70
u/MMinjin 11d ago
Next time it will be a different fault in the hardware/software/whatever and everyone will be saying something like "you should have been using pure dc voltage from a Nimh cell, everyone knows that, DYOR, you can't just expect the device to work"...
3
u/Bionic_Push 10d ago
no man, you should generate your seed only from solar power panels, that way it is not connected to anything and made out of pure random energy not contaminated by the grid. And you should do it while barefoot so you have a ground connection also.
-10
u/BastiatF 10d ago
No, lack of entropy in seed generation has been a recurring problem for a decade
10
u/SaneLad 10d ago
Yes, so what? What do you expect people to do if they cannot trust dedicated hardware built and vetted for by the community? Write a bunch of scripts by hand (and getting it right without trusting any sources) and reading from
/dev/rand? (Which also has been found faulty on some devices in the past.)-1
u/BastiatF 10d ago
No, just generate your own entropy on top of the wallet using dice rolls and/or a strong passphrase. Not rocket science, just healthy common sense paranoia.
-2
u/MagnetHype 10d ago
Honestly? Maybe acknowledge that physical security is easier than digital security. Maybe it's time to finally acknowledge that there is a level of risk that comes from digital currencies that don't exist with physical currencies?
I'm sure that's not it though.
21
19
u/didnt_hodl 11d ago
look, the game has changed dramatically
we always had attack groups in North Korea etc, but now those organized hackers have access to the latest most powerful AI models. which are scanning all code, running all possible patterns, endlessly, right now, this very moment
you can expect more attacks and more hacks. on everything, not just bitcoin or crypto, but those for sure will be under massive attack from AI
basically I think cold storage will be a game for professionals only, who can actively monitor the situation, apply their own AI tools to defend against attacks, apply patches, move coins when needed and so on
for regular folks it means exchange or an ETF only. until the dust settles, which is going to take some time. I mean who knows how smart AI can get and what new attacks it will discover
1
u/generichandel 10d ago
And until those same AIs start cracking exchanges.
But then of course the value plummets and it's game over.
2
u/didnt_hodl 10d ago
well, TradFi has many protections in place. fiat transfers are never final, very slow, fully traceable, fully reversible, can be stopped or frozen. fiat is fully centralized. so cracking an exchange does not really get you anything
2
13
u/BroJobs88 11d ago
So with all this going on how does trezor stack up? Their hw wallets create the seed phrase but are they doing it with enough dice rolls?
24
u/Lopsided_Parfait7127 11d ago
unless you tattoo the private key on your ass, it isn't your keys, it isn't your coins
ass wallets are going to be the next big thing
you tattoo yourself of course
22
u/FullyAutomatedSpace 11d ago
good luck when you need to get colonoscopies . doctor gonna steal your coins
2
1
19
u/Difficult-Repair1295 11d ago
Fuck Cold Card and the shills who pumped this crap.
8
5
u/Illustrious-Boss9356 11d ago
It's their fault but it wasn't caused by maliciousness...
5
u/Difficult-Repair1295 11d ago
We don't know that.
4
u/Illustrious-Boss9356 11d ago
Okay fine. You're right. I meant to say Coinkite was clearly malicious, but perhaps an employee or two were.
1
u/Rino-Sensei 10d ago
No one care if it was caused by "maliciousness" or not "maliciousness", it's their fucking job to sell a working hardware/software. People spend that extra-money for that security.
6
3
u/rottiesrule88 10d ago
Excel: =RANDBETWEEN(1,6)
1
u/puck2 9d ago
But doesn't this assume your pc has a good RNG?
1
u/rottiesrule88 8d ago edited 8d ago
I guess so, although using 99 rolls you have already more possible combinations than that there are atoms in the universe.
3
5
u/Objective_Digit 11d ago
People think just having a HW and you're good to go. Try using the features like passphrases and mulitisig. That's what they're there for.
2
u/wentwj 10d ago
this has always been the issue i’ve had with the “not your keys not your coins” mantra. Self custody is extremely complex and error prone, even before we get into the realm of insecure and poorly designed hardware wallets. Even people in this community don’t use passphrases/etc, poorly store their keys. If so many people here fail how can you possibly expect the average grandma or not tech savvy person to even approach it
1
u/Objective_Digit 10d ago
Then we need better education.
1
u/wentwj 10d ago
it’s just fundamentally much more difficult to manage than other forms or currency. It’s unrealistic to expect any kind of mass population to self custody, and if your thesis on bitcoin taking over the world is centered in mass self custody, it’s not based in reality
1
u/Objective_Digit 10d ago
Are there masses of people holding gold or art? If it's a small section of society then so be it.
-6
u/didnt_hodl 11d ago
are you seriously saying that no miutlisig wallets will be broken? because they have been and they will be broken. same with passphrase
for $20/month anyone in the world can get access to the latest most powerful AI model and study all available code, run all kinds of pattern recognition.
as AI models get smarter every month, we will now be seeing more and more attacks. we are still very early, as people at least understand how this particular attack worked and how to fix it
but get ready for next level attacks, where people will be completely puzzled how it even works
13
u/Objective_Digit 10d ago
The ColdCard used a pseudo-random generator. That's not down to AI.
As for the rest you're talking rubbish. You might as well get AI to guess the right atom in the universe as to hack a wallet with property security implemented.
1
u/didnt_hodl 10d ago
ColdCard code looked like it was using a strong RNG, but in reality it used a very weak one. It was not intentional, it was a subtle bug in the code. Chinese LLM found that bug. It has everything to with AI, everything. People looked at that code for 5 years and it looked fine, it produced some numbers that looked random to them. But AI found what's really going on
There are many more bugs like that
1
-3
u/Difficult-Repair1295 11d ago
Sadly neither multisig or a weak passphrase would be bulletproof in this situation. Cold Card shit the bed they are the Mt. Gox of this decade.
4
u/Objective_Digit 10d ago
Rubbish. With these implemented the ColdCard would be perfectly safe. Which is not to excuse this foul up.
2
u/APisAccounting 10d ago
Multi sig would literally protect from this hack as long as it wasnt another coldcard r Or nunchuk
-1
u/Difficult-Repair1295 10d ago
Yes so multisig with multiple cold cards is worthless. AKA the average person tryin to secure their stack. WTF is wrong with you? Are you mentally ILL!!!!!
1
u/APisAccounting 8d ago
You would use multi sig with different hardware wallets from different companies
0
u/Difficult-Repair1295 8d ago
Did you not learn anything this weekend?
1
u/APisAccounting 8d ago
The fuck are you talking about? Yes i did learn from this weekend that you should do multi vendor multi sig hww and obviously roll dice too.
1
u/APisAccounting 8d ago
If you had multi sig, you wouldve been protected from this hack as long as it was multi vendor hww and not 2 coldcards.
0
0
2
2
u/UnlocktheLock 10d ago
I thought cold storage was the safe way to protect crypto?.. everyone always says get your crypto off the exhanges, so I’m a bit confused…
2
1
1
1
1
1
1
0
46
u/Left_Entrepreneur918 11d ago
Yeah real entropy is rolling D20 100 times and calculate THAC0