Tl;dr: I think the Coldcard exploiter will be caught, but I don't think victims will be reimbursed. --------------------------------------- Apparently you need minimum 64 GPUs (properly connected) to run Kimi K3. If the coldcard exploiter used this model they would have had to have a very sophisticated institutional setup (maybe there are black hats out there that have managed to construct this?), otherwise would have had to use a service. This means it's likely that they could be found if authorities worked with model servers ... although most likely it's China based? Sounds like USA frontier models wouldn't have allowed a user to discover the exploit, so probably wouldn't find them by getting a warrant with those labs. But I also read that one of the block explorers confirmed they have a paid user account that was doing a bunch of lookups that matched the exploiter behaviour and they intend to work with authorities? I'm thinking it's probably decent odds that they're caught. Maybe they weren't even a full time criminal - possibly someone who had the idea to try it but hasn't taken a lot of other privacy precautions. Much lower odds of people getting their funds back. If anyone has the ability to recreate the exploit then they could pretend to claim possession of the private keys. Not sure how you'd verify :/
This is definitely specifically a fuckup by Coinkite, but worth pointing out that a RNG being ineffective or compromised was a well known risk - dice rolls, passphrases, multisig were all mitigations. Even though I use a coldcard, I've never recommended it to a normie who wasn't going to set it up properly (verify firmware, use dice, air gap etc.). I'd sooner recommend Muun or Blue Wallet, and these days I'd say Bitkey. Maybe that's one of the lessons - influencers and Coinkite themselves should have more explicitly steered users away from the quick but risky setup.
Probably too soon to say, but this is good for Bitcoin. Few.
Damn. Probably Odell's worst take. I can see where he's coming from in terms of user error, but he massively underestimated Coinkite risk. I'm sure he's sorry about that advice and will be taking this situation very hard.
Why would you design a seed gen system to fallback to a low entropy RNG instead of rather giving an error?
Tfw you haven't had your node online for a while so you're waiting for the blockchain to sync to find out if you're poor or not
I advise keeping a journal with pen and paper, and not on your work computer
Hosepipe ban now for Thames Water customers. I just use the same water but via waterering cans. All this state monopoly has achieved is make my life more inconvenient - how unusual.
I'm usually not allowed to wear them in public, but had to take the baby for a walk and managed to sneak past the wife. It was like I'd become my true self for a bit.
Yeah it's definitely good marketing for institutions. But also will force better practices and scrutiny of hardware.
Oh I'm just being boring and sensible by proposing something ultra retarded. CGT should be 0%. It's a tax on savings. They always make it sound like billionaires are the only ones with savings. They'll probably find a way around it and the rest of us will be paying CGT on assets that went up in $, but went down in real value.
Thank god for https://coldcard.com/docs/paranoid/
This post addresses that question: https://www.tftc.io/coldcard-rng-failed-move-your-coins Probably okay, but if like me, you can't remember the exact dice process then maybe prudent to move to a new seed. Just be slow and deliberate and don't panic I guess.
Welcome to gunson spacestr profile!
About Me
Low status fiat heretic. Often wrong. 2 + 2 = 4
Interests
- No interests listed.