TFTC's avatar
TFTC
tftc@primal.net
npub1sk7m...jraw
Truth for the Commoner. A media company focused on #Bitcoin, freedom, and truth in the digital age.
TFTC's avatar
TFTC 1 week ago
Tech stocks just saw their largest 5-week inflow in history. image
TFTC's avatar
TFTC 1 week ago
Coinkite has halted all Coldcard shipments and destroyed remaining inventory with affected firmware. Customers with in-transit orders have been contacted directly with migration steps. image
TFTC's avatar
TFTC 1 week ago
Users are reporting that Coldcard's emergency firmware update is bricking some devices. These reports are anecdotal and have not been confirmed by Coinkite, but if you're planning to update, move your funds off the device first.
TFTC's avatar
TFTC 1 week ago
A security researcher (1440000bytes) flagged a vulnerability in Bitkey's inheritance setup flow. The team responded within hours, confirming no funds were at risk thanks to their defense-in-depth architecture. A patch was submitted to both app stores and they hosted a public X Space to walk through the technical details with the community. image
TFTC's avatar
TFTC 1 week ago
Galaxy Research is tracking the Coldcard hack in real time. They've identified three waves of sweeps so far: 1,367 BTC (~$88.6M) drained from 4,585 addresses. The first wave hit 1,196 addresses in a 41-minute window, all paying an identical 30 sat/vB fee. Automated key scanning, not owners moving funds. Galaxy notes "the loss profile is dominated by sub-1 BTC addresses in count, but by larger addresses in value. This appears to be the shape of individual self-custody, not institutional holdings." Not one coin taken was created before the vulnerable firmware shipped in March 2021. image
TFTC's avatar
TFTC 1 week ago
.Kevin Loaec 🧙‍♂️🐟 from Wizard Sardine just published a full technical breakdown of a critical Coldcard vulnerability. Every seed generated on the device since 2021 is compromised. Wallets are being drained right now. The chip has a perfectly working hardware random number generator. Nobody was calling it. "The Coldcard replaces MicroPython's randomness module with its own, deemed more conservative. To do so, it disables the original one... The catch is that MicroPython does not remove rng_get() when that flag is 0. It replaces it with a software imitation." The result: "a Coldcard seed no longer held a single bit of physical randomness." A compile-time safety check should have caught this but used `ifndef` instead of `if`. "One character stood between that safeguard and its purpose." It passed on every build for 5+ years. Seeds from 50+ dice rolls or pre-2021 are safe. Everyone else: move funds now. image
TFTC's avatar
TFTC 1 week ago
As much as this hurts. The network will grow stronger from it. Don't give up. image
TFTC's avatar
TFTC 1 week ago
TFTC 778 w/ (hot_town): "The playing field is being leveled. It's no longer limited by technical ability. This opens up whole new economies." We discuss: ⚡ Building with AI agents ⚡ Bitcoin & the agent economy ⚡ Why open source wins
TFTC's avatar
TFTC 1 week ago
Conner Brown of Matthew Boyer urges Coldcard victims not to destroy compromised devices after the firmware flaw that drained tens of millions in BTC. “If you have a Coldcard that was compromised, do not throw away or destroy the device.” image
TFTC's avatar
TFTC 1 week ago
Hyperscale Data sells 100 Bitcoin, establishes BTC-backed credit facility to accelerate Michigan AI campus. image
TFTC's avatar
TFTC 1 week ago
"Even the smart guys screwed up self-custody. How can we expect anybody will comfortably self-custody after this?" (jamesob) on the second-order effects of the COLDCARD vulnerability, why every hardware wallet maker has had a fatal misstep, and why the only categorical fix may be covenants.
TFTC's avatar
TFTC 1 week ago
"Security by obscurity is going to zero rapidly." (jamesob) and other researchers independently reproduced the COLDCARD vulnerability by pointing an AI model at the firmware history. This is the new reality for open-source security.
TFTC's avatar
TFTC 1 week ago
"You screw up one thing, the wrong one thing, and it's toast." @MartyBent and (jamesob) on the COLDCARD vulnerability, what it means for self-custody, and why you should be reaching out to anyone you've ever recommended a COLDCARD to.
TFTC's avatar
TFTC 1 week ago
Coinbase Chief Policy Officer on CLARITY Act progress: "We've got ethics nailed down, we've got nominations nailed down, we've got a bipartisan bill on the substance, we should be good to go."
TFTC's avatar
TFTC 1 week ago
TFTC 777 w/ (jamesob): "If you're single-sig with no passphrase or dice rolls, you need to drive home and migrate your funds. These wallets are dangling in the wind." We discuss: ⚡ The flaw exposed overnight ⚡ How to check your risk ⚡ Why self-custody still wins
TFTC's avatar
TFTC 2 weeks ago
Coldcard founder (nvk) says the reports of drained wallets are not a device vulnerability. The thefts are part of a wider attack affecting 500 private keys across different wallet types, not just Coldcard. image
TFTC's avatar
TFTC 2 weeks ago
Sen. Cynthia Lummis says the CLARITY Act remains on track for a Senate vote before the August recess: “Sen. Thune has kept a place for the CLARITY ACT on the agenda...and I believe he does intend to go through with it...We will be moving forward.”
TFTC's avatar
TFTC 2 weeks ago
Sen. Cynthia Lummis: “This doesn’t come back next year… The realistic next chance at market structure legislation is likely 2030.” She urged passage of the CLARITY Act, adding the window to lead “is wide open.”
TFTC's avatar
TFTC 2 weeks ago
IRS warns digital asset investors of fake letters with QR codes directing to a nonexistent “Digital Asset Compliance Portal.” Coinbase also alerts clients. Do not scan the codes or enter any info. image
TFTC's avatar
TFTC 2 weeks ago
Russia just charged Telegram founder Pavel Durov with "aiding terrorism" and put him on an international wanted list. The FSB says Telegram failed to remove channels used by Ukrainian intelligence for sabotage and recruitment. This is the same playbook every government runs. France arrested Durov in 2024 over similar claims. Now Russia is doing it from the other side of the same war. The pattern is always identical. A terrible act happens. Governments point at encrypted messaging. They demand backdoors, content removal, compliance. Anyone who refuses becomes an enemy of the state. But encryption cannot be secure for some people and insecure for others. That's not how math works. A backdoor for the FSB is a backdoor for every intelligence agency, every hacker, every authoritarian regime on earth. Russia is simultaneously pushing its own state messaging app called MAX that openly shares user data with authorities and doesn't use end-to-end encryption. That's the endgame. Replace tools you can't surveil with tools you control. Every government wants the same thing, a communication layer they can monitor. They just use different justifications. Russia says terrorism. France said child safety. The US says national security. The demand is always the same. Give us access. The 60 Minutes clip from 2016 is worth revisiting. Durov said it plainly, "Encryption cannot be secure just for some people."