Bitcoin Forum
August 07, 2026, 09:49:22 PM *
News: COLDCARD users only: critical vulnerability risks funds stored on COLDCARD devices; immediate action required
 
   Home   Help Search Login Register More  
Pages: « 1 [2]  All
  Print  
Author Topic: What's your take on this moment?  (Read 259 times)
decodx
Hero Member
*****
Offline

Activity: 1498
Merit: 963


#kycfree 🗽


View Profile
Today at 07:39:25 AM
 #21

<...>
This get together is something that Ledger and others should form themselves, hardware wallet companies should be the ones doing this,

It's funny that you mentioned Ledger, considering they use closed-source firmware and proprietary secure elements. An independent external audit of their codebase is practically impossible. But to mitigate lack of total transparency, Ledger does have an internal security team (the Donjon).

why are third parties coming together to clean the mess of people who are supposed to protect against vulnerabilities in crypto space? I don't get it.

You don't get how open source software works? All software can have bugs. The whole point of open source is that third parties can actually find and fix them.

▄███████████████████████▄
███████████████████████
████████████▀▀██████████
████████████████████████
██████████▄▄██████████
█████████████████████
███████████████████████
█████████████████████
██████████▀▀██████████
████████████████████████
██████████▄▄████████████
███████████████████████
▀███████████████████████▀
 
 MoBit 
████
██
██
██
██
██
██
██
██
██
██
██
████
 NO   LOGS
 
 LOW  FEES
 
 PGP  GUARANTEE
████
██
██
██
██
██
██
██
██
██
██
██
████
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
justdimin
Hero Member
*****
Online Online

Activity: 3822
Merit: 695


www.Crypto.Games: Multiple coins, multiple games


View Profile
Today at 07:42:10 AM
 #22

It's a good movement, is all I can say, because there is basically no incentives involved and they are doing this voluntarily only for the betterment of the community and this industry, unless they have ulterior motives hidden from the general public, but we shouldn't think negative about such positive things.

After the recent coldcard attack, the community must have learned one thing: always use systems, such as hardware or anything like that, only if it has open-source software that can be publicly verified by anyone with knowledge about it. When something is open-source, it can be checked by other developers who aren't a part of the project and won't pass biased judgements, this will allow people to have more trust in the projects and also be safer when it comes to their financial holdings.

People will also learn to use passphrases on their wallets from now on, because this attacked has proved that just keeping your seed phrase safe is not enough because you never know, your seed phrase might have reached someone else before it reached you after it was created.

█████████████████████████
███████▄▄▀▀███▀▀▄▄███████
████████▄███▄████████
█████▄▄█▀▀███▀▀█▄▄█████
████▀▀██▀██████▀██▀▀████
████▄█████████████▄████
███████▀███████▀███████
████▀█████████████▀████
████▄▄██▄████▄██▄▄████
█████▀▀███▀▄████▀▀█████
████████▀███▀████████
███████▀▀▄▄███▄▄▀▀███████
█████████████████████████
.
 CRYPTOGAMES 
.
 Catch the winning spirit! 
█▄░▀███▌░▄
███▄░▀█░▐██▄
▀▀▀▀▀░░░▀▀▀▀▀
████▌░▐█████▀
████░░█████
███▌░▐███▀
███░░███
██▌░▐█▀
PROGRESSIVE
      JACKPOT      
██░░▄▄
▀▀░░████▄
▄▄▄▄██▀░░▄▄
░░░▀▀█░░▀██▄
███▄░░▀▄░█▀▀
█████░░█░░▄▄█
█████░░██████
█████░░█░░▀▀█
LOW HOUSE
         EDGE         
██▄
███░░░░░░░▄▄
█▀░░░░░░░████
█▄░░░░░░░░█▀
██▄░░░░░░▄█
███▄▄░░▄██▌
██████████
█████████▌
PREMIUM VIP
 MEMBERSHIP 
DICE   ROULETTE   BLACKJACK   KENO   MINESWEEPER   VIDEO POKER   PLINKO   SLOT   LOTTERY
Die_empty
Legendary
*
Offline

Activity: 1526
Merit: 1328


Give all before death


View Profile
Today at 08:13:44 AM
 #23

The major attraction of open-source projects is that everyone can review the code, identify errors, and propose necessary steps. I know it is everyone's responsibility to check for bugs in these decentralized wallets because we are all enjoying the benefits. But it is frightening that it is only when there is a problem that Bitcoiners with technical skills will start to review Bitcoin projects. My take is that these reviews should be done before these vulnerabilities cause harm.

But I would have to appreciate the effort of the Bitcoin Red Team. They have engaged in a selfless act that deserves commendation.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D  
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
OcTradism
Legendary
*
Offline

Activity: 2562
Merit: 1031



View Profile
Today at 08:19:25 AM
 #24

The major attraction of open-source projects is that everyone can review the code, identify errors, and propose necessary steps. I know it is everyone's responsibility to check for bugs in these decentralized wallets because we are all enjoying the benefits. But it is frightening that it is only when there is a problem that Bitcoiners with technical skills will start to review Bitcoin projects. My take is that these reviews should be done before these vulnerabilities cause harm.

But I would have to appreciate the effort of the Bitcoin Red Team. They have engaged in a selfless act that deserves commendation.
With users, not all users have to review the code because they are not capable for it. If all users have to check the code before using Bitcoin blockchain, Bitcoin wallets, I am sure Bitcoin already failed. Fortunately, code checking can be done by community members and there are many people are technical capable to do that, then publish their reviews.

Additionally, reviews will be reviewed by the other people too, so it's how a project with open source code can be considered as reliable and quality if code has been reviewed by many people.

Die_empty
Legendary
*
Offline

Activity: 1526
Merit: 1328


Give all before death


View Profile
Today at 09:26:56 AM
 #25

With users, not all users have to review the code because they are not capable for it. If all users have to check the code before using Bitcoin blockchain, Bitcoin wallets, I am sure Bitcoin already failed. Fortunately, code checking can be done by community members and there are many people are technical capable to do that, then publish their reviews.

Additionally, reviews will be reviewed by the other people too, so it's how a project with open source code can be considered as reliable and quality if code has been reviewed by many people.
I am not saying that everybody needs to check code before using Bitcoin. My point is that nothing stops anybody from gaining the requisite knowledge to review code. Since the code is open source, you can review it if you have the knowledge. Unfortunately, not everyone has the skills, so we depend on the publications of others. So we benefit from the voluntary work of others since we enjoy a safe, decentralized system. 

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D  
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
Woodie
Hero Member
*****
Offline

Activity: 2632
Merit: 970


🏰 KING OF THE CASTLE 🏰


View Profile WWW
Today at 09:45:24 AM
 #26

This discussion will now spill over to open source Vs closed source, if coldcard had run their business on an open source platform whatever vulnerability that was recently exploited would have been found and the hack would have been avoided!!

But following all the chatter about this incident , some people are saying this could have been an inside job because they themselves made a joke about this entropy generation bug back in 2021.. and 5years later boom hacked by the the very  "entropy generation bug" talk about coincidence!


Credit: cyber scrilla

-------

Goodluck to Bitcoin Red Team, hunting season is on Cool

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
decodx
Hero Member
*****
Offline

Activity: 1498
Merit: 963


#kycfree 🗽


View Profile
Today at 10:07:48 AM
 #27

This discussion will now spill over to open source Vs closed source, if coldcard had run their business on an open source platform whatever vulnerability that was recently exploited would have been found and the hack would have been avoided!!
<...>

Except Coldcard was open source... Well, sort of. The RNG vulnerability sat right there in the open repo for years, and it still went completely unnoticed until it got exploited. The problem wasn't that the source code was unavailable for inspection, but their arrogant attitude toward criticism and their choice to block a massive chunk of developers who wanted to use, and naturally audit, their code.

Nobody is going to waste hours doing free audit work for a company that acts hostile the second someone finds a flaw.

▄███████████████████████▄
███████████████████████
████████████▀▀██████████
████████████████████████
██████████▄▄██████████
█████████████████████
███████████████████████
█████████████████████
██████████▀▀██████████
████████████████████████
██████████▄▄████████████
███████████████████████
▀███████████████████████▀
 
 MoBit 
████
██
██
██
██
██
██
██
██
██
██
██
████
 NO   LOGS
 
 LOW  FEES
 
 PGP  GUARANTEE
████
██
██
██
██
██
██
██
██
██
██
██
████
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
BluebloodCXVI
Full Member
***
Offline

Activity: 140
Merit: 104


Karma Is An Imaginary Cope For The Weak.


View Profile
Today at 10:55:37 AM
 #28

Honestly, I think this is probably the best response that the Bitcoin community could have had after the whole Coldcard incident.

AI has helped to speed up the process, but it was still humans that verified the findings and pushed for fixes.
Of course incidents like this cause a lot of damages but the real strength of an open source software is that bugs can be independently scrutinized, disclosed and fixed rather leaving it unaddressed.

So if bugs can now be found faster and all these bitcoin related software projects are forced to take security more seriously, then that’s definitely a good thing for the entire bitcoin ecosystem.

Sunshine1525
Full Member
***
Offline

Activity: 189
Merit: 103


Bitcoin shall soon shine... Say it faster, hahaha.


View Profile
Today at 07:27:58 PM
 #29

This discussion will now spill over to open source Vs closed source, if coldcard had run their business on an open source platform whatever vulnerability that was recently exploited would have been found and the hack would have been avoided!!

But following all the chatter about this incident , some people are saying this could have been an inside job because they themselves made a joke about this entropy generation bug back in 2021.. and 5years later boom hacked by the the very  "entropy generation bug" talk about coincidence!


Credit: cyber scrilla

It's annoying how a mere joke turned into reality, with such discovery i think the developers of coldcard needs to be investigated cause i don't see it as a coincidence, "it's definitely an inside job" cause same bug they joked about still succeed in pulling a big hack, make it mame sense.

Even though it wasn't an inside job they might have indirectly leaked a hint to the hacker tbrough that joke, i wonder why they were so careless not to prepare for a future attack from a bug they joked about. We'll see the end of this sooner or later.

Marykeller
Hero Member
*****
Offline

Activity: 1890
Merit: 628



View Profile
Today at 08:24:07 PM
 #30

Ugly scenarios called for urgent attention; that's how it should be. We can't be calm to watch what has happened to Coldcard repeat again. The crypto space will not be a level playing ground for scammers and hackers to get into and move away with people's funds at any time.

I want to commend those who have come together to build a team called Bitcoin Red Team. At least they are standing in the gap to fill the security holes for Bitcoin core projects not be hacked because of their vulnerabilities

Antotena
Hero Member
*****
Online Online

Activity: 1176
Merit: 605



View Profile
Today at 09:25:23 PM
 #31

I'm impressed seeing that some people in the Bitcoin community are angered by the recent security bridge on coldcard and took it upon themselves to find loopholes and fix them so more issues won't occur in future but posting it on X alone would raise some doubts on clout chasing to get attentions so it would've been more a site or GitHub was created for more public awareness and verification so i support CryptoBuds opinion concerning that.

Although it's amazing how fast they were able to discover and address the loopholes but I'm curious to who sponsored the task or project rather, was it voluntary from the names you mentioned or someone anonymous? However the bottomline is that the 85 critical can't be fully trusted until a verified report is given.

You are seeing anger because people loss coins, there are people that does not lose anything in this thing and they are not regretting anything. There are people that will go and buy another hardware wallet that is worst than this one even though they have seen how people complain about the insecure random number.  Some people might lose more Bitcoin and it migjt not be through this way that are been reported about Coldcard, it might be another way.

The main thing is that people are educational about what they have experience, for long this vulnerability has been in existence and people don't even know about it, some were lucky to have use passphrase and escape the bug vulnerability and I think that many people that hs been trying to understand about passphrase and couldn't understand it through out the years have a simple way to relate it but I just think it's not, some people will still fall victim.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT|
4,000+ GAMES
███████████████████
██████████▀▄▀▀▀████
████████▀▄▀██░░░███
██████▀▄███▄▀█▄▄▄██
███▀▀▀▀▀▀█▀▀▀▀▀▀███
██░░░░░░░░█░░░░░░██
██▄░░░░░░░█░░░░░▄██
███▄░░░░▄█▄▄▄▄▄████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
█████████
▀████████
░░▀██████
░░░░▀████
░░░░░░███
▄░░░░░███
▀█▄▄▄████
░░▀▀█████
▀▀▀▀▀▀▀▀▀
█████████
░░░▀▀████
██▄▄▀░███
█░░█▄░░██
░████▀▀██
█░░█▀░░██
██▀▀▄░███
░░░▄▄████
▀▀▀▀▀▀▀▀▀
||.
|
▄▄████▄▄
▀█▀
▄▀▀▄▀█▀
▄░░▄█░██░█▄░░▄
█░▄█░▀█▄▄█▀░█▄░█
▀▄░███▄▄▄▄███░▄▀
▀▀█░░░▄▄▄▄░░░█▀▀
░░██████░░█
█░░░░▀▀░░░░█
▀▄▀▄▀▄▀▄▀▄
▄░█████▀▀█████░▄
▄███████░██░███████▄
▀▀██████▄▄██████▀▀
▀▀████████▀▀
.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
░▀▄░▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄░▄▀
███▀▄▀█████████████████▀▄▀
█████▀▄░▄▄▄▄▄███░▄▄▄▄▄▄▀
███████▀▄▀██████░█▄▄▄▄▄▄▄▄
█████████▀▄▄░███▄▄▄▄▄▄░▄▀
███████████░███████▀▄▀
███████████░██▀▄▄▄▄▀
███████████░▀▄▀
████████████▄▀
███████████
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▀▄███░░░▀████░███▄▀██▄
███░████░░░░░▀██░████░███
███░████░█▄░░░░▀░████░███
███░████░███▄░░░░████░███
▀██▄▀███░█████▄░░███▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
OFFICIAL PARTNERSHIP
SOUTHAMPTON FC
FAZE CLAN
SSC NAPOLI
Faisal2202
Hero Member
*****
Online Online

Activity: 2016
Merit: 604


#kycfree 🗽


View Profile WWW
Today at 09:30:37 PM
 #32

This is really scary that the team found so many vulnerabilities, but it is good that they found not hackers and they fixed all of them. Another thread mentioned that the OP said Red Team was behind the vulnerability detection in BTCPay Server, so that was one of them. But they spent so little time and found vulnerabilities that would have taken months or maybe a year if done manually, and yet we still think AI is not helping.

They used all kinds of models, and they definitely know what they are doing. I am surprised to see the kind of work they have done. They should be rewarded, but is there any list of all the projects where they found these vulnerabilities? Vik Sharma donated $10k, that's amazing.

So Kimi K3 gave them uncensored access to their models. Well, that's something new. I did not know models could offer such services on demand. Maybe they had some deal or something, but whatever it was, it seems it was possible due to such uncensored models because models have a lot of restrictions.

▄███████████████████████▄
███████████████████████
████████████▀▀██████████
████████████████████████
██████████▄▄██████████
█████████████████████
███████████████████████
█████████████████████
██████████▀▀██████████
████████████████████████
██████████▄▄████████████
███████████████████████
▀███████████████████████▀
 
 MoBit 
████
██
██
██
██
██
██
██
██
██
██
██
████
 NO   LOGS
 
 LOW  FEES
 
 PGP  GUARANTEE
████
██
██
██
██
██
██
██
██
██
██
██
████
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
Pages: « 1 [2]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!