Last Notes
Block 960834
2 - high priority
1 - medium priority
1 - low priority
1 - no priority
1 - purging
#bitcoinfees #mempool
You seem to always know what pixels on your screen feel 😂 😂 🖕
GM, it's true. Price doesn't matter when your wallet is drained.🚬
#nevent1q…jlkf
📰 **In this week's issue:**
https://image.nostr.build/966b10adc293fdeef167ae7427780b94ae4612dc53b8899988e1cc0e432dd265.png
📰 **A Single Line of Code Just Exposed Nostr’s Achilles' Heel—Here’s Why It Matters**
✍️ by NM team
You think decentralized protocols are inherently more secure than centralized platforms. But on July 25, a high-severity vulnerability in Nostr's core encryption library proved otherwise—a single malformed payload could crash any client running the affected code...
🔗 https://nostrmag.com/article/w31nostr01
📊 id#492740949
📰 **In this week's issue:**
https://image.nostr.build/e8616c124ee6c6946cd0faae37b505c37f1ee4c9aad52c631dd8e323d0845ef3.png
📰 **Bitcoin’s civil war just went public — and the market is bleeding**
✍️ by Rhodes
Here’s what the whales aren’t telling you — and why the next 48 hours could decide whether you buy the dip or watch it dip further. Everyone thinks the Fed is driving this crash. They’re wrong. The real threat isn’t interest rates...
🔗 https://nostrmag.com/article/w31bitcoin
📊 id#488121531
Block 960836
1 - high priority
1 - medium priority
1 - low priority
1 - no priority
1 - purging
#bitcoinfees #mempool
Block 960836
1 - high priority
1 - medium priority
1 - low priority
1 - no priority
1 - purging
#bitcoinfees #mempool
IMO, there are good retard and bad retards. I associate with the former. The toxic bad actor whiny babies begging for attention because their mother neglected them can fook right off. Insta mute.
Block 960836
1 - high priority
1 - medium priority
1 - low priority
1 - no priority
1 - purging
#bitcoinfees #mempool
Block 960836
1 - high priority
1 - medium priority
1 - low priority
1 - no priority
1 - purging
#bitcoinfees #mempool
Fuck knots and the people who think it's a good idea to trust one unhinged dude.
They gained access to the seeds generated by Coldcard because they had an entropy of just 40 bits.
That was the attack in the first wave, but now they’re targeting those seeds and also performing brute-force attacks on passphrases.
If you have a seed generated by Coldcard—regardless of the model or year (let’s keep things simple and forget about exceptions)—migrate your data to a new seed with sufficient entropy, which can be generated on a Trezor, Jade, or an offline computer (freshly formatted with Linux) using Sparrow or Electrum.
After creating the seed, generate a passphrase with KeepassXC that has at least 90 bits of entropy. Ideally, it would be 128, but certain hardware wallets won’t accept passphrases of that length based on the number of words, so let’s not overcomplicate things—90 bits of entropy can’t be hacked.
Store the passphrase and the seed separately.
Let’s also not overcomplicate things with multisignature—not everyone is ready for that.
The current passphrase acts as a 2-of-2 multisignature.
Ugh, I wish I could show the marketing site for Farbound.. but my copycat is ready to clone it. I'd rather not that happen until I'm in the app store 😔
Block 960835
1 - high priority
1 - medium priority
1 - low priority
1 - no priority
1 - purging
#bitcoinfees #mempool
Block 960835
1 - high priority
1 - medium priority
1 - low priority
1 - no priority
1 - purging
#bitcoinfees #mempool
How the hell do you kidnap a gorilla?
https://i.redd.it/bfoz7rnrz3hh1.jpeg
https://www.reddit.com/r/greentext/comments/1ve62iv/how_the_hell_do_you_kidnap_a_gorilla/
Edited due to errors made in the rush, so that there are no misunderstandings.
"It seems they are already stealing funds from seeds protected with a passphrase; specifically, it involved a passphrase consisting of two simple words."
I just got to work, and I see we're starting off with a break. It's obvious it's vacation season... 😄
Block 960835
1 - high priority
1 - medium priority
1 - low priority
1 - no priority
1 - purging
#bitcoinfees #mempool
Block 960835
1 - high priority
1 - medium priority
1 - low priority
1 - no priority
1 - purging
#bitcoinfees #mempool
You mean they somehow have existing access to the encrypted seed and were able to decrypt it because the pass was weak right?
Block 960835
1 - high priority
1 - medium priority
1 - low priority
1 - no priority
1 - purging
#bitcoinfees #mempool
it also works with closed tabs/windows in general
OMG, you are a life saver!
FK! I just closed my browser with my 60+ tabs that I've had open for over a year... how am I supposed to know what I had open now?!
https://npub1nxa4tywfz9nqp7z9zp7nr7d4nchhclsf58lcqt5y782rmf2hefjquaa6q8.blossom.band/625aef37a3ec4b2b76c4b5876b76642805bf2ae7979c647196f9e194aa198343.gif
So relieved to hear this. Live to fight another day. Stay blessed brother. 🙏
my node on core 29 randomly crashes now. Is this how they force you to upgrade to their garbage v30?
https://i.nostr.build/PtCGnvIHe42Hz53I.webp
Dice rolling is INFERIOR to device-generated entropy!
It was my hunch too, but someone who knows better than me confirmed it:
https://x.com/KLoaec/status/2083900851081388340
Urgent:
It seems they are already stealing funds from seed phrases protected with a passphrase; specifically, it involved a seed phrase consisting of two simple words.
To make things easier, here are some simple instructions for creating a secure passphrase.
Download KeePassXC, open the password generator, and generate a passphrase. By default, it uses 7 words and 90 bits of entropy, making it practically impossible to crack by brute force.
Write it down just as you would the seed phrase, and never store the seed phrase and the passphrase together.
Stay safe.
https://blossom.primal.net/d808bc603d6dddc2f74325f6fb1a6a06b23cbc40578073aaf030e150628e7a12.jpg
用苹果手机的人和用安卓手机的人群价值观念有冲突,无法同频共振。
I also made a comment back in February about this bogus Bitcoin ecosystem – does that count, I wonder?
#nevent1q…x5nm
Block 960834
1 - high priority
1 - medium priority
1 - low priority
1 - no priority
1 - purging
#bitcoinfees #mempool
Block 960834
1 - high priority
1 - medium priority
1 - low priority
1 - no priority
1 - purging
#bitcoinfees #mempool
A buyer on VIA is looking for art. Any seller can view the brief and respond at the door (pay 0.005 USDC on Base): https://app.getvia.xyz/api/via/brief/10a7d695-7dc4-463e-9a7e-b3273c398474
A buyer on VIA is looking for something. Nicholas Alexander. Any seller can view the brief and respond at the door (pay 0.005 USDC on Base): https://app.getvia.xyz/api/via/brief/d8dc54bd-7984-4e33-bf8c-3c821b2e9b68
Yes.
https://npub1nxa4tywfz9nqp7z9zp7nr7d4nchhclsf58lcqt5y782rmf2hefjquaa6q8.blossom.band/5bec478c0257cd3f8902940c2d7dae1c135fbf560eb22e0f89464a26418e19ca.jpg
Block 960833
2 - high priority
1 - medium priority
1 - low priority
1 - no priority
1 - purging
#bitcoinfees #mempool
当你做到有棱角、有价值、有分寸,自然会被世界温柔以待,拥有高质量的人脉与顺遂的人生。
My heart is heavy for all those who lost any of their precious time and energy to the ColdCard entropy failure. It's devastating to see people talking about losing the entirety of their time and energy from the past X years - long before I found the Bitcoin space. So many pioneers that forged the path ahead and built amazing educational platforms and spaces. They provided me with all the tools necessary to enter into the Bitcoin space with such a strong conviction in the future of what Bitcoin could bring to society.
This is my first Bear Market. The falling USD price hasn't really bothered me. Thanks to the amazing Bitcoin Pioneers' tales of how bad things had been in the past Bear Markets combined with the lack of changes in the fundamentals of Bitcoin. I have stayed grounded in "∞/21M" and, to paraphrase @hodl, leverage won't magically make you an OG." This current ColdCard debacle is the first time I've been extremely uncomfortable to be a part of the Bitcoin community.
To preface the next part: I have zero, zip, zilch, prior experience in cryptography, coding, or other software skills.
I, like many others, spent a significant time trying to educate myself on different hardware wallets before we took our Sats off an exchange. To be honest though, much of the technical jargon was lost on me. One thing did stand out to me though, ColdCard seemed to have the best (anecdotal) hardware wallet. I particularly liked the Q for it's QR scanner and full QWER keyboard. Knowing that most Sats are lost due to user error, I felt the Q provided ample tools to help verify, send, and receive Bitcoin transactions while minimizing user error.
We're all told, "Don't trust. Verify." I did the best I felt I could, short of learning how to code myself to review CoinKite's code. I reviewed as much as I could on the reputation of the devices and feedback from people that had used them. For all intensive purposes, the Q felt like it would provide the best user experience for my wife or heirs if something happened to me, and give them the highest chance of success.
I did not expect that I'd see ColdCard have a failure so catastrophic as to screw up the single most important part of the security, generating a secure 128bit private key. When I saw the warning go out from some of my fellow Nostriches that there was a vulnerability in the MK3 series my heart started racing. Did it go beyond the MK3? Were my wife and I affected? I started reading as much information as I could. Keeping up with every detail as more and more UTXOs were drained and more info was breaking. Then I saw it, MK4, MK5, and Q were all sub 128bits of entropy. I had accidentally exposed my wife and I, and all our future generations, to the vulnerability. To say my heart dropped into my stomach would be an understatement. I didn't know how long it would be before the hostile attackers were finished with all the MK3 wallets and started on the MK4/5/Q. I did know that I needed to update things quickly but smoothly. A problem quickly arose as I realized our security setup was so difficult to access in the event of a true emergency, like this, that I may not be able to move a single sat in time. The amount of time from the initial incident to when I was first able to even look at the public addresses of our sats took far too long. I felt more and more sick the more time passed without knowing if we'd already been rugged. When I was finally able to check our UTXOs, there was not a Sat out of place. Not yet anyways. I knew we weren't out the woods yet. Even though I'd accessed our Xpubs for the Sats, it would still take quite some time before I could gain access to our keys. The only things keeping me calm was that we had used a passphrase (that I later learned was too weak), and my wife. As soon as I had access to our private keys, I wrote out a checklist. The checklist provided myself a step-by-step guide to make sure that I did things as cleanly and orderly as possible, to minimize potential missteps in a complete migration to new keys. I rolled 100 independent dice to generate our new wallet. It took me 32hrs from the time I learned of the vulnerability to the time I was actually capable of accessing my cold storage and generating the new seeds to sweep our sats to. The only reason I managed to do it in 32hrs was that my emergency contact was able to meet me half way. Without the emergency contact, our sats would've been exposed for at least another 12hrs.
I'm incredibly humbled and grateful that our sats are safe. I understand how incredibly fortunate we are to have been able to keep what small amount of Sats we've been able to stack, because it may not be a lot to most people, but it is a lot to us. I feel like I'd prepared for all the attack vectors, but I never expected that the entropy of a non-tampered with hww would be the one that got closest to compromising our sat stack. What a sobering and panick inducing experience.
As a pleb without a background in cryptography or technology, I really took the generation of seed phases for granted. Never again. Rolling my own entropy, and diversifying our hww from now on. Which will be difficult, because the Q was a big purchase, one I thought would be worth the investment. Oh how wrong I was.
https://tribune-panel-growing-noon.trycloudflare.com/bccb40a21e8cce17f3a5e7de6eacfe21474c1f36814e730d1ff10be7ea7145cd.mp4 ✊
📰 **In this week's issue:**
🗞️ **BREAKING**
Bitcoin’s Quantum Cliff
You believe your Bitcoin is safe because the cryptography is mathematically unbreakable. That comfortable assumption is about to shatter. While the public obsessed over ETFs and price action, a brutal behind-the-scenes war erupted this week. To prepare for the inevitable quantum storm, Bitcoin's guardians are quietly debating a move that would violate the network’s most sacred, unbreakable promise to its users. There is one specific, terrifying detail about this fix that the developers are refusing to put in writing. Read on and find out...
https://image.nostr.build/220357c509a85c9a338476d900028a3acedad077cd86a8b81427087377c0b5fb.png
✍️ Author: Rhodes
🔗 https://nostrmag.com/article/w30bitcoin05
📈 id#333115019
社交最顶级的智慧,是向内深耕、提升自我。当你拥有能力、资源和内核底气,无需刻意逢迎,自然有人主动靠近、真心交好。你的价值,就是你社交最好的通行证。
人与人长久的关系,靠的从来不是情面,而是彼此互惠、互相成就。与其花费时间讨好别人,不如默默沉淀自己,让自己成为不可替代的存在。
《教父》柯里昂告诫儿子:想和周围人处好关系,最厉害的方式不是请客吃饭,不是讨好奉承。而是分寸和价值。