OgNasty (OP)
Donator
Legendary

Activity: 5544
Merit: 6435
Leading Crypto Sports Betting & Casino Platform
|
 |
August 01, 2026, 04:45:11 PM Last edit: August 02, 2026, 01:38:11 PM by OgNasty |
|
I just wanted to give a proud pat on the back of all the coinmakers here who managed to properly safeguard the keys they use in their products. A lot of noise is made whenever something goes wrong, but not a lot of thanks is given when things go right. If a company with sales of products like Coldcards couldn't safeguard their product when that is the #1 purpose of it, you'd think that we would see more hacks from products made by amateurs on these boards. If you've created a product that holds BTC for users here and it hasn't been hacked. Thank you on behalf of the community. You did good. https://bitcoinworld.co.in/binance-founder-warns-hardware-wallet-safety-coldcard-hack/EDIT: As a side-note (and more on-topic), I do think the title of this topic could be better (it is a tad vague). Something like "Thank You to the makers who did their security right", but I'm not going to bother changing it.
|
| ..Stake.com.. | | | ▄████████████████████████████████████▄ ██ ▄▄▄▄▄▄▄▄▄▄ ▄▄▄▄▄▄▄▄▄▄ ██ ▄████▄ ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██ ██████ ██ ██████████ ██ ██ ██████████ ██ ▀██▀ ██ ██ ██ ██████ ██ ██ ██ ██ ██ ██ ██████ ██ █████ ███ ██████ ██ ████▄ ██ ██ █████ ███ ████ ████ █████ ███ ████████ ██ ████ ████ ██████████ ████ ████ ████▀ ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██ ██ ▀▀▀▀▀▀▀▀▀▀ ██ ▀█████████▀ ▄████████████▄ ▀█████████▀ ▄▄▄▄▄▄▄▄▄▄▄▄███ ██ ██ ███▄▄▄▄▄▄▄▄▄▄▄▄ ██████████████████████████████████████████ | | | | | | ▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄ █ ▄▀▄ █▀▀█▀▄▄ █ █▀█ █ ▐ ▐▌ █ ▄██▄ █ ▌ █ █ ▄██████▄ █ ▌ ▐▌ █ ██████████ █ ▐ █ █ ▐██████████▌ █ ▐ ▐▌ █ ▀▀██████▀▀ █ ▌ █ █ ▄▄▄██▄▄▄ █ ▌▐▌ █ █▐ █ █ █▐▐▌ █ █▐█ ▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█ | | | | | | ▄▄█████████▄▄ ▄██▀▀▀▀█████▀▀▀▀██▄ ▄█▀ ▐█▌ ▀█▄ ██ ▐█▌ ██ ████▄ ▄█████▄ ▄████ ████████▄███████████▄████████ ███▀ █████████████ ▀███ ██ ███████████ ██ ▀█▄ █████████ ▄█▀ ▀█▄ ▄██▀▀▀▀▀▀▀██▄ ▄▄▄█▀ ▀███████ ███████▀ ▀█████▄ ▄█████▀ ▀▀▀███▄▄▄███▀▀▀ | | | ..PLAY NOW.. |
|
|
|
Kryptowerk
Legendary

Activity: 2380
Merit: 1566
Crypto Casino with No KYC on routine deposits
|
 |
August 01, 2026, 06:27:09 PM |
|
For a second I was very confused, the name is just too close to Yogg's coldkeys.
I mean your shoutout is nice. I agree, they deserve some merit. However it should just be a given that safe key-generation and no ill-intent is very base-level of what makes a good crypto-collectible producer. It's like saying a beer company deserves a shoutout because for over 10 years they never used toxic ingredients. It should be the base layer of a decent beer producer.
To be fair, having a secure way of managing keys is no simple task and nowadays attack-vectors for are even larger, apparently there are many AI based hacking tools that can finde exploits much easier than it used to be in the past.
|
| | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | | | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | | ████████████████████████████ 100 FREE SPINS ████████████████████████████ | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | CLAIM BONUS |
|
|
|
rsincognito
Copper Member
Full Member
 

Activity: 1190
Merit: 183
|
 |
August 01, 2026, 10:28:24 PM |
|
I put up a full post up talking about this the other day and it was taken down  made no sense, the questions I asked in my post had to do with btc collectibles and how they were made and if coldcard played any part in someone coin makers key making, its a far fetch questions but worth asking imho.
|
|
|
|
|
|
henkcryptotank
|
 |
August 02, 2026, 07:29:40 AM Last edit: August 02, 2026, 07:51:43 AM by henkcryptotank |
|
Clarified
|
Losers never hold. Holders never lose.
|
|
|
Mitchell
Moderator
Legendary

Activity: 4732
Merit: 3175
Verified awesomeness ✔
|
 |
August 02, 2026, 07:41:48 AM Last edit: August 02, 2026, 01:03:39 PM by Mitchell |
|
I put up a full post up talking about this the other day and it was taken down  [...] Yea i wondered where that post went, thats some bs!
Saying it got taken down is disingenuous and calling it bullshit doesn't help. The topic still exists: Questions and a discussion about COLDCARD hardware device compromises. It was moved to a different section by by someone (it wasn't me). Instead of posting here, which doesn't help you, unless someone of the staff happens to read it, why didn't you make a topic in Meta? Reported your own topic and asked for it to be moved back? You could've even reached out to me, I promise I don't bite (except right now). What was the end goal here? Are you trying to create drama? We've enough of that on this board. I legit do not understand. If it helps, I do think it belongs in this section (as long we keep the ColdCard topics to a minimum) and I've reported the topic as such with the question to have it moved back. EDIT: As a side-note (and more on-topic), I do think the title of this topic could be better (it is a tad vague). Something like " Thank You to the makers who did their security right", but I'm not going to bother changing it. EDIT2: It has been moved back.
|
|
|
|
Stalker22
Legendary

Activity: 2324
Merit: 1612
|
 |
August 02, 2026, 08:23:33 AM |
|
To be fair, having a secure way of managing keys is no simple task and nowadays attack-vectors for are even larger, apparently there are many AI based hacking tools that can finde exploits much easier than it used to be in the past.
Yes, but it should go the other way too, right? If hackers are using AI to scout for exploits, developers should be using those exact same tools to audit their own code before pushing it to production. I agree that it is not a simple task, but that is precisely why hardware and software wallet companies, and anyone making physical coins or crypto collectibles, should not get a pass when they drop the ball. I mean, come on, we are talking about millions of dollars of peoples hard-earned money here. It is not a playground. If a company or developer cant handle the heat, and do the paranoid-level testing, they simply should not be in this business. Plain and simple.
|
|
|
|
krogothmanhattan
Cypher Hodl LLC
Legendary

Activity: 3332
Merit: 4463
The Stone the masons rejected was the cornerstone.
|
 |
August 02, 2026, 10:42:09 AM |
|
To be fair, having a secure way of managing keys is no simple task and nowadays attack-vectors for are even larger, apparently there are many AI based hacking tools that can finde exploits much easier than it used to be in the past.
Yes, but it should go the other way too, right? If hackers are using AI to scout for exploits, developers should be using those exact same tools to audit their own code before pushing it to production. I agree that it is not a simple task, but that is precisely why hardware and software wallet companies, and anyone making physical coins or crypto collectibles, should not get a pass when they drop the ball. I mean, come on, we are talking about millions of dollars of peoples hard-earned money here. It is not a playground. If a company or developer cant handle the heat, and do the paranoid-level testing, they simply should not be in this business. Plain and simple. Correct indeed! Whatever happened to the our adage of VERIFY DONT TRUST!! Truer words have never been said and in this case it applies 100%! How come none of the smartest minds out there never tested these? This is a big blow and smear to self custody! And yeah I have bought their products but only as a collectable.
|
|
|
|
hybridsole
Legendary

Activity: 1017
Merit: 1013
|
 |
August 02, 2026, 01:36:44 PM |
|
There is a huge lack of clarity when it comes to how coin makers generate keys, something that many have complained about for years. Ognasty you often say we are all toxic and bullies to new coin makers, but the coldcard situation is exactly why we are. There are too many ways someone inexperienced can fuck up the key generation process, and there should be an intense amount of scrutiny of makers, especially newer makers, on their process and legitimacy.
They should not get a pat on the back for not fucking up.. It should be the bare minimum to exist in this space and earn our business and trust.
These makers are generating keys not just for themselves but dozens or hundreds of additional people. Without clarity we will get more situations of someone using a malware laced paper wallet program or other inadequate setups. Very few makers have revealed their process like having a 2nd PC that is airgapped, a non-wifi printer or laser etcher. What open source tools they are using to generate the valid addresses, and other quality control measures to test the keys match the address. All of these details would be nice to know otherwise I just refuse to trust putting even a single satoshi into their keys.
|
|
|
|
|
OgNasty (OP)
Donator
Legendary

Activity: 5544
Merit: 6435
Leading Crypto Sports Betting & Casino Platform
|
 |
August 02, 2026, 03:28:16 PM |
|
They should not get a pat on the back for not fucking up.. It should be the bare minimum to exist in this space and earn our business and trust.
Agree to disagree. It is not easy and that is why even a product like the Coldcard with 1 job wasn’t able to do it. It is ok to give people their flowers.
|
| ..Stake.com.. | | | ▄████████████████████████████████████▄ ██ ▄▄▄▄▄▄▄▄▄▄ ▄▄▄▄▄▄▄▄▄▄ ██ ▄████▄ ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██ ██████ ██ ██████████ ██ ██ ██████████ ██ ▀██▀ ██ ██ ██ ██████ ██ ██ ██ ██ ██ ██ ██████ ██ █████ ███ ██████ ██ ████▄ ██ ██ █████ ███ ████ ████ █████ ███ ████████ ██ ████ ████ ██████████ ████ ████ ████▀ ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██ ██ ▀▀▀▀▀▀▀▀▀▀ ██ ▀█████████▀ ▄████████████▄ ▀█████████▀ ▄▄▄▄▄▄▄▄▄▄▄▄███ ██ ██ ███▄▄▄▄▄▄▄▄▄▄▄▄ ██████████████████████████████████████████ | | | | | | ▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄ █ ▄▀▄ █▀▀█▀▄▄ █ █▀█ █ ▐ ▐▌ █ ▄██▄ █ ▌ █ █ ▄██████▄ █ ▌ ▐▌ █ ██████████ █ ▐ █ █ ▐██████████▌ █ ▐ ▐▌ █ ▀▀██████▀▀ █ ▌ █ █ ▄▄▄██▄▄▄ █ ▌▐▌ █ █▐ █ █ █▐▐▌ █ █▐█ ▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█ | | | | | | ▄▄█████████▄▄ ▄██▀▀▀▀█████▀▀▀▀██▄ ▄█▀ ▐█▌ ▀█▄ ██ ▐█▌ ██ ████▄ ▄█████▄ ▄████ ████████▄███████████▄████████ ███▀ █████████████ ▀███ ██ ███████████ ██ ▀█▄ █████████ ▄█▀ ▀█▄ ▄██▀▀▀▀▀▀▀██▄ ▄▄▄█▀ ▀███████ ███████▀ ▀█████▄ ▄█████▀ ▀▀▀███▄▄▄███▀▀▀ | | | ..PLAY NOW.. |
|
|
|
hybridsole
Legendary

Activity: 1017
Merit: 1013
|
 |
August 02, 2026, 03:38:53 PM |
|
They should not get a pat on the back for not fucking up.. It should be the bare minimum to exist in this space and earn our business and trust.
Agree to disagree. It is not easy and that is why even a product like the Coldcard with 1 job wasn’t able to do it. It is ok to give people their flowers. Coldcard majorly fucked up and used the equivalent of a Fisher Price random number generator, which is why they are getting crucified. Entropy isn't all that difficult if you use real open source cryptography, which has been around in many forms since bitcoin's existence. The original bitcoin client is still holding Satoshi's coins just fine. And bitaddress.org that uses mouse movement entropy is still undefeated for 12+ years, assuming it was done offline. I know many coin makers have used bitaddress, and that is standard practice.
|
|
|
|
|
[btc]
Full Member
 

Activity: 154
Merit: 282
"Messages are broadcast on a best effort basis,"
|
 |
August 03, 2026, 01:14:00 AM Last edit: August 03, 2026, 05:29:16 PM by [btc] Merited by hybridsole (2) |
|
Entropy isn't all that difficult if you use real open source cryptography, which has been around in many forms since bitcoin's existence. The original bitcoin client is still holding Satoshi's coins just fine. And bitaddress.org that uses mouse movement entropy is still undefeated for 12+ years, assuming it was done offline. I know many coin makers have used bitaddress, and that is standard practice.
Is there a way to verify that a wallet generated with bitaddress.org was done offline? Is there also a way to verify that the p-keys of said wallet were properly discarded? Like let's say I am a physical collectibles maker: - I build/purchase airgapped computer hardware - I use bitaddress html offline - I generate the wallet(s) offline - I print the private key(s) out using offline printer - I put the p-key(s) onto the physical item(s) - I place a tamper-evident seal(s) over the p-key(s) - I destroy everything related to the p-key(s) How do I do all this in a way that ensures the customer's eyes, are the only pair of eyes, that see the p-key(s)? How do I do all this in a way that ensures the public can verify I did not retain any copies of said p-key(s)? I know it may sound ridiculous to you, but I am genuinely asking. I have aspirations to be a maker one day, and I really want to know what the standardization is. What is the absolute trustless way for someone to manufacture wallets? No one here knows me, and I've already read through all of the horror-stories (from krogo's threads/lists). This ColdCard shit is now a horror story, and it's been very sad reading the outcome of such gross negligence. So ideally, I'd want my future products to be created the "right way", so-to-speak, it would make my aspirations easier to acheive. The fact that you say bitaddress is a battle-tested method (when done offline), is good information for me, because [1]I didnt know that prior to reading this and [2] that method of running bitaddress offline seems pretty straightforward and easy to use. I don't want people to trust me fully, as I know for a fact trust is not absolute - we are human beings with several potential vectors of failure. I think satoshi's coins are still untouched because he most likely destroyed the keys to those wallets - he was smart enough to not even absolutely trust himself.
@[ btc ]
Thanks for the handy links, I'll look into those. Also, your advice for completely airgapping is solid - I myself am slightly familiar with the Glacier Protocol. Here's a post I made referencing it back in March. I'm honestly more curious about methods to prove that the way the maker generated/destroyed the keys, is the proper way. Outside of "trustmebro", of course. For example, why does the world at large trust Casascius (Mike Caldwell), and the keys he made? Certainly it's not because he was one of the pioneers. I give a rat's ass if you were a pioneer/some revolutionary - I solely care about the fact you do/do not have access to private keys I bought off you.
|
BTC ■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■
|
|
|
bitbollo
Legendary

Activity: 4060
Merit: 4967
|
 |
August 03, 2026, 02:41:16 AM Last edit: August 03, 2026, 03:02:33 AM by bitbollo Merited by hybridsole (3) |
|
... They should not get a pat on the back for not fucking up.. It should be the bare minimum to exist in this space and earn our business and trust. ...
Absolutely... it's like selling cars that have no brakes... I am surprised we don't think this is a "must" for bitcoin colletible. I am not just "delegating" the risk to another user/company. There is always the chance for an error during production/a voluntary mistake or just some ignorance during key generation. I have seen a few interest in this argument but this is one the hardest processes for generating a safe wallet. Isn't just downloading and run a program but there are many other actions to avoid a further issue from generating to storing the key. Again, we can't delegate this process since it's one of the most critical aspect (the first!) while using bitcoin. RNG has already been an issue in wallet generation, and in general it's a well known issue that "random" doens't mean nothing since it can be in some way predictable. Other hardware/software makers have the same issue in the past providing a "weak" RNG.... List taken from Jameson Lopp Post: bip3x Python library http://bitaddress.orgBitcoinSpinner http://Blockchain.com Android wallet http://Blockchain.com web wallet http://brainwallet.org browser generator Cake Wallet CoinPunk COLDCARD Mk2 – Mk5 & Q Ethereum presale wallet generator Libbitcoin Explorer (bx seed) Mycelium Bitcoin Wallet PHPCoinAddress Profanity QuickCoin Schildbach Bitcoin Wallet for Android Trust Wallet browser extension Trust Wallet for iOS] Here there is the first problem. These systems allow users to check how and why a specific seed has been generated.... About this specific hack, it seems that other users have blamed the same issue a couple of years ago and have been just muted (not here in bitcointalk but in Reddit). Has non sense use bitcoin if self-custody can't be done as required or must be trusted blindly. There are many examples of mistakes also on this board. Personally, I can trust coinmaker with small amounts of funds. Since I have never seen the whole process I can't trust these keys. The same apply with all these devices. No matter how "influencer" can be appreaciated on X... Don't trust... Bitcoin Collectibles (at least to me) doesn't mean "trust another keymaker" for my coins...
@[ btc ] Before accessing the website/download a script you had to be sure of the machine you're using. It's brand new? Has already been used? Has a previous access to the internet? All these systems are required to be completely airgap. I would suggest to have a read in glacierprotocol.org just to have an idea on how to build a safe system from scratch. The best solution are likewise old and boring. "You are the enthropy", you don't need to use or trust any product released by third person. Using dice/seed for generation. COMPLETELY OFF LINE. Create your own from scratch - convert random text and add extra words... [OT Weak generation of seed with waves wallet online = https://bitcointalk.org/index.php?topic=3462507.0Generate keys starting from text or images https://bitcointalk.org/index.php?topic=5400780.0]
|
| DΞX.fo | | | | | | ▄▄██████ █████████ ██████████ ██████████ ██████████ █████████ ▀▀██████
▄███████ ▄██████████ ████████████ █████████████ █████████████ | | | | ▄▄█ ▄████▀ ▄███▀█▄ ▄██▀█▄██ █████▀▀█ ████████ ████████ ▀██▄████ ▄████▄▄█ ▄█████▀███ ▄█████▀████▀ █████▀███████ ▀██▀█████████ | | | | | ..BTC......XMR... ..USDT.....LTC... ....Fees 0.8%..... |
|
|
|
buckrogers
Legendary

Activity: 2836
Merit: 1196
|
 |
August 03, 2026, 03:42:19 AM |
|
Entropy isn't all that difficult if you use real open source cryptography, which has been around in many forms since bitcoin's existence. The original bitcoin client is still holding Satoshi's coins just fine. And bitaddress.org that uses mouse movement entropy is still undefeated for 12+ years, assuming it was done offline. I know many coin makers have used bitaddress, and that is standard practice.
Is there a way to verify that a wallet generated with bitaddress.org was done offline? Is there also a way to verify that the p-keys of said wallet were properly discarded? Like let's say I am a physical collectibles maker: - I build/purchase airgapped computer hardware - I use bitaddress html offline - I generate the wallet(s) offline - I print the private key(s) out using offline printer - I put the p-key(s) onto the physical item(s) - I place a tamper-evident seal(s) over the p-key(s) - I destroy everything related to the p-key(s) How do I do all this in a way that ensures the customer's eyes, are the only pair of eyes, that see the p-key(s)? How do I do all this in a way that ensures the public can verify I did not retain any copies of said p-key(s)? I know it may sound ridiculous to you, but I am genuinely asking. I have aspirations to be a maker one day, and I really want to know what the standardization is. What is the absolute trustless way for someone to manufacture wallets? No one here knows me, and I've already read through all of the horror-stories (from krogo's threads/lists). This ColdCard shit is now a horror story, and it's been very sad reading the outcome of such gross negligence. So ideally, I'd want my future products to be created the "right way", so-to-speak, it would make my aspirations easier to acheive. The fact that you say bitaddress is a battle-tested method (when done offline), is good information for me, because [1]I didnt know that prior to reading this and [2] that method of running bitaddress offline seems pretty straightforward and easy to use. I don't want people to trust me fully, as I know for a fact trust is not absolute - we are human beings with several potential vectors of failure. I think satoshi's coins are still untouched because he most likely destroyed the keys to those wallets - he was smart enough to not even absolutely trust himself.
@[ btc ]
Thanks for the handy links, I'll look into those. Also, your advice for completely airgapping is solid - I myself am slightly familiar with the Glacier Protocol. Here's a post I made referencing it back in March. I'm honestly more curious about methods to prove that the way the maker generated/destroyed the keys, is the proper way. Outside of "trustmebro", of course. For example, why does the world at large trust Casascius (Mike Caldwell), and they keys he made? Certainly it's not because he was one of the pioneers. I give a rat's ass if you were a pioneer/some revolutionary - I solely care about the fact you do/do not have access to private keys I bought off you. I’d suggest a different approach if you have a coin design that’s actually appealing and worth buying: leave the keys out of it entirely. Sell it as a pure DIY physical Bitcoin — the buyer generates and funds their own keypair. That removes the entire set of risks and trust issues you outlined (offline generation, secure discarding of private keys, ensuring no one else ever sees them, etc.). You no longer have to prove anything about your process, and buyers don’t have to place any trust in you beyond the physical quality of the coin and the holograms. You can still do strong volume this way. Many people (myself included) will happily buy a well-made physical Bitcoin that includes proper tamper-evident holograms and is clearly sold as DIY. What most of us will not do is buy a pre-loaded or pre-generated keypair from a new maker — especially one still working through the security questions. The track record of even previously “trusted” makers over the last several years has made a lot of people extremely cautious. The original purpose of loaded physical Bitcoins (as Mike Caldwell demonstrated) was to help people grasp the concept by holding something tangible. In 2026 that educational role is largely complete. Adding loaded or pre-generated keys now mainly introduces serious downside risk for both the maker and the buyers, with very little upside that can’t be achieved more safely with a high-quality DIY product. If the coin design is strong, focus on that: make a nice piece, include solid tamper-evident holograms, and sell it as DIY. That path is cleaner, lower-risk, and still commercially viable. Thanks!
|
“Don’t waste your time on anything that doesn’t thrill you or bring you love. See you out somewhere in the cosmos.”
|
|
|
Rymaster
Member


Activity: 475
Merit: 40
-Squidster-
|
I’d suggest a different approach if you have a coin design that’s actually appealing and worth buying: leave the keys out of it entirely.
Sell it as a pure DIY physical Bitcoin — the buyer generates and funds their own keypair. That removes the entire set of risks and trust issues you outlined (offline generation, secure discarding of private keys, ensuring no one else ever sees them, etc.). You no longer have to prove anything about your process, and buyers don’t have to place any trust in you beyond the physical quality of the coin and the holograms.
While your points are spot on, this option absolutely kills the collectability side of a physical crypto piece for me. Reason being because only one of two things can take place, 1) either the hologram will forever live off of the coin and it'll always feel "incomplete" or 2) the buyer will create a wallet, load the coin and it'll have nearly no secondary market value because now the next buyer will have to trust a completely random person, over potentially a more well known physical bitcoin creator in the space. ONLY time I can justify this option is if I'm buying a coin that I want to load and give someone as a personal gift.
|
|
|
|
hybridsole
Legendary

Activity: 1017
Merit: 1013
|
 |
August 03, 2026, 01:30:04 PM |
|
I have aspirations to be a maker one day, and I really want to know what the standardization is. What is the absolute trustless way for someone to manufacture wallets?
There is no way to know for sure that any of these steps were followed correctly. So we must rely on trust, which is earned over time and can be lost suddenly. But your detailed questions about the process is more than most makers are willing to do. I've seen new makers who come here and offer keyed coins with absolutely no mention of their process, or perhaps will say something like "keys generated offline" and leave it at that. If you create a design that looks great (and not something that was 100% AI), and went into some detail about your process of generating, printing, assembling keys, that would be a great start. While your points are spot on, this option absolutely kills the collectability side of a physical crypto piece for me.
I agree with this. There's something very unsatisfying about a coin with a loose hologram to keep track of (that nobody will ever use). Loaded coins have and will continue to be the most interesting to me.
|
|
|
|
|
rsincognito
Copper Member
Full Member
 

Activity: 1190
Merit: 183
|
 |
August 03, 2026, 02:51:32 PM |
|
I put up a full post up talking about this the other day and it was taken down  [...] Yea i wondered where that post went, thats some bs!
Saying it got taken down is disingenuous and calling it bullshit doesn't help. The topic still exists: Questions and a discussion about COLDCARD hardware device compromises. It was moved to a different section by by someone (it wasn't me). Instead of posting here, which doesn't help you, unless someone of the staff happens to read it, why didn't you make a topic in Meta? Reported your own topic and asked for it to be moved back? You could've even reached out to me, I promise I don't bite (except right now). What was the end goal here? Are you trying to create drama? We've enough of that on this board. I legit do not understand. If it helps, I do think it belongs in this section (as long we keep the ColdCard topics to a minimum) and I've reported the topic as such with the question to have it moved back. EDIT: As a side-note (and more on-topic), I do think the title of this topic could be better (it is a tad vague). Something like " Thank You to the makers who did their security right", but I'm not going to bother changing it. EDIT2: It has been moved back. bro calm down lol. it was a simple question, your reply doesn't sounds like you don't bite lol, I am extremely close to mj and Mopar , we all live like 30 mins from each other, you can ask them if I have ever been about drama and I already know their answers. who hurt you ? again. chill. THANK YOU ! ( and if you were a possible victim from the cold card thing, im very sorry to hear about that). all the best
|
|
|
|
|
Mitchell
Moderator
Legendary

Activity: 4732
Merit: 3175
Verified awesomeness ✔
|
 |
August 03, 2026, 02:55:03 PM |
|
bro calm down lol. it was a simple question, your reply doesn't sounds like you don't bite lol, I am extremely close to mj and Mopar , we all live like 30 mins from each other, you can ask them if I have ever been about drama and I already know their answers. who hurt you ? again. chill. THANK YOU !
It didn't read like a simple question and I felt compelled to answer, especially after henkcryptotank's reply to it. The section has had a "decent" amount drama in the last few months, so I might be more on edge because of it. Sorry about that. If it's all good, it's all good. I am also close to MJ (and maybe Mopar, you'll have to ask him), just not physically. Next time just message me, I'm happy to help out. 
|
|
|
|
aoluain
Legendary

Activity: 3080
Merit: 1729
|
 |
August 03, 2026, 05:32:41 PM |
|
For a second I was very confused, the name is just too close to Yogg's coldkeys.
Same as that, I thought Yogg was sweeping the remaining cards or something.
|
| DΞX.fo | | | | | | ▄▄██████ █████████ ██████████ ██████████ ██████████ █████████ ▀▀██████
▄███████ ▄██████████ ████████████ █████████████ █████████████ | | | | ▄▄█ ▄████▀ ▄███▀█▄ ▄██▀█▄██ █████▀▀█ ████████ ████████ ▀██▄████ ▄████▄▄█ ▄█████▀███ ▄█████▀████▀ █████▀███████ ▀██▀█████████ | | | | | BTC XMR DAI LTC Fees 0.8% |
|
|
|
|