The fact that we do _not_ need an hardware wallet, was the lesson learned from the @COLDCARD shitshow. Today is @Trezor , tomorrow it will be someone else. You do not need an hardware wallet if you are just hodling.
đź”” This profile hasn't been claimed yet. If this is your Nostr profile, you can claim it.
Edit
The fact that we do _not_ need an hardware wallet, was the lesson learned from the @COLDCARD shitshow. Today is @Trezor , tomorrow it will be someone else. You do not need an hardware wallet if you are just hodling.
Those ~70 bits make a real difference. They push bruteforcing from “trivial” (MK3) into “painful but still theoretically possible.” The entropy remains weak, just not catastrophic. Has anyone actually cracked an MK4 using a seed that was generated on the device itself (not imported)?
After a full dive into Mk4 today: Mk4 keys are not enumerable like Mk3 keys at all. Thanks to the reseed, it’s basically impossible to bruteforce them even, if they have weak entropy. When correctly set up, the private keys are so secure that they remain effectively uncrackable,
About the Mk3 draining, attackers can choose different "cones" to look into for wallets to hack. The weak Yasmarang RNG value is determined by a small state (pad + chip/mixer skip history). A "cone" is just a hypothesis about that history, e.g: first boot vs later login vs weird PIN session. Each cone is a slice of skip/space. Wrong cone → almost no hits. Right cone → mnemonics become enumerable. That’s why wallets can still sit unexplored in other cones. The attack can go on for years and still find utxos
I remember Jimmy Song writing, on the first day of Ordinals: “The first one that forks loses, and they (the spammers) will surely fork.” What I’m witnessing three years later feels like a lysergic experience. People I once thought were smart now look like completely unhinged madmen.
After carefully analysing and testing the @COLDCARD rng bug, I am quite sure the attacker(s) knew about the bug already and spent weeks if not months to enumerate some vulnerable wallets. The whole enumeration did not take 3 days (the delta between Kimi K3 release and the attack)
Let’s imagine we successfully activate BIP110. Currently, the majority of spam comes from tiny OP_RETURN transactions that won’t be filtered out by nodes running BIP110. So what this fork actually tackles is: - The `if (false) { ...data }` inscription envelope - Large OP_RETURN transactions. Given that large OP_RETURNs are already rare and inscriptions have been mostly dead for the past two years, what happens the "day after" the fork? We’ll likely see a new wave of inscriptions using a different envelope, paying more or less the same fees as today (since you can still get into a block for 1 sat/vbyte). What did we actually achieve? This is what I mean: spam is garbage and spammers are pieces of shit, but we need to reason logically rather than emotionally. What did we achieve other than proving we wasted time while spammers continue to mock us by spamming without any real disruption?
Stripping the emotion from the 110 fork debate, the proposal is technically useless. No protocol should patch one specific issue that can be replicated countless other ways. We have far bigger problems focus on what actually matters.
How to defeat the newly created Bitcoin cartel? - Keep pushing SV2 & Datum - Plebs running their own nodes
https://x.com/wk057/status/2077444826232955365
Instead of buying dice on Amazon, go to your local boardgames store. These guys will have amazing choice, dice that FEEL (and look) great, and they don't need to know where you live. Support your local game store.
Taproot Wizards - gone BIP110ers - gone Everything is going according to plan.
mistakes by 110ers: arguing nodes control protocol changes and miners will capitulate. subtly wrong. the economic users control the protocol, via the market. they transmit their views by transacting with their economic nodes. 1000s of nodes with no economic use have no influence.