EDIT: Looking at my self-custodied BTC wallets since months again today, everything is still fine, by the way.
this really shook some people up it seems
i mean yeah im rather laid back and lazy and such.. but i still havent checked my trezor balances. and if youre not really really confident in how this all works, dont do self custody. thats long been my take.
that being said cold card hardware and design seemed pretty good. sucks for those that got burned (read someone lost 18 btc.. ouch).
True randomness is hard to find, but totally worth it.
yup, casino dice here
I am and have been a pretty BIG advocate for both getting started and learning through experience, and so many of us know that mistakes will be made, yet at the same time, we don't want the mistakes to result in years and years of our labor and/or efforts, so there can be a bit of a dilemma in regards to learning through experience.
I recall that it was several years that it took me to get into hardware wallets and then it was several years more before I started using passphrases, and I think that many times we are afraid of overcomplicating our set up, yet in the Cold Card key generation case, there ended up being an over-reliance that the manufacturer had incorporated enough entropy into its standard wallet (prior to the passphrase), and it does not even seem like a BIG expectation for a normie (or even a normie newbie) to have if the wallet had been touting itself as having great security and privacy features.
[edited out]
I remember at the time this came out many people that knew what they were talking about were saying this guy was a hack.
If you trust a black box than why should you be surprised when it fails you?
Bitcoin has always been Verify, Don't trust.
Everyone wants to add Trust in and then blames bitcoin when their trust models fail, I for one AM Fucking Sick of it!
These FUD campaigns piss me off to no end from Tards that know nothing and shills that just use idiots ignorance to propagate lies.
I find it hard to blame normies for a lot of these matters, since people are not naturally technically adept, and normies tend to have a lot of things going on in their lives so they cannot always focus on what they need to focus on and sometimes
they we get distracted by disinformation or misinformation or even just going down paths of thinking that some things sound logical, when they are not as logical as they seem.
Even, one of you guys, mentioned the possible issue with paper wallets. There are some guys who swear by paper wallets, and I recall even years back there had been questions about the ways that some of those paper wallets might have had been generated.
There are a lot of missteps that guys can make, and I recall some guys in these here parts stating that they had set some of their wallets up in ways that were a bit too complicated, and I am even guilty of that and it makes it worse trying to explain to someone else with their eyes glazing over as I am trying to explain the rationale behind creating my own levels of entropy that could end up biting someone in the ass, whether me, or my heirs or whatever.
Wasn't another member (@asUHWEceyc) talking about brainwallets, and surely brainwallets might work for short periods, and some folks think that they have such great memories, which surely they could become glitched, so there may well be needs to have back ups of wallets that are based on memories...even remembering where the back ups are and how they are stored can be difficult, which may be a good reason to tell someone else who is trustworthy, and sometimes we don't have people we can trust in our lives. As we age, the trustworthy ones might have all died.
[edited out]
That's unfortunately the truth, I know people who use super simple passwords for every possible account they have and all they have to say in their defense is that it's a way to not forget/lose their password. However, in the case of CC hacking, the fact comes to light that some users of that HW, who should be a little more aware of possible risks, did not additionally protect their accounts. A randomly generated passphrase of at least 10+ letters/characters/numbers would protect any seed that was exposed to hackers.
I know that we have had this conversation in this thread previously, and I think that the fact of the matter is that any passphrase would have given at least some level of protection, and can buy some time, even if the passphrase is fairly simple. Of course, the more complex and longer the passphrase then the harder it is going to be to brute force it, with the complication of potentially locking ourselves out, which locking ourselves out risk remains a quite common and ongoing issue.
By the way, it is said that some researchers managed to link the hacker to a centralized platform that he used for this operation. If so, I think the only question is whether they want to find the hacker (if they are looking for him), because VPN or Tor mean nothing to today's three letter agencies.
You are correct that sometimes "they" don't really want to help.. .those fucks.
[edited out]
Get it, JJG - you stupid scumbag dickhead?
Yes. I get it.
There are all kinds of ways that normies get lured into inferior products, and could you imagine if everyone used those inferior (3rd party products)?
Bitcoin would have no value since it would be the same as any other imaginary vaporware financial product.
Bitcoin's use and value come from self-custody.
You must not know nuttin.

What else is new, DunningKruger boy?

- you stupid scumbag dickhead?
And whenever I think I'm being too much of an asshole I can always un-ignore one of this guys posts and feel good about myself.

Not exactly a good role model for, relatively speaking, innocent church-goers like yourself.

So my suggestion would be do not allow RBF for your sweep transaction and set a very high fee to ensure that your transaction will be picked up immediately. Then pray.
Well, I will try to remember this.
Also, ironically, you could use one of the controversial services that spammers like, for example, slipstream to pay a miner directly to include your transaction in a block without it ever being publicly seen before the block is mined.
A few months ago, I deposited Bitcoin from Binance onto a Visa card and used it to pay at a restaurant, something that many people do, especially in countries where direct payments using Bitcoin are not possible.
It took me about 5 minutes to do, and it was a different experience for me.

You could have something like Bluewallet on your phone, and you could keep a few hundred in bitcoin within some addresses there. You could also have Phoenix wallet for lighting payments, and the same thing a few hundred dollars in bitcoin there.
I understand that some of the exchanges do offer some kind of a credit card, so sure, there is nothing wrong with that, and any vender who accepts credit card would be able to accept it without knowing that bitcoin is involved since they would receive the amount in their local currency.
Second hack occured from ColdCard wallet, more than 1000 coins (so far) stolen.
All ColdCard models are being drained.
This is so fcked up for people holding longterm for years as retirement funds...GONE!
Even though several of us have been hearing about this for a couple of days, there are some guys that go "radio silent." Maybe they are on a camping trip or some other kind of a digital silence retreat, and then they could come back to the world of bitcoin news and find out for the first time that there is a vulnerability related to a wallet that they use and that they presumed to be secure.
I genuinely hope no one here has been affected.
While being away having a break from Bitcoin space i do check out the news -not so frequently as normal- just to keep updated for good news like the most likely coming Clarity Act and this ColdCard hack.
Always stay focused when it comes to your precious coins, check your coldstorage few times a year if it still in place.
Stay save guy's.
Yeah. We do need to check our set up from time to time, and also surely if our coins are still there. Just recently, I was having trouble figuring out one of my wallets, and it was a good-sized amount, and I went back and forth through my notes before I realized (Oh? it is obvious what I meant by those notes.) Obvious might not be so obvious after some passage of time.
I have also had it come up that some passwords that I use on a fairly regular basis, all of a sudden I cannot remember it. So I end up having to go look up some cheat sheets in order to be able to narrow in on what is the password. Just like any of us who might think that we are super smart, it might ONLY take a plunk on the head, and then viola!!!!! We cannot remember a variety of "basic" things. Probably quite a few of us have had periods where we forgot our phone number, even if we might have had been using the same number for 10 years or more.
Mangoes from my home tree. No chemical used in ripening them. 100% organic and taste exceptionally good.

The ink on those newspapers might not be organic or even good for you. hahahahahahaha