pull down to refresh
There are something more than 40k deaths caused by motor vehicles each year just I'm the US. That's not just money, it's people's lives. And yet, we mostly all still drive because it gives us something that we think is worth the risk. Why don't you think Bitcoin is like this?
I still do. However the hack is unacceptable. Someone could follow the directions to a T, doing everything exactly like they are supposed to and still lose their savings despite perfect off-chain security. It is unacceptable.
Bitcoin is competing against houses and gold atm, and those things do not get hacked.
What others are unwilling to admit is that the bug-apocalypse is just beginning, the AI tools are relentless, merciless and unforgiving and they find bugs that humans cannot. This is likely just the beginning of crypto-bugs and apparently bitcoin isn't immune either.
Bitcoin is competing against houses and gold atm, and those things do not get hacked.
They can get "hacked" in other ways. Nothing is foolproof. Let's wait and see what really happened to this user and what the point of failure was.
Friend it wasn't the user. It looks like a failure of the ColdCard hardware RNG which means that thousands, maybe 10s of thousands of users are effected. Using the RNG's entropy for a seed phrase means it can be brute forced, and if that's true a lot of addresses are now vulnerable.
"unacceptable"? What are you saying?
You have no choice than to accept it because it happened 21h ago and there is not going to be a rollback. What is needed is a path to safety, a post mortem, infrastructure to structurally improve whatever weakness this turns out to be. More safeguards.
"What is needed is a path to safety"
That's nice to say but it's hard to tell users that when they have stacked sats and suddenly they wake up and they're all gone. The number of users affected could be much, much higher if I understand the twitter analysis right. A lot of people won't move their funds, or they'll move them wrong or make a mistake or they wont have another hardware wallet or won't even know about the hack before their funds are gone. For all we know the entropy on the Coldcards is highly compromised.
I personally didn't lose a sat (thank goodness) because i 'manage risk' across multiple devices but that's a lot to ask of people to use multisig when Coldcards were supposed to be 'safe enough.' Of course there isn't a rollback but IMO the magnitude of something like this shouldn't be papered over either.
If we're being really honest AI makes gold look good - it is permanently offline and the best way to improve bitcoin is to be transparent with ourselves.
this is the same old adage of blaming the money when a bank gets robbed, no its the institutions and software/hardware that are 'protecting' it.
Coldcards used to be standard, no way after this fiasco
you might as well buy a laptop from best buy put linux on it download core
Anything other than this is additional surface risk in the stack, less reviewed, less obscure.
Hardware wallets cost more than an old laptop and create a paper trail, and then people defeat the purpose and use them with software on their daily driver.
The only reason not to raw dog Core is backups, which leads to seed phrase middleware, and then the fucking seed phrases cause more people to get robbed than anything.
All the time and money wasted on the HWW industrial complex could have been applied to making cheap micro mdisc drives and/or a decent brain wallet process in Core.
For those of you who can't or won't say it:
This is an absolute disaster. If Bitcoin isn't secure it is worthless. Multisig should not be necessary it is already complicated enough without multiple keys.
And it really pokes a hole in the whole 'hardware wallet security' industry, you might as well buy a laptop from best buy put linux on it download core and generate your private key that way. It's possible there are many, many users affected and it is quite bad.
"Hacks" like this are not acceptable.