What a night. When I read the Stacker News article, I got nervous at 01:30 a.m. At around 02:00 a.m I realized that I couldn't sleep. At 02:30 a.m I drove to my first location, only to see the funds drained. I wasn't nervous anymore I had a real panic attack and puked multiple times. Over the next few hours, I drove to each location, collecting stuff and sending it to a single fucking Opendime I still had available. At 09:00, I had to go to sleep. I couldn't see and think well enough anymore. Now the result is all my remaining stack on a single Opendime. I can't believe it. After all these years, that's all I have to show for it. @Nunya Bidness @jimbocoin πŸƒ @ODELL @HODL

Replies (40)

I don't even know what to think about Coinkite as a company anymore. I really liked my ColdCard and was convinced Novak was the most paranoid person on the planet about security. I don't think that company survives this. As of last night I don't use ColdCards and will never recommend them to anyone ever again. Nothing about this is right. Lives were destroyed and all Novak did was essentially say, "I'm sorry".
Yeah, at this point, reading the extent to which Coinkite was owned I wouldn't trust the Blockclock. It is true that the Opendimes generate entropy differently than the other products but the more I look at this thing the more convinced I am that Coinkite is simply unsafe.
Yeah, this is a nightmare scenario for them. As I have said elsewhere, and maintain, the hardware wallet has one job: to protect your seed material during use. It is not your hardware wallet’s job to generate entropy. It is not your hardware wallet’s job to resist an attacker long-term with physical access. But, I accept that my stance is unconventional. People get into this field with the β€œdon’t trust, verifyβ€œ mentality, but then they place all their trust in the single most important thing that must not fail. The generation of their seed.
Sorry is an obvious one, followed by some sort of step to try and make things right- probably impossible though. Would have been better if his first response hadn't been to dismiss it.
Kingbee's avatar
Kingbee 4 days ago
So sorry friend. Loss of words here. πŸ’”
Pablo, hes been saying plenty for years. He went to war with Foundation because they decided to provide an alternative to his product. It’s not what he can say now, it’s would he should have done then (ie foster an ecosystem, something which he couldn’t comprehend) Now it’s too late. You might like him, maybe hes a friend, but hes fucked Bitcoiners here who won’t come back from this and NVK is gonna get ZERO sympathy against that cohort. Literally Zero. He said plenty already. Now the chickens come home to roost and people suffer for this guys ego.
A rare post that actually says what I've been saying. I still think the need to sell hardware wallets has caused of what a hardware wallet is supposed to be and how useful it is and is not supposed to be all in the name of sales. In hindsight, we should push for it to be common practice for devices to warn users that generating keys on device is not guaranteed to be 100% secure and to propose rolling your own entropy. By the way, even supplying dice rolls to a device is not good enough. If you can take that entropy and turn it into 11 words yourself then when the device gives you your 12 seed words, at least you can compare notes and know that the computer is using the entropy you provided.
Thank you! I hope that more people will adopt the mindset that they really do need to be in charge of their own entropy production. Everything depends on that.
Hofer99's avatar
Hofer99 4 days ago
Or back up even further if they had left seed signer alone. Karma is a btch they say.
The ColdCard problem is bad entropy generation. The OpenDIME doesn’t even try to generate entropy. It leaves that entirely up to you. So this current problem does not apply to the OpenDIME. You could choose not to use it for other reasons, but it’s not vulnerable to the same problem.
The lesson of this whole debacle is that the only way to KNOW that no one else has your seed is to generate it yourself. Therefore, any device that does not allow you to supply your own seed is unsuitable for use. Full stop. So I would NEVER put serious amounts of coin secured by Bitkey, Ballet, Satscard, etc. because I can’t verify that their seed material has not been compromised. I admit that my opinion in this matter is a bit of an outlier here.
What? Ballet, Bitkey, Satscard… what’s the difference? All of them generate seed material that you cannot observe nor override. So from your perspective, they’re all vulnerable.
Artel 21's avatar
Artel 21 4 days ago
Fucks sake. Man, hope it turned out well enough!
umni's avatar
umni 4 days ago
Is activity on nostr tracks with the downfall.
Fraser Aumua's avatar
Fraser Aumua 4 days ago
I can't thank myself enough for getting started. Despite the economic situation, I'm so happy to see €78,000 in returns from a €15,000 short-term investment with pjtradinghub. His videos are top-notch and highly educational, giving you real insights to achieve your goals and come out from debt! For a guide to a professional trader, I highly recommend everyone check out his Telegram πŸ‘‰ "pjtradinghub" image
↑