DevilishLemonBar πŸ¦₯βš‘πŸ³οΈβ€πŸŒˆ's avatar
DevilishLemonBar πŸ¦₯βš‘πŸ³οΈβ€πŸŒˆ
_@slothy.win
npub1y3k2...vp4j
Electrical "Engineer" Aggie'20. Onlyfans (NSFW): http://tx.ag/Igebcre β‚ΏIP-47: http://helali.me/bip47 ⚑Node (shutdown): 03817596435f25a156da4a89c9dabf2a3e4f9a74418543f3de6b77cab780a473a1 Ω…ΩŽΨ³Ω’ΩƒΩΩˆΩ†ΩŒ Ω‡ΩŽΨ°ΩŽΨ§ الجِنُّ بِΨ₯ِنْسْ.
Zero announcement / advisory notice / blog post or any indication of the vulnerability on BTCPay Server's website other than the post on X. It has been 4 hours. If this is how they operate, I advise you all to just pull the plug and shut your BTCPay instances down.
Friendly reminder that even in 2013, RNG bugs had a response with much better user UX, often indicating that a new seed is required, and guiding users to migrate funds. Yes, with a hardware wallet this is slightly more complicated, but if something like Bitkey can handle seamless seed refreshes and fund migration (ex: the enhanced privacy upgrade) then others can. Every hardware signer should have some form of official companion app that can make these flows possible for the average non-technical user.
Also, not having an optional first-party companion app is a major downside. This could've been handled much faster and with less friction if there was an app flow that a) alerted to a signer having a vulnerable firmware. b) initiated a migration tx to a new seed as soon as the device firmware is updated (possibly a hop to a software key in the interim if the signer can only have one active private key). If Bitkey can do it (ex: the enhanced privacy upgrade requiring a new key - seamless flow) every company should have a similar flow ready for this type of situation. It should only take a couple of clicks.
A somewhat gross but nonetheless true statement: In the grand scheme of things ~90M USD in drained ColdCard wallets is a drop in the ocean. I'd wager that ColdCard's marketshare isn't even that significant in the grand scheme of things. What particularly sucks is that these are pretty much all from plebs who worked their assess off to stack that corn. And ironically from those who probably tried to go the extra mile to get something more "sophisticated". It's "only" 90M but the impact this loss has on those affected is immense.
I see people saying this Coinkite/ColdCard incident will reduce confidence in self custody. It shouldn't. This was an amateur flaw in a company run by a narcissist who should've never been trusted to begin with. If you ignore the red flags around their hostility towards FOSS, seedsigner (including squatting seedsigner.org btw), then I don't know what to tell you. Maybe if nvk spent less time shitposting and more time auditing his garbage, we wouldn't be here. If you're going to use a hardware signer, use proper hardware signers from serious companies who have their work audited... especially you know, the bits around fucking entropy and seed generation, fundamental parts of a fucking hardware signer. And it should go without saying that "influencers" who shill this garbage should reconsider. Sympathies to everyone affected.
↑