Chef @zknoxhq | Co-founder @Ledger 🦄. I build permissionless and hard to break things. Fan of Magic Internet Money (but no MSB). Entrepreneur if duty calls

Unhosted
Perfect execution
3
13
881
Nicolas Bacca retweeted
We regularly communicate about the results we achieve. But sometimes, the journey matters just as much as the result. We recently managed to bypass the RP2350-A4 debug protection using an innovative approach combining two techniques: photon emission imaging and laser fault injection. Here our technical blogpost: donjon.ledger.com/blog/rp235… A big thank you to @Raspberry_Pi for the collaboration and for highlighting this work. 💥
Lasers. Microscopes. $250K. One secured chip. Ledger Donjon just showed how they cracked debug access on RP2350-A4, a break worthy of Raspberry Pi's own Hacking Challenge. Respin or no respin? Raspberry Pi says no. Read why: raspberrypi.com/news/everyth…
2
10
60
24,666
if you're building a self-custodial _software_ wallet, add _max_ friction to creating hot wallets & push users toward hardware wallets. idgaf if it hurts onboarding. your main job is keeping users' funds safe and in a world full of malware, making hot wallets the easy default is fucking _reckless_.
29
9
111
12,574
Freedom of speech is going just great
Breaking: Trump says he will ban reporters from POLITICO, CNN and MS NOW from the White House. politico.com/news/2026/09/18…
1
7
784
Je forwarderais bien à Aurore pour ajouter plus de contrôles à défaut de virer les KYC mais malheureusement comme elle a bloqué tout l'écosystème ça va être compliqué :(
New evidence shows: (1) @Revolut did apply the one refusal ground the law gives it. (2) the attackers targeted in their malicious request high-value clients using blockchain transactions. Documents show that on 24 July 2026, on a request covering 198 hashes, Revolut refused direct disclosure for 169 tied to Revolut Ltd (UK) and 29 tied to a Swiss entity, redirecting the requester to UK mutual legal assistance. Only accounts held at Revolut Bank UAB in Lithuania were treated as covered by the EIO. The refusal ground available to Revolut was jurisdictional. They APPLIED it. EU AML law imposes no verification duty on the bank and provides no meaningful mechanism to check who is really behind an authenticated state request. Refusal to answer carries fines in the millions. In practice, verification is impossible. Now, how the attackers targeted high-value clients? Per Duel's verified .eml files, they used public blockchain data as query keys. Hundreds of crypto transaction IDs and deposit wallet addresses tied to suspected high-value Revolut users were submitted under the forged EIO cover. Revolut returned encrypted zip files with folders of ten customers each, ID pictures, verification selfies, account data, unredacted transaction data, with the password sent in a follow-up PEC. Anyone whose wallet address appears on-chain can be turned into a target this way. Self-custody does not close this door: the moment your KYC data sits with a regulated intermediary, the same channel opens.
1
5
40
2,007
Nicolas Bacca retweeted
Unlukey now has a public repository and client SDK: github.com/coinspect/unlukey The goal is simple: make detection of known weak seeds something wallets can add with one integration.
Researching weak wallet generation incidents we found that even when we could identify affected addresses, we had no way to warn the users who were using them. Unlukey turns each known weak generation code into datasets that wallets can use to identify and warn users: coinspect.com/blog/introduci…
2
2
5
1,346
8 heures de live 🎙️ Et une première édition du Crypto Day passée à une vitesse folle ! Plus de 250 personnes se sont inscrites 🤩 Un grand merci aux 7 intervenants, à toutes les personnes présentes en direct, à celles qui ont posé leurs questions, relayé l’événement ou simplement soutenu cette idée. Merci d’avoir fait de ce Crypto Day une vraie journée de partage autour de Bitcoin, des cryptos et de la blockchain 🙏 Vous avez été nombreux à me demander les replays : ils sont disponibles dès aujourd’hui ! Et pour ceux qui découvrent le Crypto Day seulement maintenant, il est encore possible de s’inscrire pour y accéder. Lien dans le premier commentaire.
2
2
6
685
The lack of any kind of velocity checks, common sense and responsibility when sharing critical consumer data is really disturbing
‼️ BREAKING: Duel can report that the Revolut hacker used a "spray and pray" strategy, sending hundreds of cryptocurrency transaction IDs to Revolut and asking for the associated account details. Revolut complied. This explains the sheer volume of data the hackers were able to obtain over several months. The hacker, who goes by the name "IAmNotAVillain," told Duel that he would present Revolut with hundreds of crypto transaction IDs and deposit addresses he believed to be associated with high value Revolut clients. Compelled by the fake "European Investigation Order," Revolut would send back large numbers of files containing all associated customer information. We received and verified authentic .eml copies of the emails sent by Revolut. One of the emails contained 10 folders, each one named after a customer. Each folder contained ID pictures, a selfie, account data, and transaction data, fully unredacted. For security, Revolut sent the password to the downloadable zip file in a separate email. It has been a point of curiosity in our investigation: how exactly did the hacker manage to pull off getting data specifically on high value clients? What did he ask for? Now we know. All he had to do was knock using data from public blockchains, and Revolut provided all of the requested information in a near-firehose format. We are working on a larger investigative piece that will answer a few more questions, including the fallout between "Villain" and "Smilik," more chat logs, and a video showing the extent of the hacker's files. We wanted to release this piece of information ASAP so that everyone was aware of how it was done.
1
8
1,078
It's a cool trick but keep in mind that it's very (very, very) difficult to verify what a pre built device only upgradable by software is actually running, open OS or not. That being said you should get one to play with if you support hardware innovation.
It's time for a new foundation. Not a new start. Legacy Mode is live on Passport, keep every account you already have, on code anyone can inspect. Switch to open source hardware and software while keeping your existing accounts for supported assets. Here’s how. 🧵
1
1
9
1,336
Image from github.com/btchip/CryptoXR20… - I'll have a condensed update for
Replying to @BWBulgaria
🍻 Wed 23 Sept, 19:00 | Sofia Crypto Meetup, September Edition Bar de Rouge, with @BTChip, co-founder of Ledger and now at @zknoxhq, and @MaxRoszko, BD Lead at @CurveFinance. DeFi, stablecoins, and what survives the next phase. fb.me/e/6lR9PmzRZ (Luma page WIP)
1
237
Nicolas Bacca retweeted
Onchain security is everyone’s problem and nobody’s job. ETHSecurity Initiatives is how we are changing that. Propose the work. Fund the work. Build the work. initiatives.thedao.fund/
40
109
392
195,750
Nicolas Bacca retweeted
It drive me nuts that now people use AI to write tweets. If you think that this way you will get more popular and so forth, think twice. Write something authentic. AI is great but it is easy to misuse. Your tweets must be your more cared thoughts.
59
31
635
30,782
Nicolas Bacca retweeted
⚠️ A message to anyone caught in the Revolut leak ⚠️ If you got the notification, assume your name is now on a list of people worth robbing. I was the victim of a home invasion after being targeted through a similar leak. Take this seriously. Alarm system, reinforced entry points, panic buttons, a safe room if you can manage it, legal self-defence options where you live. All of that on top of normal wallet opsec. Physical security is the part crypto people skip.
39
86
985
87,073
Un point que j'ai oublié de rappeler lors de mon intervention pendant le Crypto Day de @Maurganecrypto aujourd'hui - si vous avez une question à me poser sur twixtter, posez la en publique. Je ne lis pas les DMs, et ça permet de toucher plus de monde.
3
3
18
1,503
Nicolas Bacca retweeted
Meet DART. We build the technology that finds, secures, and returns lost crypto. Alongside independent white hats, we rescued over 50 BTC exposed by the COLDCARD entropy flaw. Now held in trust pending ownership verification and lawful return.
2
4
17
969
Nicolas Bacca retweeted
Nicolas Bacca co-founded Ledger. He is now a researcher at @zknoxhq, and he joins ETHSofia on 24 September. @BTChip is on "The Custody Paradox: Security, Usability, and Who Gets to Verify", the panel that puts hardware wallet makers on one stage. His own work is making hardware security open, understandable, and affordable to all, now accelerated with AI. A useful bias to bring into a room of competing security models.
1
5
15
313
Nicolas Bacca retweeted
9
28
232
9,633
Gud setup, the key (pun intended) is to be able to gradually make your self custody setup better (up to whatever you want, inheritance, social recovery, the sky is the limit) without changing your address. Do it yesterday.
Bold is the tree hiding the forest of friends who gave up on self-custody. After a decade, we simply did a poor job of educating people on how to use the chains safely. Stuck between being too dogmatic, pushing for purity of an overly complex system, and too reckless of yolo mode Let me try again; don't just bookmark this do it. Give the link to this tweet to your AI and have it help you: 1) Use @ambire as your main wallet; it handles simulation, complex tx, and is designed to work well with @safe 2) Deploy a Safe now. I don't care if it's a 1/1 linked to your hot wallet for now; it's fine. It's already better this way, and with Ambire, using it is seamless. YOU DO NOT HAVE TO USE THE SAFE UI; Ambire will do it all for you. 3a) Generate a real seed; use pen and paper. You'll get the fancy steel stuff later if you want. 3b) Too lazy for the seed stuff? ok, use a "hotwallet" for your signer generated with a passkeys with an good password manager, you have a Mac? The Passwords app is fine; you're a Revolut client? NordPass is included; you ready to spend a bit? 1Password has a great API, and you'll love it once you're AI-pilled. 5) The signer wallet must hold no funds, doesn't hold gas, doesn't do any txs; it's the key to unlock the door of your safe; it signs, and that's it. You'll learn later that proposing (creating tx), signing, and executing tx are 3 different jobs that don't need to be done by the same wallets. 6a) Now create a second hot wallet, "executooor," and send some gas to it, a few bucks of ETH suffice. Use gas.zip to have some gas on every chain you use. 6b) Don't want to do that? No worries, use the "gas tank" feature on Ambire; it does the same job you can always improve later. That's it for step one, and just that you're safer than Bold and 99% of guys out there. Step 2 is buying a hardware wallet and rotating the safe signer with it for much safer holding Once you're there, you can start considering a 1/2 with a second hw or with an old phone you have in your drawer that you've factory reset and will use only for that. You keep it out of easy reach; it's your insurance if something bad happens to your main signer. Then maybe a 2/3 and the nerdy stuff; you can always do "better," but the foundation of all that is getting your first safe deployed and climbing from there. Do it now; it's not hard, it's worth it.
1
15
1,995
Nicolas Bacca retweeted
I'm building a strange harness — Autonoetic 1 bet: 1 agent that mechanically knows itself, and what every other party is owed, can be a trusted member of a community mixing AI + humans under 1 signed law enforced in code (+ other concepts) The essence of society: rights + duties!
1
1
253