Sooly⚡️سولي 🇱🇧🇧🇪🇦🇪🇦🇴's avatar
Sooly⚡️سولي 🇱🇧🇧🇪🇦🇪🇦🇴
sooly@NostrArabia.com
npub1hzz3...nqel
🟠 #Bitcoin for MEA (Middle East & Africa) 🔘 Founder, NeoWealth 🔘 MEA Nation State Advisor @JAN3 🔘 Faculty Professor at the World's 1st Bitcoin Masters Program 🔘 Co-founded 1st Arabic Nostr Relay (nostrarabia.com) 👾 Sooly.bio | sooly.npub.pro 🎖️ Suspended for 3yrs on X (@sooly_kobayashi) 🌍 Building open-source sovereignty tools for wealth, privacy & independence.
If governments could legislate prosperity, poverty would have been outlawed decades ago. Venezuela’s statutory wage floor: ~$0.17/month. Burundi: ~$0.76. Cuba: ~$4.76. Georgia: ~$7.64. These are legal floors, not typical pay. The law controls the number. Productivity and the currency control what it buys. image
🚨 IMPORTANT Blink Wallet Users If you use a custodial Blink account, you must migrate/withdraw your funds: ⚠️ August 10: end of receptions ⛔ August 31: deadline to withdraw your funds Don't wait until the last minute. Not your keys, not your coins. 🟠
A lot of Bitcoiners are not technical. That is fine. If we want to onboard new coiners, self-custody advice cannot sound like you need a cybersecurity degree to protect your Bitcoin. After the recent Coldcard incident, my advice is simple: Choose a well-established hardware wallet that prioritizes: • open-source hardware and firmware • reproducible or independently verifiable builds • a strong security track record • public vulnerability disclosure, ideally with a bug-bounty program • keeping your recovery words completely offline For beginners today, I would look at BitBox02 Bitcoin-only, Trezor, and Blockstream Jade. Open source does NOT mean bug-free. It means the manufacturer is not asking you to blindly trust what is happening inside the device. Independent researchers can inspect it, challenge it, and report weaknesses. Then keep the rest boring: Buy directly from the manufacturer. Never photograph or type your recovery words into a phone or computer. Start with a small amount. Learn how recovery works before moving serious savings. As your holdings grow, your security can grow with them. You do not need to become a security engineer before taking self-custody. You need a setup you understand, can recover, and are unlikely to screw up. Good security should make Bitcoin ownership safer. Not scarier.
Non Technical Plain English Update: the Coldcard incident appears far bigger than first reported. The early 594 BTC figure now looks like only the first visible wave. The current observed on-chain estimate is about 1,367 BTC across 4,585 addresses in 3 waves. That does not yet prove every case is tied to the same actor, or that every wallet has been publicly proven case by case. But the risk is clearly bigger than many first thought. Plain English: A hardware wallet is supposed to create a secret key so random that nobody can realistically guess it. A firmware bug meant some Coldcards generated seeds with far less randomness than intended. That allowed an attacker to calculate likely keys offline, compare them against Bitcoin addresses visible on-chain, and drain funds without touching the device. If you use a Coldcard, the message is simple: - Update to fixed firmware - Do not trust the old seed - Generate a completely new seed - Verify backup, fingerprint, and receiving address -Send a small test transaction - Then migrate the rest carefully Important: Updating alone does not fix an old weak seed A weak seed remains weak forever 50+ private dice rolls materially reduced this specific risk A strong BIP39 passphrase helps, but migration is still the prudent move Multisig helps only if enough keys were generated independently and securely The hard lesson: An air gap can protect a strong key. It cannot rescue a weak key created at birth. Share this with anyone using a Coldcard. image
594 BTC. Around 500 wallets. Roughly 25 minutes. The devices never needed to be touched. Here is the Coldcard security incident in plain English: A hardware wallet is supposed to create a secret key so random that nobody could ever guess it. A firmware bug meant some Coldcards generated keys using far less randomness than intended. Think of choosing a winning number from billions of billions of possibilities, only to discover that the machine was secretly choosing from a much smaller list. An attacker could calculate possible keys offline, compare them with Bitcoin addresses visible on the blockchain, and take the coins without touching the device or knowing its PIN. What is confirmed: • 594.48 BTC was swept from 1,324 old #Bitcoin outputs • The sweep involved roughly 500 single-signature wallets • 562 #BTC was later gathered into one address • Coldcard confirmed a serious seed-generation bug • Fixed firmware has now been released What is not yet fully proven publicly: That every wallet in the 594 BTC sweep came from this exact Coldcard bug. The connection is strong, but the investigation is continuing. Coldcard users should: 1. Update Mk3 to 4.2.0+, Mk4/Mk5 to 5.6.0+, or Q to 1.5.0Q+. 2. Do not stop after updating. An old weak seed remains weak forever. 3. Generate a completely new seed on the fixed firmware. 4. Verify the backup and receiving address, send a small test amount, then move the remainder carefully. At least 50 fair, private dice rolls materially protected against this specific flaw. A strong BIP39 passphrase adds another barrier, but Coinkite still recommends migration. Multisig helps only when enough keys were generated independently and securely. The uncomfortable lesson: An air gap can protect a strong key. It cannot rescue a weak key created at birth. Self-custody removes the bank. It does not remove software risk, human responsibility or the need for independent verification. Share this with anyone using a #Coldcard. Calm action protects funds. Panic attracts scammers. Credit to Rob from Anchor watch (tag him if you know his npub) for the sharp on-chain tracking behind the 594 BTC figure. Rob, flag anything here that needs tightening.