Show Posts
|
|
Pages: [1]
|
I think most of us must have seen the news around Coldcard compromised, it was actually highlighted on the news section on the forum visible for everyone to see; coldcard compromisedI know many will be actually surprised because its primarily about hardware wallet which are considered safe but that is the reason why not all hardware are actually good for use. This coldcard wallet was initially an open source wallet but right now it’s a source verifiable, what this means is that you can check the source code to verify it but cannot legally use it on your project, what this means is that less developers will pay attention to it, because after all I can actually look into something that will be beneficial to me too. With few developers looking into it means less people finding the vulnerability or errors like randomness in creating seed phrases and this is clearly similar to closed sources too. How was this attack pulled off The attackers actually found a vulnerability in the RNG, that’s the randomness associated with the generation of seed phrase, we all know that the security of your wallet is basically on randomness and entropy which 128bits is just secure enough, so if your wallet software uses a weak PRNG generator it’s easier for attackers to actually find the vulnerability by getting a weak seed that is part or starts the generator and it’s around here that this coldcard vulnerability came from. Extent of the attack so far The attackers were sweeping addresses with at least 0.15 bitcoin base on the addresses posted running across 500 transactions, with total number of bitcoin stolen totaling over 1000 so far. What should you do 1. First instance will be to not trust hardware wallets to actually generates your seeds for you most especially closed source or similar hardware wallets and the best thing is to generate your own seed phrases either manually by picking the words yourself and allowing a wallet to generate the last word for you only for checksum 2. or use open source wallets like electrum in an offline environment before Importing into your hardware wallet 3. use passphrase which are strong enough or make use of multi sig with most co-signers if not all generating seeds as described above. This saves you from hardware wallet firmware attacks like this of coldcard 4. Test this wallet first and back up all seed phrases and passphrase properly. Who should be scared now I will say if you’re using closed source wallet or even hardware wallets like ledger which extract yours seeds for you phrase for recovery then you should simply sweep your bitcoin to a new wallet
|
|
|
|
Saw this a while ago on X (formerly twitter) that FTX has started disbursement of payments Is this true, For those who might have filed a claim and select a distribution provider? Recall that FTX had actually filled for bankruptcy in November 2022, which was reported linked to misuse of funds by founder Sam Bankman-Fried (SBF). Hopefully this is true because I could recall similar thing was reported for MtGox and I don’t think the payment has been completed yet. To avoid all this unnecessary lost of funds, one should prioritize self custody of funds, Not your keys not your coins
|
|
|
|
The chart above shows the relationship between Bitcoin vs Gold since the US/Isreal vs Iran war started which had affected the global market with the energy sector the most affected. Since the start of the war over over three weeks ago, bitcoin has gone up over 30% against Gold. Why am I bringing this stats? this is simply to remind newbies and everyone who might have read many bitcoin slander articles during the Gold bullish period early this year (2026) where it even got a new ATH at $5,000+ per ounce, when many haters or anti- bitcoiners accused bitcoin of not been a store of value, with haters like Peter Schiff even calling for dumping of bitcoin to invest into silver then. Now look at the performance of Bitcoin amidst the world crisis? What more can a store of value offer.
This thread isn’t about comparing bitcoin to any asset but stating clearly that bitcoin bearish moments shouldn’t be used to undermine its value and potential.
|
|
|
|
Many of us might have been seeing this circulating on X. In simple term this is an attack or say hack into one of the most trusted NPM developers account, this Node Package Manager is the biggest host for JavaScript Packages. So it was found out that through phishing this hackers injected a malicious code into the packages which are capable of compromising many applications including wallet extensions most especially those hot wallets, in fact there is reports that it has been downloaded over billion times already. It can simply affect all chains and isn’t selective. This does actually steals data but as an interceptor it can interact with affect apps and even changing things automatically. What is your business with this; Becareful with the kind of transactions you make and as usual check through transactions details before finally submitting it because this is the regular copy and paste address attack but it has the ability to change an address to another address if the application used is compromised. This again calls for the use of cold wallet because it is reported that the attack is capable of getting info from wallet APIs which could lead to seedphrase exposure for online wallets. This attacks also shows that no matter your knowledge you should extra careful still be a highly skilled developer like this was gotten through phishing attack from emails, so we all should be careful. This tells us to start embracing cold storage more
|
|
|
|
So of recent many people got there withdrawal suspended due to a potential poisoning address attack after receiving payment for rainbet campaign managed by Hhampuz, this is common with KuCoin exchange users what I noticed from the last week payment transaction fdf3ebb10508808c3cde9df6b99a3af60b2cb820020a993b6094f87f5e60471b was that it was flagged to be address poisoning as shown in the image due to two similar addresses in the output. The addresses are 1. bc1qg4arhl5fuep5tr9r2upplkj8qezur5hxnwxd8w belonging to *Ace* on spreadsheet number 12 and, 2. bc1qgralnxqcvmg335km595lh542vseqkf3flfyc8w belonging to ChocolateBitcoinK on spreadsheet number 20. *Ace* join the rainbet campaign from week 31 and with similar adresses as chocolateBitcoinK with both addresses having prefix bc1q and suffix 8w and both coincidentally receiving similar payment, the transaction involving them is tagged address poisoning. KuCoin exchange has actually suspended the withdrawal of funds from their customers who Recieved bitcoin together with this addresses In as much as we all know this was a coincidence nobody’s problem it shows that self custody should be adhere to seriously when receiving bitcoin. Most of us who used KuCoin and other exchanges to recieve payment need to take note that there are many risks involved because of some exchanges policy and it is best to use wallet and then probably move your bitcoin out from the wallet to exchange to sell. This is usually the best practice when Receiving bitcoin.
|
|
|
|
Just days after The US Treasury secretary Scott Bessent announced that the country which is actually setting up a bitcoin strategic reserve is not looking to buy bitcoin. With the intent of actually keeping the 200k bitcoin which is heavily reported to seized bitcoins in their possession as reserve. Just after that a blockchain analytics platform Arkham reported that $300k value of coins have been moved to the government account from coinbase and it was reported to be siezed from an Hacker Even though this is not bitcoin but is this the new method of which US are trying build their own reserve by holding siezed assets My question is; is this actually right? I think this assets are supposed to auction or sold off? Does Not buying bitcoin actually signifies that they don’t believe in bitcoin at all and are only fulfilling campaign promises.
|
|
|
|
|
So this thread actually comes out as a result of negligence from Access bank for Nigeria. The bank app; Access More has been down for close to four days now and there is still no solution for it, for people who actually uses this bank app for transfer they are left stranded except they have the physical card which some do not have.
Yes someone would say move to fintech as they digitally the best option now but still people get stuck with traditional banks because some employees accept only that for salary payments
Now my Concern is can a banking system not been able the address a problem for almost four days, will they simply just leave their customers stranded even those with emergency?
If it was bitcoin network or decentralized networks there is never such a thing, if one node goes down there are millions of nodes to propagate your transactions and there is nothing like a system upgrade which will take days to complete. For me decentralized networks are seriously here to stay
|
|
|
|
|
Bitcoin reaching new ATH and with possibilities of multiple ATH to come again there will be some investors who will be taking profit from their bitcoin investment. This shouldn’t be surprising or be discouraged by anyone, we all have different strategies in this market, some are taking profit because they wanted just 2x from the market some more. For me bitcoin is still at an early/mid stage and will increase in price as the demand and adoption increases, but that doesn’t stops one from taking profit base on their strategy.
But the real question is why are you taking the profit:
Some are taking profit to actually invest into other assets which is what we call diversification or to build their businesses which is a great idea as profits from this business can still be used to invest into bitcoin yet again. But are you familiar with this investment or business, if not why take profit.
Some can take out profit to either help to Carter for their needs like building or buy themselves houses if what they have now is a rented property or to renovate the property if it is theirs, certainly there is nothing wrong with this.
Why you shouldn’t take profit is:
1. Using the money to actually spend it on unnecessary luxuries (emphasis on unnecessary, as there is nothing bad to get some luxury for your self).
2. It is wrong to take profit and abandon it on fiat currency, that’s going from an asset with a store of value to one with devaluing characteristics.
3. Taking profit to actually invest into altcoins because there is predicted alt season coming with some Altcoins been rumored to be able to do 5x or more is a capital gambling which mostly results more into losses than profits. 4. lastly Buying Altcoins are not diversification means so do not take profit from bitcoin to buy Altcoins.
|
|
|
|
As seen from the image above, I went to check for bitcoin fees currently using the mempool.Space explorer and I found that there has been relatively too low transactions currently in the mempool such that some blocks mined contain few transactions only. This to me might be as a result of the market conditions which is currently consolidating. One of the advantages of these periods is you can simply consolidate all your little inputs into one such that you can have one UTXO and save fees later when the network gets congested later. Because each UTXO is treated as one input during bitcoin transactions Although the disadvantages of consolidating your fees is that it links all your addresses together which reduces privacy.
|
|
|
|
|
This thread is more like an onboarding thread for newbies as they are set to experience there first bull and also an insight thread for OGs
As this year begins we all know how the bitcoin history Dey take behave, the past trend na after each halving comes bull run, last year we bin don experience halving and now we Dey position to actually witness bull run.
How to get onboard
For me the easiest way is to simply buy the coins with huge potential and low risk and the coin that ticks this box is bitcoin. But that doesn’t mean I am against Altcoins too but as a newbie you’re better off with bitcoin than gambling ok Altcoins you have no knowledge about, that’s why you read posts from brainboss, CharlesTim and Igehh warning against Altcoins because there volatility is usually very high.
When to invest
The best time to invest has always been when the market is down or during dips, but is it ideal to wait for bottom? Personally I will say for bitcoin it is not advisable rather I will say one can DCA anytime they have funds and stay position for a longer time. Waiting for dip might be too risky because it may not come since there is no perfect prediction for bitcoin. As for Altcoins avoid buying the top there are you’re easiest way back to village.
When should I take profits,
This is one challenge that many newbies face, taking profits is simply base on your strategy don’t wait for too long most especially Altcoins, take profits when you have 2x, 3x or more, there is never a regrets in taking profit. Don’t go searching for 100x only few coins with high risk can give that now. As for bitcoin I will say I can only see it doing at most 2x from current position, my realistic target is 1.5x from here ($108k).
Security,
This is the most important aspect of investment, do not invest for scammers to take advantage on.
Tips for security are: 1. Be your bank by using non-custodial wallets; there are many wallets but my pick is do not go for closed source wallets or exchange in-built wallets. Avoid storing your coins on exchange.
2. have a very good back of your seedphrase or private key the most advisable means has always been prioritizing offline back up and never take your wallet keys on to the internet. Back them up in different locations for safety against natural disasters or hazards.
3. Avoid getting your wallet hacked through phishing links; this is the easiest way most people lose there assets, seperate your wallet storage from online devices. For airdrop farmers try as much as possible to have different wallets, scammers are working day and night to get your funds,
Avoid future/leverage trading,
As a newbie my advice is to avoid all this future trading because without knowledge they are the easiest means to liquidate your assets back to the market. I my self I am a trader but it is very hard to be profitable so take your time before diving into this niche.
Lastly bitcoin should be your save heaven for investment, have a portfolio with bitcoin taking almost 80% of it.
Start investing today, tomorrow might be too late
|
|
|
|
Today bitcoin reaches an historical high by breaking into the six figure value, 15 to 10 years ago only few people have actually predicted this historical landmark. Congratulations to everyone who got and witnessed this, now let’s ride this to a million dollars. The most frequently asked questioned by some investors is what happens to the lost bitcoin due to burning or losing seed phrase or private and the answer is that it adds to everyone’s value according to Satoshi which is a very satisfying feeling. One thing I found out is some investors usually have this mindset that all dormant addresses are lost forever, which is not true but most of these dormant addresses are simply long term holders who have set a price target or year to move them out. As bitcoin got to $100k today many dormant address started been active again by moving large amount of bitcoin out maybe to a safer wallet or to take profit. Which signifies that dormant address are not lost bitcoins
|
|
|
|
|
Yes this is just another thread on bitcoin halving but instead of speculating on the price I will like to warn newbies or probably members who are just experiencing their first bitcoin halving.
First the bitcoin halving only cuts the block subsidy which is also know as the block reward into halve (this time from 6.25bitcoin to 3.125 bitcoin) and nothing special or different changes again from the way the past blocks were mined. The size of the block and also how fees are calculated and payed are still the same.
Secondly which is for Naive newbies, there’s no special giveaway or airdrops that is accompanied with this event. Be very wary of scammers who ask you to connect your wallets to some sites to receive airdrops for celebration of the halving, it’s a phishing scam. I wouldn’t say other shitcoins won’t run airdrops but it will be risky to connect your wallet to any site for airdrops.
Thirdly Excess or high transaction fees payed in the past blocks are not returned to you after this halving, it is also scammer tactics to get access to your wallet.
Lastly Bitcoin halving doesn’t coherently means that the bitcoin price will skyrocket, yes base on past events they do go up some months after the halving, but that doesn’t mean you should go and invest an amount that you can not afford to lose. Past events are just speculations and do not reflect what will happen in the future.
Stay safe, accumulate your bitcoin and secure your wallet properly. May the pump be with us.
|
|
|
|
|
Just read through some multiple X handles now that Microstrategy’s X account had been hacked and tweet was done citing the claiming of the $MSTR tokens. As usual the link was a wallet drainer link and around $400k has been lost so far. Currently the tweet seems to have been deleted from the account but it’s deed has already been done.
There is daily continue warning of just clicking links as a bitcoin or cryptocurrency investors but yet many people actually continue fall victim for something I will say as a result of gullibility or greed.
The points from this phishing attack just like others is;
1. Make use of cold wallets; this shouldn’t be put on a second thought.
2. Do not trust any information from social media even if it is from an influencer account or an official account, verify, verify and verify your information.
3. If you are to engage on airdrops use a burner wallet at all cost.
|
|
|
|
The record breaking high transaction fee of 83 bitcoin paid for a transaction of bitcoin which the block was mined by Antpool had earlier reported here which was found out to be a hacked wallet due to weak randomization of seed has been after a tweet on X. Now the pool that got lucky to mine the block in which is AntPool is ready to return the excess fees. Although it is not mandatory to return the fees but they are willing to return it. Now the procedure is to just sign a message using the private of the sending address. The procedure is as explained here by AntPool with deadline set to 10 December. My problem or say concern is what if the hacker is still in possession of the keys and ends signing the message. Should Antpool decides to be careful and send the excess bitcoin back to that address as any new address collected by them might also belong to the hacker and in sending it back to the address again what if the sweeping malware is still on the address and the bitcoin is immediately sent out again to the hacker new address is there away for the network to block this kind of immediate transaction again from that same account for the main time. Just like double spending sometimes is rendered invalid by most nodes. If you’re the owner and you are not if the private key is with the hacker and they could use it to Sign the message what will you do at this moment?
|
|
|
|
As we all know the transaction fee continues to get high as the mempool remains congested for almost a month now due to reoccurring ORDI tokens on the bitcoin blockchain. This has left some people a bit furious and some newbies making costly mistakes of setting high transaction fees. A transaction that was in block 818087 had actually paid a whopping sum of 83 bitcoins as the transaction fee. I would say this is a costly mistake but for someone having that huge amount of bitcoin in their possession I don’t get it. The transaction was first broadcasted with a fee of 70 bitcoins and then later was replaced with that of 83 bitcoin as fees. My guess is the sender was probably trying to set is fee as 70 and 83Sats/vbyte and then mistakenly set out that high fee. The block was mined by Antpool, hopefully they would treat it as mistake and return the funds. 1. TXID for the 83 bitcoin fee: b5a2af5845a8d3796308ff9840e567b14cf6bb158ff26c999e6f9a1f5448f9aa 2. The replaced transaction ID: 0c35f3c8a0c38f45629940ee9ab2b1c93d408be113845a735043261ad20f3351 Advice to newbies check properly the amount your setting as fee and make sure you are looking at the right fees estimator, use wallets that allows bumping of fees in case you set a very low one
|
|
|
|
Woke up this morning and was going through some threads and wanted to merit a post. My intention was definitely to send 2 merits because to that post and then got carried away and mistakenly sent 22, I didn’t even notice until I saw my smerits drained, yeah it is ok to spend all smerits but definitely the amount to be sent should match the content of the posts. My reason for this post is shouldn’t we have something like a second warning when the confirm button is clicked, like ’are you sure you want to send this amount to so so’
Secondly shouldn’t we have a patch on editing merit sent even if it is for a specified time like how the edit button doesn’t reflect edited when it is done immediately the post is made. PowerGlove is there a way to go round this? Definitely pained to have wasted all my smerits on a single post.
|
|
|
|
Just like not your keys not your coins is repeated on the forum, it seems sim swap attack warning/awareness needs to be spread as such. It is not news again that co-founder of Ethereum Vitalik Buterin had his twitter(X) account hacked. This lead to a phishing link been posted and many lost their funds. Now Vitalik himself has come out to said the attack was through his T-Mobile phone number by sim swap and the hacker got access to his X account through requesting for the authentication through phone number. Vitalik prostrated that he didn’t take the security warning about sim swap serious if not now. The takeaway is avoid taking authentication through phone numbers alone, but if we look at it accepting authentication through even E-mail is risky so the best act is to avoid storing funds on platforms that requires this. How to know if your phone number has been swapped. 1. When you notice your network is no longer available 2. When you receive a notification from your network provider about a change of sim 3. When you can not have access to your social media accounts or any online accounts accounts again. Once you notice one of this then you need to act fast
|
|
|
|
|
Bitcoin main purpose according to Satoshi himself, is as an alternative payment to fiat currency. But over the years bitcoin has grown in such a way that many have seen it’s potential of been a great investment asset. This could be deduced from some of the advantages of his below; 1. Decentralization 2. Stores of value 3. Great Return on Investment 4. Fixed Number or Supply 5. Adoption rate.
Due to all these advantages some people have not only taken bitcoin as an investment asset but have generalized it to other cryptocurrencies as well. Some have thoughts that investing in these alternative coins are actually diversification of one’s portfolio. But is this really portfolio diversification?
Diversification of portfolio can be termed the process by which investors, invest in different assets to mitigate a loss been encountered in a particular asset.
Alternative cryptocurrencies cannot be regarded as diversification of portfolio because; 1. Most of all the altcoins follow the same price trend as bitcoin, with just few going higher than it due to hype, which has made many to call them pump and dump coins.
2. Bitcoin is the only true decentralized cryptocurrency and as such eliminates the fear of centralization which is in many altcoins which could be use to manipulate its market.
3. Bitcoin supply limit is what makes it a store of value and also an hedge against inflation, giving it an edge ahead of other cryptocurrencies.
With all these and more, and most importantly the fact that bitcoin price change is actually been followed by other cryptocurrency which are not secure, makes them more risky to be used as an investment asset.
It will be better to look into other assets like stock, gold and real estate for an ideal portfolio diversification
Aside bitcoin, treat alternative cryptocurrencies as pump and dump coins that they are.
Note: I am not advising anyone on investment
|
|
|
|
|
I have found and read through numerous threads on the forum about the spreading of bitcoin awareness and adoption by many forum members. Two of the widely used methods from this threads that I have read are; Class room teachings and using bitcoin as a payment method for ones business. This is a great way to increase bitcoin adoption spread to others, but isn’t this done at the detriment of the advocate’s safety and privacy?
One of the main aim of bitcoin from its inception by satoshi is not just to protect our money but also to protect the user. Therefore by spreading bitcoin awareness in countries or communities that it’s government are against it, should be done cautiously. Because once the government decides to take strict actions against the users, some of the advocates that spread it publicly or use it in their businesses will easily be traced and could be convicted for breaking the law, and I don’t think even Satoshi will appreciate that.
I feel like bitcoin should be spread in these kind of communities secretly and cautiously to avoid exposing our privacy and hampering our security. It should only be thought to people that show interest and not going to schools to teach them because that is like breaking the laws of the community or country, and bitcoin or Satoshi himself is not have law breakers or criminals as it’s users or advocates just like how the media and government portrays it.
So before spreading bitcoin awareness, first of all take care of your own security First. If you can then leave the advocacy for that period. Bitcoin Uniqness will surely pave way for itself like it has been doing through the years.
|
|
|
|
After so many weeks of struggling to allow withdrawals Paxful has officially suspends its marketplace and has advice it’s customers to withdraw their funds immediately from the exchange. This is definitely a bad news to many especially Africans who were the major customers on this exchange. Is this the right time to ditch Centralized exchanges for decentralized one’s totally? https://twitter.com/pledditor/status/1643243489528889348?s=46&t=QdZ3_ryvESgybupE3D6xaQ
|
|
|
|
|