slush retweeted
Sorry, the video is in Portuguese 🇧🇷, but this is the first real demo of my Tropic Key project! 🌴🔐 In the video I: • Unlock the password manager using the Tropic Key • Generate and display a TOTP code • Show the encrypted password storage • Connect the browser extension to the desktop app • Autofill a login and password • Log in using a passkey, similar to the Windows Hello experience The hardware, desktop app and browser integration are finally talking to each other. Still a prototype, but it works. 🚀 @Trezor @tropicsquare
2
2
19
1,802
slush retweeted
It’s been 4 years of not knowing who our customers are. Vexl started as a gift to the Bitcoin community from @satoshilabs — to bring Bitcoin back to its original idea: peer-to-peer currency, without centralized intermediaries. Since then, 20,000 people across 100+ countries have joined Vexl. And the numbers keep growing 🚀 We know KYC sucks. So, just this once, we’re rewarding you for the pain. 👉Drop your worst or most ridiculous KYC experience below. Worst one gets a Vexl merch pack 🎁😎
15
19
59
5,021
This is *not* about Trezor. Also, this is textbook FUD - riding on Coldcard and AI fear-mongering without naming a single concrete detail. Make it actionable or STFU.
11
7
209
16,904
In 2016, we did a major overhaul of the Trezor website and switched the narrative from "wallet" to "signing device." Few people know this, but Trezor could act as a signer for SSH, GPG, U2F, and FIDO2 almost from day one. Sales dropped to near zero overnight. Nobody knew why to buy a signer - everyone was looking for a bitcoin wallet. We reverted within three days. So @Excellion opinion isn't unpopular. It's just naive.
Unpopular Opinion: We should rename “Bitcoin hardware wallets” to “Bitcoin signing devices.” It’d fix so many problems in understanding for Bitcoin beginners and make it evident why a passphrase is needed. Everything is a @SeedSigner with extra steps and tradeoffs.
25
33
703
76,606
Yeah, because for normies this is not confusing at all. /s You have to connect your signer to see money in your wallet.
We agree so much we already did it. Last October at Op3n we retired "hardware wallet" for "signer," and Ledger Live became Ledger Wallet. Two words, two jobs. The signer is the hardware that proves intent and consent. The Wallet is where you actually buy, swap, and stake. And signers matter even more now. Deepfakes can clone your face and your voice. They still can't press your button.
2
1
24
3,324
Agree fully - it isn't even a debate. There's no reason to trust something fully closed and unauditable. Yes, even some "open" solutions aren't open enough yet. But it's a journey, and the world is clearly moving from "trust me bro" to decentralized, auditable systems - because they're simply less fragile. Bitcoin has a long history of failed "trust me bro". Don't repeat it. And yes, AI is teaching us a lesson now. The answer isn't to close everything back up - it's better architecture and better engineering. Closedness and "trust me bro" are the enemy.
For Ledger, open source vs. closed source isn't a debate. They both have purpose and merit. In the wake of the recent industry exploits, Ledger CTO @P3b7_ explains why open source is great, but isn't a security property.
5
22
146
19,358
If an enemy wants you to panic to drive you into their flanking manouevre, the best move is to not panic and hold the position. Close the ranks, keep the line tight and dig in.
18
27
277
13,972
That's literally how I've lived for the past decade: everything offline or self-hosted, unreachable from the Internet.
the internet may become a dark forest
2
2
87
9,689
Running Deepseek V4 Flash 0731 @ 1M context and I'm stoked. Refuses nothing and the speed is stupid. I barely see the difference between DS4 and Opus anymore.
8
2
60
5,472
JFYI I cloned Coldcard firmware from Jan/2026, asked Deepseek for security audit and it spotted the RNG issue correctly at first try (without searching in internet, of course).
3
2
23
1,337
This is how over-reaction look like, folks. What absolutely terrible advice - using custom, vibe-coded software on a standard computer to generate recovery seeds. This is a disaster in the making.
Rolling a die 60 times takes 2 minutes. Converting it to a seed phrase takes 1 minute. Is your Bitcoin worth 3 minutes of your time?
48
40
517
34,820
slush retweeted
You don’t have to go through KYC to buy Bitcoin. Be like Ralph. No KYC. No pain.
4
13
62
5,509
Biggest self-custody heists: 2018 - Low entropy paper wallets 2026 - Low entropy HW wallets 2032 - Low entropy dice-roll wallets
25
20
178
16,446
slush retweeted
Multiple entropy sources are only worth something if the code actually uses them. You can have four different sources of randomness in the device, but if it is using a test generator instead (code bug), none of those sources actually matter. Rolling dices doesn’t imply the device will actually use it. The entropy is not the problem here, the problem is the device not using it. We already explained that Trezor does not use the affected code. Here are some examples of what we are already doing to make sure we do not accidentally bundle in testing RNG (random number generator): 👉 We do not use MicroPython's random module at all. It is disabled outright in our firmware config [1]. 👉 rng_fill_buffer() reads the STM32 TRNG peripheral registers directly. No macro dispatch, no software path to fall through to [2]. 👉 The software PRNG lives in a file literally named "crypto/rand_insecure.c", and compiling it emits "NOT SUITABLE FOR PRODUCTION USE!" warning [3]. 👉 random.reseed() exists only under ifdef TREZOR_EMULATOR, and the C function behind it only under USE_INSECURE_PRNG. Two independent guards, and no reseed API in production firmware at all [4]. 👉 rng_fill_buffer_strong() fills from the MCU TRNG, then XORs every byte with Optiga output (Safe 3, Safe 5) and, on Safe 7, Tropic output on top. If a secure element fails it returns false and the caller raises RuntimeError. Fail-closed, not fail-quiet on models with a secure element [5]. 👉 Our Entropy check makes sure that the host’s (computer/phone) RNG is mixed in as an extra failsafe [6]. These are just some examples of how we protect from this kind of failure. That being said we never stop building and we always humbly learn from situations like these. So we are carefully studying what lessons can be learned from this incident and we are already drafting more safeguards on top [7]. You don’t have to trust me on this, our code is open-source and you can see for yourself or use your favorite AI model. See the links below. And don’t forget to ask your wallet if they can do the same… [1] github.com/trezor/trezor-fir… [2] github.com/trezor/trezor-fir… [3] github.com/trezor/trezor-fir… [4] github.com/trezor/trezor-fir… [5] github.com/trezor/trezor-fir… [6] trezor.io/learn/security-pri… [7] github.com/trezor/trezor-fir…
22
43
345
53,070
This is common misunderstanding that the problem is somehow specific to HW wallets only. Such problem happen to Mycelium, which used broken RNG on certain Android phones. This vector is not a property of being HW wallet. It is property of devs not understanding their stack.
Every hardware wallet producer is now sweating and reviewing their cryptography. Every hardware wallet user is now sweating to figure out a better wallet setup. Right??
12
14
160
16,915
Trezor is mixing entropy from several sources since early prototypes in 2013, to prevent exactly what's happening now to some hw wallets (and what happen before to some software wallets, too). 👇
Randomness is the foundation everything else in a hardware wallet stands on. Get it wrong and nothing else matters. Not the secure element, not the air-gap, not the metal backup. Weak entropy during initialization = funds drained "remotely." No device access needed, attacker just recomputes your keys. It's the single most critical path in a hardware wallet, and we treated it that way from the very first Trezor Model One (just turned 12 years old!) by mixing device entropy with entropy from the host (computer or phone). Never trust one source. We deliberately designed it this way from the very beginning. The nightmare scenario is that test mode with weak randomness is shipped by accident. People think their wallet generated something truly random but it didn't. Anyone who knows the pattern can work backward and recreate their private keys and AI is definitely speeding this up. We run dedicated safeguards to make sure that can never happen in our builds. Trezor Model One and Model T mixed two entropy sources together (from MCU and from the host). With Trezor Safe 3 we took this further and added Optiga as an independent entropy source. Safe 7 mixes four: MCU, host, Optiga, TROPIC01. On all models this results to 128-bit entropy in default settings. On top of that, we also introduced Entropy Check back in February 2025. From a different angle: Let's finally retire the myth about air-gap. Air-gap doesn’t necessarily imply stronger security. With air-gapped wallets you miss this entropy from the host. If the randomness is not sufficient and keys are predictable, the attacker never needs to touch your hardware.
16
38
462
112,665
Nothing is more permanent than a "temporary" tax.
6
1
66
3,962
Czech here. Went to the US. Made the mistake of honestly answering "how are you?". Never again. 🫠
One of my old coworkers lived in Finland for a decade, and she said her outgoing, chipper personality resulted in her being almost completely isolated. So isolated in fact that she started a multicultural society for other immigrants from around the world who were experiencing the same thing. I think I would lose my mind.
19
11
1,264
147,350
Learned about this "workaround" earlier today from this tweet, just to experience the exact same situation right now. And it wasn't even a frontier model - just Deepseek V4 Flash running locally 😅
Codex just found a “workaround” of not having sudo on my pc…
5
10
3,733