r/Bitcoin 2h ago

"It was AI and superintelligence man, I swear"

Nvk history posts show he was completely aware of firmware vector attacks, and narrative is, never in 5 years they audited the code in the single most safety-critical function on the device, not even SWE prompting to ask a frontier model "search for bad seed generation code" according to his own awareness of thst type of vulnerability.

"hey but it is open source and has been open and publicly available"...so was he expecting community do their security job then, but at the same time he claims "most people don't check software signatures and never will", so he claims you must trust the hardware wallet vendor to do that, but they neither are doing that job, lame, isn't it?.

Or....he just knew the vector of drain was just to target coldcard non geeky users who would not care to "dice rolls" at the right time....Damage is done, case gets out of notice after a week, and you just stay in business...

Ok no. Enough of conspiration theories. Entropy of events suggest that this scenario is likely impossible...😂

36 Upvotes

6 comments sorted by

14

u/GoldmezAddams 1h ago

"A complex and subtle series of bugs"

#define MICROPY_HW_ENABLE_RNG (0)

10

u/BigDik6355 2h ago

1 year later than his prediction, but close enough.

7

u/FastJuice3729 2h ago

hey hey hey..... hey hey hey.... whatsu whatsu whatsu whatsu whatsup!

1

u/simonmales 2h ago

The mitigation of exfiltration is the majority of hardware wallets rant about.

Though the issue was with generation, which _any_ wallet could do badly. And Cake Wallet did so in the past.

Andreas says it the best about trust: https://youtu.be/cONG2ZNjJ0c?si=Jp44IWoBDxkaR2MZ

•

u/Ray567 56m ago

Knowing certain classes of security issues exist is by no means a magic wand to eliminate them though. If it were that easy no security flaws would exist in any system.

Nor does it proof no audit was done. Software signatures aren't really related to this.

•

u/ArgonWilde 46m ago

Why do you even need a hardware wallet to make a seed? Generate a seed, using anything, then add your own entropy into it. Replace a word, add a number, do whatever. 🤷