Don't let the Coinkite crew gaslight you. Coldcard had a silent fallback to false/pseudo entropy IN THE MOST CRITICAL PATH of their firmware. This was not a "sophisticated AI attack", but (best case) morons larping as edward snowden and succesfully fooling the entire #Bitcoin space. The real attack was social.

Replies (8)

Thank you. People are saying “first it started with coldcard” as if it’s going to somehow spread to other devices where they have sufficient entropy. Coldcard had basically ZERO entropy 😭😭😭
Why the fuck would a fallback even exist. Like if it fails why force it through?! TOS may be void if Gross Negligence and Willful Misconduct can be proven.
The micro Python interpreter used the wrong random number generator function because they had the same name, so instead of using the coldcard function, it used the built-in micro Python one that wasn't secure.
Using dynamic scripting languages like Python/JavaScript for do or die cryprography... 🪦🪦🪦