In this case, there isn’t much of a mistake to point out. I’ve seen a couple attempts from people trying the told-you-so routine using some arguments about multisig wallets as the only option, but mostly it looks like people are panicking and wondering if their choice of wallet has some undiscovered vulnerability waiting to be exploited. I mostly try to stay away from Bitcoin communities but in events like this it spills over everywhere. I feel sorry for anyone who lost coins, of course, but it’s also interesting to watch the communities grapple with reconciling their appreciation for irreversible key-based transactions with the realities of how this works when their money is on the line. The old ideas about having perfect OPSEC and being smarter than the other coiners are starting to get weakened with examples like this.
My guess is that the next phase is to revise history and form a consensus that Coldcard was never a recommended wallet and that it was obvious to everyone with good OPSEC at the time.
this is an inexcusable slop-y error that made me press close on the tab.
While no one knows if there might have have been earlier exploitation, the new exploitation just started and did not extend back to the vulnerable firmware release.
https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt
It doesn't appear that Coinkite, the company behind ColdCard products, had mature senior engineers in the loop. At least, no engineers who could flag such sloppy (and ongoing to this day) code commit practices.
chistev•9m ago
Or, given that previous hacks and losses didn't affect the price from shooting up to new highs, is this the perfect time to buy?