McCoy's avatar
McCoy
McCoy@primal.net
npub18y33...x5t7
Bitcoin NOSTR block 768722
McCoy's avatar
McCoy 1 week ago
Is this true? Checking my clanker: @craigraw @Bluewallet "For a pre-derived xpub imported into a watch-only wallet for monitoring only (2/3 multisig, P2SH) the derivation path label does not change address generation." Blue Wallet deriv: m/1' Sparrow: m/45'/0'/0'/0 Both create same addresses, ?
McCoy's avatar
McCoy 1 week ago
PBKDF2 is a form of hash function that is designed to be slow (by hashing the data multiple times before producing the result). This has the benefit of making it more difficult for anyone to brute-force mnemonic sentences to try and get seeds that people have actually used. In addition, PBKDF2 also allows you to provide a second input called a salt ("passphrase", "seed extension") along with the data you want to hash, which allows you to produce completely different seeds from the same mnemonic sentence. - learnmeabitcoin.com
McCoy's avatar
McCoy 1 week ago
Not sure is this logic holds but, hit me back if I'm way off: - rolled my own entropy + pass phrase; 2-4 years later key not swept, likely means I'm good _forever_? as if the entropy was bad, then the money would have been gone long ago vs - use hardware _X_ to generate key; 2-4 years later, still not safe as AI+wizard humans could still hack/uncover weak spot in the hardware down the road (=AGI future)
McCoy's avatar
McCoy 1 week ago
Amazing that in my MSM feed(s) there is no mention of the coldcard fiasco. None. In bitcoin self-custody circles feels like the sky is falling, everwhere else, meh
McCoy's avatar
McCoy 1 week ago
Consider dusting swept wallets with 10000-20000 sats and watching them. Did this with any single sig CCQ with weakish pass phrase, no dice
McCoy's avatar
McCoy 1 week ago
Dont forget the USD is the real shitshow. Stealing from everyone forever.
McCoy's avatar
McCoy 1 week ago
Silver lining to this CC hack/gate/fiasco: there is much work to do to make self custody easier + secure for the common man. But is must be done. Bitcoin definitely fails if some cant self custody. It actually doesnt need to be that many, just some with the option to if the custodians f-around. Enough to keep them honest. IMO this will scare the normies, as it should and keep it underground for longer. We have a lot more time to build and learn. LFG
McCoy's avatar
McCoy 1 week ago
Long 48 hours of redoing some private key generation, dice rolls, remembering set ups, triple checking, testing back ups. Silver lining: was mostly ready. Sparrow fire. Good practice doing this. Also, wife, fully engaged, asking tons of questions.
McCoy's avatar
McCoy 1 week ago
RNG-hack f-n sucks. Many did (nearly) everything right - took way more personal responsibility than 99% of people and got screwed. F those who spend their time stealing people's time/energy. Go hack a shitcoin exchange or an suitcoin instituon - why target the few plebs trying to do it right. The only way bitcoin wins is if some are willing to self custody and the option/path to do so exists. There is obviously a lot of work to do to ossify the self custody path. Lets get to work.
McCoy's avatar
McCoy 1 week ago
.....hundreds of unrelated wallets were being emptied in a 25-minute window, and the funds were all flowing into the same consolidation addresses: bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0 bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r Lookonchain, a blockchain monitoring service, was one of the first to publicly flag this coordinated sweep. A victim posted on Reddit While the addresses were already public, the first human alarm came from a victim who noticed their dormant Coldcard wallet had been drained and posted about it.
McCoy's avatar
McCoy 2 weeks ago
Dice/coin entropy is the strongest mitigation against RNG bugs in general because it removes trust in the device’s random number generator. SeedSigner is not affected by the Coldcard RNG flaw, and its dice-roll feature lets you generate seeds without trusting the device’s RNG at all.
McCoy's avatar
McCoy 2 weeks ago
Per Maple AI: "Could the 32-bit reseed be brute-forced? Yes. If an attacker knows or narrows down the UID and timer state (via USB serial number, purchase records, or boot timing), the remaining work for Mk4 collapses to brute-forcing 2³² = 4.3 billion reseed values. That is very feasible for a well-resourced attacker. But brute-forcing the full ~72-bit space (without knowing the UID/timer) is not practical today. That is why Block said the attack is "ongoing" and warned that targeted Mk4/Q wallets — especially those with weak passphrases — could be next, rather than being hit in the initial mass sweep."
McCoy's avatar
McCoy 2 weeks ago
Stealing is illegal and immoral, right? bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r
McCoy's avatar
McCoy 2 weeks ago
The focus on Fed rate is pure noise. Short-term rates mean nothing. Real rate is determined by the market (=10+yr bond sales). When appetite is low for US 10y they MUST raise the rate to attract more suckers (=buyers). When market tells them _no thanks_, they will just buy debt themselves = yield curve control = fiscal dominance = ponzi Opt out.
McCoy's avatar
McCoy 2 weeks ago
BIP 110 contentious debate is a nothing-burger compared to what could be coming...... Wait til governments and large corporations are disagreeing about bitcoin + censoring each other. It will always be work/physical energy that resolves conflict. Gold was a physical, bearer asset. I have the Gold, I make the rules until someone takes it from me. In Bitcoin real physical energy also resolves the conflict. Economic nodes. Hashers. Out-of-bound transactions: real work, in the real world. The way to transact in a future hostile world will be: run an economic node, build blk-templates yourself, harness energy, hash. Always without permission. Always with real work.
McCoy's avatar
McCoy 2 weeks ago
Bitcoin would be _easy_ to spend if I aquired the coin at say $100. Sure spend 0.001 now and then. Purchased at $105k, not so much.