Yesterday's 'impossible' is today's weekend project thanks to AI.
These tools are fucking great!
Momo
momotahmasbi@primal.net
npub1heqk...kx28
The Host of Round the Fire with Momo
🧡💜🥩
It feels good scrolling through Nostr.
On X or Instagram, you can feel the algorithm feeding you whatever is most likely to keep your attention at that moment.
On Nostr, you simply see the people you’ve chosen to follow. If everyone is talking about ColdCard, you’ll naturally see lots of ColdCard posts, but you’ll also see their unrelated thoughts, photos, jokes, and everything else they choose to share.
On other social media, the algorithm tends to show you more of whatever is currently exciting or engaging you. On Nostr, people decide what you see, not an algorithm.
If Coinkite doesn't go out of business after this colossal fuck-up, then nothing wrong in this world will ever be righted.
Instead of helping people, NVK's removing tweets!

X (formerly Twitter)
Zach Herbert 🇺🇸 (@zherbert) on X
NVK is currently deleting old posts from 2020 to try to clean up the history. Screenshot them while you can. They will all be gone soon.
If quantum computers ever broke Bitcoin's cryptography, it would look exactly like these past two days.
We did it!
After a long coordination involving three people, we successfully moved 3.6 BTC out of an ColdCard MK4 and into a secure wallet.
We're not completely done yet. We still need to update the firmware, except the wallet won't recognize firmware files from either microSD or USB. So the device itself appears to be defective on top of the recent firmware disaster!
@npub12ctj...c5ky should reimburse the cost of this wallet at the very least!
QR codes were supposedly a security risk until NVK incorporated them into his own Coldcard Q.
USB cables were supposedly a security risk too and he never missed a chance to mock Ledger over them. (This "issue" he kept raising had a very simple solution, but if you only listened to him unchallenged, you'd never have heard about it.)
He poked fun at @Blockstream Jade for using the marketing term "virtual secure elements", yet having two secure elements did nothing when his product failed to generate enough entropy.
He mocked @npub17tyk...3mgl for using a general-purpose Raspberry Pi and made a huge deal about being able to extract the seed if you were close enough to the device using radio extraction techniques. Yet he made such a blunder that you didn't even have to be anywhere near his devices to compromise them.
I'm mad! I'm still waiting to hear from a friend who had a single-sig on MK4. I hope his funds are safe or at least he transferred any serious amount to his Cold Card.
I remember NVK laughing off the DarkSkippy exploit and saying something like it would have been impossible on a Coldcard, something that was never confirmed by the researchers behind the attack simulation.
It's unfortunate that such a critical vulnerability existed and could be exploited without physical access to the device.
At least with DarkSkippy, an attacker needed malicious firmware on the device and you had to make at least one outgoing transaction before your seed could be exfiltrated. With this vulnerability, the official firmware itself was the problem, and you didn't even need to make a spending transaction to fall victim to the exploit.
That's just tragic!