For wallet recovery or private support, request it here cryptoguide.tips/recovery-se… GPG: 7c81 7290 6b9a 7eaf 9f0b d8f1 62a1 d33e 233c 8ea0

So got secure boot implemented on Luckfox pico which closes a persistent security limitation when running on Raspberry Pi :) Also finally got a bunch of 2.8 inch displays that were stuck in customs, so can make some boards available for folk to beta test next week some time.
1
6
44
1,741
Crypto-Guide retweeted
👻Specter-DIY v1.10.5 is out 🔐 Security hardening for randomness and transaction verification: - TRNG fails safely - Stricter change-output verification - Mixed-wallet input warnings restored - Reproducible builds fixed github.com/cryptoadvance/spe…
Made with AI
9
35
94
12,574
No Pi, no problem. Shieldsigner running @SeedSigner on Luckfox Pico Mini :)
7
15
88
3,918
No Pi, no problem.. Luckfox pico mini plus hat looks pretty good, lower profile camera helps too :) Will get a basic reference case and should be ready to roll for folk who want to beta test shortly :) Luckfox pico devices supported on Shieldsigner (@SeedSigner smartcard fork)
9
13
67
3,444
Coldcard had three sources of entropy sitting inside it from day one. Only one of them was plumbed in. New video: where hardware wallets actually get their randomness, why Coldcard's design was always weak, and why most other wallets would have been fine piped.video/di-R_soeBe8
6
15
69
8,263
Same bug on any of these would have been survivable.
7
257
Worth naming who got this right, because most of the market did: @Trezor mixing device and host entropy since day lne @Blockstream Jade pulling from every layer @ShiftCrypto BitBox02 same @FOUNDATIONdvcs Passport, added multi-source entropy as one of its first changes
4
2
15
583
Crypto-Guide retweeted
🚨Announcement: Krux has a new lead maintainer We're pleased to announce that Krux has a new lead maintainer @JohnDoe_le_frog Jean joined Krux years ago, initially as a skeptic. He started with a deep jaw-dropping investigation into Krux's flash storage...
24
41
181
25,573
Crypto-Guide retweeted
I've been sitting on an article about the DIY signing device ecosystem for way too long. @BitcoinMagazine isn't accepting outside submissions anymore. Who's got a platform that I can guest publish this on? @SeedSigner @SpecterDIY @selfcustodykrux #Kern @YTCryptoGuide @satochip
51
62
305
13,103
Crypto-Guide retweeted
Want to give an update on AI scans b/c a few people have asked about it. Over the last week and a half we have received a *lot* of results from automated scans using Kimi K3 and similar tools from the bitcoin red team and from individuals. @newtonick, @KeithMukai and some of our other regular contributors have evaluated all of those submitted, with people like @YTCryptoGuide providing great perspectives as well. Our sense right now is that none of the identified issues are considered critical, and that all of them require a compromised malicious coordinator to attempt the given exploit. To date, we haven't seen or heard about any instances of a malicious coordinator attempting to execute one of these kind of attacks. There are some mitigations our devs can put into place to solve for identified edge cases, and we are planning a near-term release with those fixes (targeting the end of this month). To serve their designated purpose, wallet coordinators have to connect to the bitcoin network and are in turn of course exposed to the wider internet. If you have concerns about your wallet coordinator, consider migrating to a fresh install on a separate machine that is not your daily driver where you browse the internet, open emails, etc. etc. Another option is to use a security-oriented Linux live USB like Tails, and then install Sparrow or another coordinator in that environment. There are also projects like DTails (dtails.gitlab.io) that can pre-install Sparrow or other bitcoin tools in a bootable image. There were no SeedSigner-related vulnerabilities identified involving bitcoin at rest, so waiting until our next release before you make a transaction is reasonable too. These AI vulnerability scanning tools will likely continue to surface security issues in many bitcoin tools, and in the broader infosec landscape, for at least the next 12-18 months at least. This will likely continue to be a tumultuous time and is a good reminder for us all to think carefully about our own cold storage setups and what risks we may, and may not, be exposed to. Multi-vendor, multi-sig wallets continue to provide the strongest assurances in the current adversarial environment.
6
16
80
17,953
Crypto-Guide retweeted
Someone ordered the fully transparent Smartcard SeedSigner. Combined with the new white PCBs and white buttons gives a great result!
19
10
180
11,031
Crypto-Guide retweeted
Highly recommend @YTCryptoGuide for one on one support in the bitcoin space. I’ve learned so much from his channel/privately. New video dropped today regarding the coldcard situation. piped.video/GQOoONFuDE0?si=4L1e…
2
11
371
Crypto-Guide retweeted
Seedsigner sim progress, full camera working & smartcards mocked. First version live soon on the Bitsaga website. Learn multi-sig hands on ^^
Seedsigner running in browser, including (real) camera and (fake) smartcard functionality ^^ Full interactive tutorial soon.
4
6
39
9,362
Crypto-Guide retweeted
The amount of sociopathy it takes to still be selling exploitable products to people. What on gods green earth is wrong with you @nvk
82
103
1,071
124,770
Crypto-Guide retweeted
Made a little program that shows how bad the coldcard bug is. A duplicate wallet on average would have been created every ~1.3 million seed generations. Took 4.7 seconds to find a collision on my M1 Max...
94
217
2,481
367,318
Crypto-Guide retweeted
I'm a software engineer with an MSc in Computer Science and 25+ years in the industry. Here's why Coinkite's Coldcard bug isn't an oopsy, it's disqualifying. Coldcard's seed generation silently fell back to a non-cryptographic "random" number generator for 5 years. Not because crypto is hard, but because Coinkite violated the most basic rule of secure system design: fail closed, never open. When a security-critical path can't be verified, the system refuses to run and throws an error. It does not quietly substitute something weaker and carry on. This code should have refused to produce a seed. Instead it produced a predictable one and continue silently. ☠️ A company that lets its most critical code path go unverified for half a decade cannot be trusted with your keys. Throw away your Coldcards. Never buy one again.
165
449
3,619
225,207
So anyone who generated a seed on a @coldcard since 2021... If you are using BIP85 for other wallets, without using a passphrase or multisig, you need to move funds off those child seeds immediately too. (They will almost certainly be drained in the next 24hrs)
4
3
20
1,386
Had a look at the @Keycard_ Shell. Great option to split hardware in such a way as to remove vendor trust. (Works great with DIY flashed Javacard) piped.video/5NPP4c0D2FM Core functionally of my @SeedSigner fork (Shieldsigner) but available to normal folk as a retail offering :)
5
5
28
4,309