryptographer yes you can. As a human we all work on trust based society. Imagine your doctor said “don’t trust verify” “you should have known about the disease, diagnosis and treatment” after they fuck up. You pay a hardware provider and they have just one job. To generate random seed. Just like you pay a doctor or a lawyer. No other hardware provider has been affected. Sure they aren’t just “bitcoin only” but they have done their work. Imho you need to call out the circle jerking happening in our community rather than pointing out to people that they need to do more. People have already done their best and still got rugged.
Don’t carry the weight of the world on your shoulders, Gigi. Your writings have educated and inspired countless people to take sovereignty into their own hands. Self-reflection is good, but guilt isn't yours to hold. The mission to educate never ends, and we need voices like yours now more than ever. We learn, we adapt, and we rebuild stronger together.
Computers can't generate random numbers without external help. Dice and coins might be one source of entropy, but they aren't the only one. Cameras are a good source of entropy too. Hardware wallets are great and will remain important. I remember early full-disk encryption software that forced the users to move their mouse for a minute or two and type a lot on their keyboard (to generate additional entropy). Most of our products don't do stuff like this right now. They should.
repeating bacon (or any of the other 2047 bip39 words) with an additional passphrase would be only marginally safer as a plain brainwallet (sha256 of a passphrase) which isnt safe at all. pratically a passphrase 'strong' enough may not easier to remember than seed words it's not advisable to do rely on passphrases because the speed and cost for checking brainwallets (and its variations) can only get cheaper overtime
Gnom's avatar
Gnom yesterday
You done? go home and get your shine box tosser
You are a cryptographer, you know everything about this space because that’s what your job is. Someone who is not a cryptographer won’t understand the complexity and will fuck up. So that’s why they pay someone to do the heavy lifting. That’s how the economy grows and scale. It’s not possible that everyone who wants to self custody will roll the dice. We need to be practical. This hack wasn’t because of some sophisticated attack. It was because coldcard wrote shitty code.
Well same as with a password for websites, just make something up, pepper some numbers and special characters in, make sure it's 12 or more characters long and it's fine 🤔
But these passwords are secure right? Let's say it's your Facebook password, unless it gets compromised, there's no way to brute force it? At least that was my understanding 🙈
I'm not a cryptographer. And yes, it was shitty code. I'm talking about something else. I'm talking about how gun people will handle any and all guns always as if they are loaded, even if they know they are not.
How were you on the board of Opensats this long and never suspected that Coinkite's blatant contempt for open source development wasn't a clear red flag that their products may also be affected by such a stance, that NVK's own judgement as a board member would be affected? Open source code is not secure because more people read it, it's secure because more people use it and exercise it. No one sits and reads code unless they have a worthwhile reason to do so. And with no one able to actually use Coldcard code in their own work, no one had any incentive to externally review the code. A hasty migration between cryptography libraries introduced this zero day bug 5 years ago that could have been caught if people were building on Coldcard's code. That's just in one part of the codebase. Who knows what other zero days are lurking in any Coinkite product because of their stance on so-called "cloners?" I'm glad to see NVK stepping down from Opensats board. But this incident has really shaken many people's trust in the organizations NVK was a part of, and the people who most interacted with him. It's crucial to continue educating users about safe practices. But I believe it's equally crucial that you educate people about how this bug really came to be, from more than a technical standpoint. So that a disaster like this can be prevented in the future.
How many people drive cars? How many people are handling guns on the regular? How many people wield a very sharp kitchen knive every day, or handle highly explosive substances like natural gas and the like? People are more capable than we usually give them credit for. The issue is that they don't care, and I see it as my job as a bitcoiner to make them care.
That was said in jest, and you're right, grandma would probably enjoy a game of dice from time to time.
Your readers self select from a very large pool of people. You have the entire population and then people who know about bitcoin and from those who have dabbled in it - multiple touch points and from those the ones who self selected for Bitcoin only and from those to be curious about self custody and then down to rolling dice (I’m skipping many levels). Yes people are a lot more capable than they give themselves credit for, but that doesn’t tell us much about the few that end up choosing to roll the dice or not. Plenty of hardcore bitcoiners did not roll any dice even if they read your blog. Again, not speaking about the quality of education which is excellent imo.
I am non-technical but have spent countless hours doing the deep dive into Bitcoin. The ideology and cultural aspect is usually where the majority of my time is spent as that is what interests me the most but by no means have I neglected the technical side of the coin. Key generation is something Ive spent very little time on. Almost like it was taken for granted. It wont be any longer. My heart goes out to all those affected. Cold card users were likely some of the most convicted users in the community. Something this bear market has apparently revealed was the strength of the network from the individuals. So much noise from Treasury companies, financial products, clarity blah blah, politicians. Seems very clear that our current price support levels are what they are because of the plebs that believe in the better world that Bitcoin can offer. For this attack, at this point in time, to target this specific group is probably one of the worst things that could have happened. Everyone has failed here. Everyone feels this loss. It seems such an obvious vulnerability in hindsight. Its our responsibility to fix. Bitcoin is working as intended. Its stewards were not.
The problem is it's much harder for a user to check that a HWW "code is actually.. using it." vs. adding manual entropy.
But this incident has really shaken many people's trust in the organizations NVK was a part of, and the people who most interacted with him. blah blah blah stop making shit up nvk is nvk open sats gives money to good projects they dont need your trust
Just use multiple sources (not xored). 5 sources, cause why not. After that, the only point left to check is the joining and hashing. A strong kdf wont hurt and it will slow the attacker down a lot, even in case of bad entropy. But people want "fast" experience, cause waiting 1 minute for a kdf to run ONCE when generating is an immense pain the ass, right? Short keys. Weak kdfs. Leaky HSMs and TPMs disguised as security and used as a user behavior control tool. No. This not the way.
you might have a bit of a rescuer complex take better care of yourself! it all starts with you then you can share yourself with the world from a strong foundation hope you get to your cc mk in time
this depends on the attack, But if the attacker knows the seed phrase, the passphrase needs to have ~70bits of entropy. Per truly random alphanumeric character, you get about 6bit per character. so you need 12 minimum If the passphrase is not truly random, the bits you get per character sink drastically (eg. it includes well known sequences or numbers)
In your long speech you didnt mention bip110 or how the node software you support is crucial - especially in this climate. Why aren't you as articulate and detailed on that topic?
FB password is not an encryption password. It's an access password. Apples vs oranges. Encryption password has to be LONG. 30 chars. 40 chars. And has to be stretched by password stretcher known as a KDF. The KDF has to be chosen accordingly (to current technological advancement) People have brains mangled by google and apple and 'one' pin. This is wrong. Learn about basic entropy and encryption. And teach others, so we don't have fuckups like Trust Wallet with a 6 digit pin as password which has an entropy of a dick. And no, tee/ree doesnt fucking count.
Important to you, you write about it. He’s not writing to you specifically, your royal highness 👑
james_r's avatar
james_r yesterday
what has this bug to do with opensats, really
@semisol what would a user runnable self test for that look like? capability was never the problem on the coldcard, the source was present and quietly stopped being mixed in, and nothing outside the device could tell.
GM. Bitcoin needs to go back to the basics. Except this time we can build everything up even better
synking's avatar
synking yesterday
You were the one who convinced me to take Bitcoin seriously, to keep my own keys, and to do it right. You taught me back then that Bitcoin is more important than my own quick personal gains. You didn't fail us.
XMRun's avatar
XMRun yesterday
I am sorry to hear that. It is disaster.
100% You literately have to roll dice and enter a number:1-6. Both Coldcard and Seedsigner walk you through it. Could not have been easier. Self custody is the full expression of personal responsibility. It is exactly that: each person is responsible for themselves.
A cleansing of the plebs embracing sovereign money, driving them back into the institutions already co-opted by the government. It all feels like a logical, orchestrated plan of attack.
Fuck ups: 1) Regular dices are heavily weighted on one side. They don’t generate the same entropy as a casino dice. 2) doing it on a hard surface like your table, uneven surface. This reduces the entropy as causes dice to slide. 3) Not shaking properly every time you roll. 4) Most importantly you are relying on coldcard to give you the seed word. How can you trust that device, that’s it’s really really giving you the randomness you generated via dice rolls. For true proper generation you have to do the dice rolls properly plus do the math yourself otherwise it’s always trust involved at certain point.
Default avatar
Martin yesterday
If you're looking to recover your Bitcoin. Paul Jon is the best man to meet to guide you through every recovery process and I highly recommend everyone to check him out. He is the BEST 🌟 image
Appreciate your knowledge/take. Honest ?s: so the number generated from the "badly weighted dice" are biased to one numer (1-6), so the hacker then scans a smaller subset of possble PVT keys with "too many" 1s or 2s....etc.... Is this how it works? And yes at some point u trust someone to generate the 1s0s or u do the math yourself, i get that. So will the future standard be: roll high grade verified (how?) casino dice + do the math yourself? Who checks my math? Gets kind-of crazy...
You are just doing mental gymnastics at this point. Buy any hardware wallet. Most of them use TRNG, which generates seed inside the hardware. It was not the failure of TRNG but instead coldcard coded shitty software where they defaulted the seed generation to PRNG. They are total clowns in the space and all the circle jerks instead of pointing that out are telling us that we did something wrong. If you don’t understand what you’re doing in cryptography, you should probably not do it. Staying retarded helps.
This is not a zero day… it’s clear to me that people’s wallets have been getting drained since this bad update came out… It’s just been "covered up and disregarded" by coinkite as a company…
What about this message I’ve been spreading to learn from errors? Heal the industry. Follow and work with the guys advocating against hardware wallets and taking flack for years. Open source, non-BTC specific hardware. Seedsigner BtcCuracao JW Weatherman heavilyarmedc BenWestgate Peter Todd Robert Maxwell Robert Spigler LibertyMugs and Epic Curious
Beyond the immediate devastation, this disaster really shreds any credibility bitcoiners had in normie land. We all look like fools whether we lost money or not. Me. You. Everyone. It's a huge blow to self custody and just seeds the ground for custodial tyranny *within bitcoin*. I can hear it now: "Your wealth is safer with a credentialed state-approved custodian; look at what happened with ColdCard!" 😔
Your book, all the podcasts you have done, the writings on your blog are still available and still ‘out there’. You have arguably been my greatest teacher when I was first trying to learn about Bitcoin. You have contributed more to this community as a teacher than most. And your body of work is manifest in the world for anyone to seek and find! (And hopefully v4v zap you for the privilege.) Everyone’s life has twists and turns, seasons for sowing, seasons for reaping…. Times of going inward, Times of outflow and output…. We don’t have to be responsible for the timing of such things. It will happen with the hand of Grace. I would personally LOVE to see you return to teaching, and sharing your gifts with us all. That would be cool. You were the first person I heard mention that a wallet could be created by a person in a prison cell - simply by flipping a coin 256 times…. That sent me down a major rabbit hole! When you feel so called and the desire to flow outward again is supported by Grace - I’ll be a happy man…. To learn from you anew. Please don’t feel obliged in anyway though. Duty is an extractive motivator. When the time is right and your inner healer is full, when flowing outward feels fun again, it will nourish us all….. @Gigi included 💚
Care is the scarce resource. Bitcoin forces humans to care about keys. AI wallets will force agents to care about limits, logs, and blast radius. Same game, weirder players.
Bitcoin qt. With the unsupported pass phrase has been great for me and the few people I've managed to orange pill ish.
Ok , chill dude. Bitcoin fails if the path to self custody isnt _easy enough_ and _safe enough_ for highly motivated, but ultimately just regular people willing to do it. We're a long ways from that right now.
synking's avatar
synking yesterday
Team self-custody: 28 Team exchange: 1
This is LONG from over. Investigators are hot on the trail. And, bitcoin leaves a great trail. I'm still very optimistic this will end very well for 80% + of the people and it will end up strengthening the network.
Sat’s Oil's avatar
Sat’s Oil 21 hours ago
Definitely not your fault 🧡 Lesson learned #NotYourEntropyNotYourCoins
I read these things and understand your points of course but don’t get the why everyone is avoiding elephant in the room and point a finger to the @NVK and his epic level failure. He kept talking shit about seed signer instead of checking his own code and project. And he ended up this situation because he was acting against the real Bitcoin and FOSS ethos. I can’t think of a bigger disgrace for Bitcoin then undermining the self custody. And he deserved some shit and everyone from the community just dancing around it instead of blaming him for his incompetence. I would like to think it is not just because people get paid by him at some point via sponsorships stuff like that.
Hardest thing above all about this attack is that we know we lost true soldiers. These were people like us who we know would lay their lives on the line for the principles, morals, and ethos of Bitcoin.
State Level Attack insider attack within the pleb garden walls. Circle jerking friends of his will think he was wrong, careless, greedy and arrogant but those who have studied real history and recognise patterns will know there's more to it than just a fishy smell. Ashkenazi or not - Quadriga involvement and profiting was highly sus. As is dormant bug exploited at a convenient time - for various reasons. Flagged early but silenced, likely to keep a future attack possible. Ingraciated himself with influential plebs, to buy credibility and market share. Like Saylor the Fed. Too rich for some people's blood yet they know we're in the then they fight you stage. Just wait until you go deep on Ross and Silk Road! And keep an eye on Swan, Pritzker and Klippenstein
Kunt Sniffer's avatar
Kunt Sniffer 13 hours ago
I’m sill using the cold card for now but with a 24 rolled dice roll and a complicated passphrase. I’m just nervous to move it to an online hot wallet with a generated seed at the click of a button. If anything we cannot trust this method anymore, the dice method is cheap and easy
yeah it's what makes it so tempting to imagine that there is a larger game here. If you wanted to undermine the culture and credibility of self-custody, can you think of a more effective way to do it?