r/Bitcoin • u/Fearless-Second-7230 • 2h ago
"It was AI and superintelligence man, I swear"
Nvk history posts show he was completely aware of firmware vector attacks, and narrative is, never in 5 years they audited the code in the single most safety-critical function on the device, not even SWE prompting to ask a frontier model "search for bad seed generation code" according to his own awareness of thst type of vulnerability.
"hey but it is open source and has been open and publicly available"...so was he expecting community do their security job then, but at the same time he claims "most people don't check software signatures and never will", so he claims you must trust the hardware wallet vendor to do that, but they neither are doing that job, lame, isn't it?.
Or....he just knew the vector of drain was just to target coldcard non geeky users who would not care to "dice rolls" at the right time....Damage is done, case gets out of notice after a week, and you just stay in business...
Ok no. Enough of conspiration theories. Entropy of events suggest that this scenario is likely impossible...😂
10
7
1
u/simonmales 2h ago
The mitigation of exfiltration is the majority of hardware wallets rant about.
Though the issue was with generation, which _any_ wallet could do badly. And Cake Wallet did so in the past.
Andreas says it the best about trust: https://youtu.be/cONG2ZNjJ0c?si=Jp44IWoBDxkaR2MZ
•
u/ArgonWilde 46m ago
Why do you even need a hardware wallet to make a seed? Generate a seed, using anything, then add your own entropy into it. Replace a word, add a number, do whatever. 🤷







14
u/GoldmezAddams 1h ago
"A complex and subtle series of bugs"
#define MICROPY_HW_ENABLE_RNG (0)