Last update: 2026-08-30_Sun_22.36h (Amsterdam time)

Change your preferences in LoyceV's notification bot.
See Notifications for others.

LoyceV receives Notifications when he's quoted or mentioned

Ignore list:
Posts from these users are ignored:
1. Timelord2067
2. LoyceV
3. wolwoo
4. Bitcoin SV
5. The-One-Above-All
6. Excimer
7. truth or dare
8. bonesjonesreturns
9. KaneVWE
10. Laudanum
11. Quantum_Resolve7987V
Posts in these topics are ignored:
1. [ТОП-200] Щедрые пользователи, дающие мериты
2. [TOP-200] Members who support newbies - Thanks!
3. [TOП-200] Пoльзoвaтeли, пoддepживaющиe нoвичкoв - Cпacибo!
4. Time Series Analysis on Distributed Merits in the forum (daily, weekly, monthly)
5. [CLUBS] Top Merited-Users Classified into 4 Clubs
6. Interquartile range of intra-day merits with time series plot
7. Timelord2067's Timely Test and Main-neT LighTning Loans to a "T"
8. Weekly earned merits (median) of top 100 merited users
9. The active levels of sent/earned merits of users , excludes autobanned/ nuked
10. Bitcointalk Merit Dashboard


Username "LoyceV" occurred in the following posts (quoted and/or mentioned):


1. Post 67096562 (unedited backup) (by PrivacyG) (scraped on Sun Aug 30 22:30:13 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: LoyceV on August 28, 2026, 03:51:58 PM
How does that work? Say you have a Trezor: do you enter that complex seed extension each time you use the device, using those 2 small keys scrolling through characters?
I have some experience with both kinds of Hardware Wallets.  The button kind and the touch screen kind.  Both are absolute horror to use for complex keys, but I believe buttons do have a some what advantage considering the touch screen ones are easier to mistype on.



2. Post 67095294 (unedited backup) (by vapourminer) (scraped on Sun Aug 30 14:27:31 CEST 2026) in 2TB or 4TB drive upgrade?:

Quote from: LoyceV on Today at 10:07:49 AM
if the SSD gets corrupted my backup does too.
So it's not a backup Shocked
[...]
Have you considered creating daily snapshots instead of overwriting your old backup each day? Something like this:

ZFS does snapshots so im covered there. i run TrueNAS with zfs level 2 (5 drives, any 2 can die).

but you are right, backup is not raid



3. Post 67095272 (unedited backup) (by DaveF) (scraped on Sun Aug 30 14:13:01 CEST 2026) in 2TB or 4TB drive upgrade?:

Quote from: DaveF on August 27, 2026, 02:01:17 PM
Just did a test for the heck of it. 6th gen i5 *4* GB of ram 2TB ssd that is really old.
From a couple of hours of when you made this post till now. Still syncing, should be done when I get home from work. Shows 98% as of now but I have to run out the door to get to the office.
Can you check how many TB was written to that SSD? I tried this a while ago with 8 GB RAM, and it wrote several TB already due to the lack of RAM.
I must say I'm surprised this takes 8-ish days. Assuming your internet speed isn't the limiting factor: do you have one of those SSDs with bad sustained write performance? You make me want to test this again.

It's a 10 year old system with an 8 or 9 year old SSD. Was not a great performer back then. Will see what I can see about writes when I get home, more likely over the weekend.

......

Just finally remembered to check. 2.4TB written since last boot.
So figure about 2.8x the IBD size.
Not the worst since due to the lack of RAM there would be a lot of stuff coming on and off the temp.

Was kind of an interesting experiment, have done it a few times before.

But, yes you can fairly easily run a node on hardware that is a decade old even with a SSD of about the same vintage.

-Dave



4. Post 67095256 (unedited backup) (by bitmover) (scraped on Sun Aug 30 14:04:37 CEST 2026) in [ANN] bitcoindata.science:

Quote from: Pmalek on Today at 07:08:33 AM
Don't blame bitmover, it's my server that's "missing". It makes me think of the scene in Silicon Valley where they threw all their servers at the back of a rental van.

Update: it's back online Smiley
The only logical explanation is that they are following this thread, they saw my post, they put all their manpower on the task of bringing your server back online, and now everything is back to normal. Cheesy


This actually happened in Twitter. Elon musk himself rented trucks and put Twitter data center computers inside trucks   Grin

Full history here

Quote
At 3 p.m., after they had gotten four servers onto the truck, word of the caper reached the top executives at NTT, the company that owned and managed the data center. They issued orders that Musk’s team halt. Musk had the mix of glee and anger that often accompanied one of his manic surges. He called the CEO of the storage division, who told him it was impossible to move server racks without a bevy of experts. “Bulls---,” Musk explained. “We have already loaded four onto the semi.”
https://www.cnbc.com/2023/09/11/elon-musk-moved-twitter-servers-himself-in-the-night-new-biography-details-his-maniacal-sense-of-urgency.html



5. Post 67094768 (unedited backup) (by Hatchy) (scraped on Sun Aug 30 09:52:02 CEST 2026) in [allowed?] Posting Monero crypto shop project in Service Announcements:

Quote from: LoyceV on Today at 06:20:08 AM
I know the Services board is supposed to be only for Bitcoin-related services, but recently my report on a dollar campaign was marked Bad, and I don't really get why.
I think this was most likely marked as bad because the reward was paid directly to their casino account at $50. The instructions also didn't specifically say that they needed to provide a USDT address for the reward.Since the reward goes directly into their casino account, they can withdraw it in any supported cryptocurrency, so I think it can remain under the Bitcoin service section.
Quote
Deposit $50 and wager at least 5x through at least five Frogbet Original games, post your honest review, and receive a $50 wager-free cash reward directly into your account.

Quote
That brings me to the Service Announcements board: would it be allowed to promote a Monero crypto shop project there? It's now in Service Announcements (Altcoins), and I think it doesn't get the attention it deserves there:
It's a bit of a pity that I can't promote a service associated with a different cryptocurrency.
Since it's specifically monero I doubt it will fit that board. Buh I do come across brands that offers multi chain services there on the bitcoin service announcement..let's see what the mods have to say about it.



6. Post 67094696 (unedited backup) (by Pmalek) (scraped on Sun Aug 30 09:08:38 CEST 2026) in [ANN] bitcoindata.science:

Quote from: LoyceV on August 29, 2026, 07:41:16 AM
Don't blame bitmover, it's my server that's "missing". It makes me think of the scene in Silicon Valley where they threw all their servers at the back of a rental van.

Update: it's back online Smiley
The only logical explanation is that they are following this thread, they saw my post, they put all their manpower on the task of bringing your server back online, and now everything is back to normal. Cheesy

Quote from: LoyceV on August 29, 2026, 02:25:29 PM
Let's test this with Pmalek's list:
...
Don't beat yourself up, creating 95 dynamic images instantly is a lot to ask.
Yeah, most of the images don't load. But the way it is now it's already working so that is great.
@bitmover I wouldn't lose any sleep over it.



7. Post 67094655 (unedited backup) (by Wind_FURY) (scraped on Sun Aug 30 08:40:01 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: LoyceV on August 28, 2026, 08:55:10 AM
Just reading this on reddit. It seems the hacker is trying to move the money but still not smart enough to do that.


The "hacker" should have used ThorChain, and swapped the stolen Bitcoin to Monero


The hacker can read advice on what to do from all those people who call him "not smart enough" Tongue
From the Reddit screenshot: 64 BTC in, 54 BTC traced out. That means 10 BTC is now hidden (and people who had nothing to do with this hack now own 10 BTC from this hack).


Technically those UTXOs are all mixed now, which means that those people who had their outputs with the hackers' outputs during the mix are possibly holding some of the hackers' coins.

  ¯\_(ツ)_/¯

It may matter for some of the people who are looking at the blockchain, but from the viewpoint of the network - it doesn't. A UTXO is a UTXO.



8. Post 67094364 (unedited backup) (by pbies) (scraped on Sun Aug 30 02:37:25 CEST 2026) in List of all Bitcoin addresses with a balance:

Quote from: LoyceV on August 29, 2026, 03:21:56 PM
It occurred to me....
What if I provide uncompressed text-files? Would that work with rsync? I've never used rsync to a public location. It would save so much bandwidth if only the removed/added addresses have to be downloaded each day!
Alternatively: what if I provide only a list of changes, that users can easily add on their own each day? It could even be a daily list of changes from the past week, so downloading once a week is enough to be up to date again.
Thoughts?

You would need to host "diff" files. Much work on client side to update the file.

Also .txt goes full size thru Internet (can be even packed in the air but still bandwidth takes whole file) so loss of bandwidth.

I don't like neither of these solutions. My own opinion.



9. Post 67093149 (unedited backup) (by bitmover) (scraped on Sat Aug 29 18:38:43 CEST 2026) in [ANN] bitcoindata.science:

Quote from: LoyceV on Today at 02:25:29 PM
Don't beat yourself up, creating 95 dynamic images instantly is a lot to ask.

Thanks. Yeah, still need to work on that.

I will use your post to test and see if i can still improve performance with small changes



10. Post 67092855 (unedited backup) (by albert0bsd) (scraped on Sat Aug 29 16:51:25 CEST 2026) in List of all Bitcoin addresses with a balance:

Thank you loyceV for the rsync Grin

Here is my mirror:

Code:
https://addresses.albertobsd.dev/

I remove LATEST symlink file to avoid people trying to update it each 3 minutes, All other files will be there.



11. Post 67092629 (unedited backup) (by Lucius) (scraped on Sat Aug 29 15:34:25 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: BlackHatCoiner on August 28, 2026, 04:16:16 PM
This sounds like having a dedicated airgapped computer for bitcoin with extra steps.

Am I the only one who just does not trust neither Trezor nor Ledger? The whole point of using separate hardware is so that you do not put any trust on neither the computer nor the coordinator wallet software running (such as Sparrow), but I feel like there are far more attack vectors that can be exploited to a hardware wallet that connects with the computer, than a signing device that is airgapped.


Not a single hardware wallet that you have to connect to an online computer to function is on my list of devices I trust, although I have a Trezor that I use for amounts I can afford to lose. The only thing I still have some confidence in are air-gapped wallets, but even there things are clearly not completely secure considering what happened.



Quote from: LoyceV on August 28, 2026, 03:51:58 PM
I am advocating for using complex passphrases as seed extensions, though.
How does that work? Say you have a Trezor: do you enter that complex seed extension each time you use the device, using those 2 small keys scrolling through characters?

You buy hardware wallet that has a physical keyboard and if you still remember how we used to write SMS messages on the good old Nokia 3310, you won't have any problems entering a 15-20 character passphrase.




12. Post 67092183 (unedited backup) (by bitmover) (scraped on Sat Aug 29 12:15:37 CEST 2026) in [ANN] bitcoindata.science:

Quote from: LoyceV on Today at 07:41:16 AM
Any idea what could have happened? Did something maybe change on your end recently?
Don't blame bitmover, it's my server that's "missing". It makes me think of the scene in Silicon Valley where they threw all their servers at the back of a rental van.

Update: it's back online Smiley
Great that everything is working again.

A few months ago I made a small change recently that had a huge impact on performance (i changed the name of the image files in my server, making them more unique), so I think now my server would be able to handle all calls from your table  simultaneously.

Later on if there is any problem with LoyceV proxy, you can try to make the calls direct to bitcoindata.science. I think they will work.



13. Post 67091967 (unedited backup) (by Real-Duke) (scraped on Sat Aug 29 10:42:55 CEST 2026) in LoyceV's 0.1 sat/vbyte Electrum Server Adventure:

Quote from: LoyceV on Today at 05:33:32 AM
Update: it's back!

Just tested -> works again! Cool



14. Post 67091846 (unedited backup) (by MisFoxie) (scraped on Sat Aug 29 09:29:25 CEST 2026) in [Userscript] Highlight to Profile- highlight any username to get profile links.:

Quote from: LoyceV on Today at 07:13:12 AM
When a username is selected, a small box appears just below it
What happens when you select something else? Does this affect the default copy (CTRL-V) feature?
No, It doesn't cause any effects in normal ctrl+c and Ctrl+v..

If something looks like username only then it send request. When a user select more than 4 words nothing will appear. If a username is too long selecting half of the text may bring the actual results.
 
Quote
Highlighting ordinary prose like "for the data" sends no requests at all..

Highlights longer than 25 characters or more than 4 words are ignored on purpose



15. Post 67091820 (unedited backup) (by Pmalek) (scraped on Sat Aug 29 09:09:13 CEST 2026) in [ANN] bitcoindata.science:

Hi bitmover,

All the images in my Withdrawal Fees and Withdrawal Amounts on Crypto Casinos thread are down at the moment. I noticed it late last night. Any idea what could have happened? Did something maybe change on your end recently? I will tag @LoyceV as well since I am also getting data from his for that table of mine.



16. Post 67090961 (unedited backup) (by Ambatman) (scraped on Fri Aug 28 23:32:02 CEST 2026) in What was the price value of bitcoin?:

Quote
Bitcoin's starting value was 0. Maybe how did it create a value through the first trading?
The estimated mining  cost was used in setting  the price then
And the first seller was a user here Sirius to
 
Quote from: LoyceV on Today at 05:08:38 PM

Supply and demand. It's the same for every other thing being sold: a seller and buyer agree to a price.
I will also be sharing this that was stated by DdmrDdmr some years ago

Quote from: DdmrDdmr on October 05, 2021, 12:20:28 PM

As said, offer and demand did not set the price back then (initially), but rather the above formula that ensured covering costs. The variation in price from one day to another is, I figure, due to the change in the "bitcoins generated by my computer(*) over the past 30 days" part, which will change as the 30 day window slides forward another day. Later on, price calculus was modified to include moving averages and the cost of data bandwidth.



17. Post 67090765 (unedited backup) (by takuma sato) (scraped on Fri Aug 28 22:28:07 CEST 2026) in Privacy problems with Windows GDID:

Quote from: LoyceV on Today at 09:49:16 AM
I have never seen a Lenovo computer that did not come with Windows preinstalled.
They're quite common on Amazon Germany. I bought one years ago (and had to replace the German keyboard).

Im not sure im following as when I read your link I cannot really find something that says it doesn't come with Windows pre-installed. In fact as far as I can tell the Amazon link says that it comes with Windows 11 pre-installed.

Brand    Lenovo
Model name    83GW007YGE
Screen Size    15.6
Colour    unknown
Hard disk size    512 GB
CPU model    Intel Core 7
RAM memory installed size    8 GB
Operating system    Windows 11 Pro
Special feature    Numeric Keypad
Graphics card description    Integrated


Edit: Oh wait it says so on the title, FreeDOS, so Im assuming it comes with that and the Amazon details are not accurate. Well that's really cool but how common is it to find these? Never seen it before. Also most nice Thinkpads that you can install a free BIOS at are older models and from what I've seen all used models were originally pre-installed with Windows before the owner installed Linux and flashed the BIOS.



18. Post 67090427 (unedited backup) (by joker_josue) (scraped on Fri Aug 28 20:51:31 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: LoyceV on Today at 05:05:35 PM
Stateless, opensource airgapped signers with optical QR communication are the only true way to eliminate host machine trust.
I've never used those, but I've always been curious: how do you know for sure the QR isn't compromised? I'd wouldn't feel completely safe without decoding the QR on another air-gapped system.

With Seedsigner, you manually copy the QR code yourself. Therefore, it's up to you to ensure it's correct.
Then, to validate, you can use an old mobile phone, without an internet connection, to read the QR Code and check if it matches what was supposed to.

I haven't tested this system yet, but I've read good feedback about it.



Quote from: Meuserna on Today at 05:53:04 PM
Airgapped means the device never connects to the internet, or to anything at all. The device communicates using a camera and a screen. Hackers can't reach it over the internet.

Stateless means my seed is never saved on the device. When the device turns off, the seed and the wallet are wiped. If the device gets lost or stolen, no worries. There's nothing on it.

I never save my seed on any device, ever.

The issue is saving the QR code to validate transactions.
The person must take care to keep it well stored. It's also not the solution for crates that are used more frequently.



19. Post 67090188 (unedited backup) (by Danish Ali) (scraped on Fri Aug 28 19:45:25 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: BlackHatCoiner on Today at 05:09:34 PM
I've never used those, but I've always been curious: how do you know for sure the QR isn't compromised? I'd wouldn't feel completely safe without decoding the QR on another air-gapped system.
The signing device displays on its little screen what inputs you spend and what outputs you create (which addresses are being paid), therefore you don't trust the coordinator software for sending a compromised QR image. 

Unless you're asking how do you know that the compromised QR image doesn't exploit a vulnerability that would allow the attacker to compromise your funds. For example, a compromised QR image could be a series of bytes that disable something in the firmware, but this is another level of paranoia for the sake of the discussion. What matters is that it can't steal your randomly generated seed phrase.

BlackHatCoiner explained the visual verification logic perfectly.

Beyond that, stateless signers also rely on open-source reproducible builds and standardized PSBT specs (BC-UR v2) to ensure the QR data payload isn't modified or leaking key material.

I did a detailed breakdown on their security models here:

https://bitcointalk.org/index.php?topic=5591374.msg67049627#msg67049627



20. Post 67090125 (unedited backup) (by Meuserna) (scraped on Fri Aug 28 19:31:25 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: bitmover on Today at 12:18:50 PM
And I firmly believe Ledger's key extraction scheme is a disaster waiting to happen.
For now, the extraction must be physically authorized in the device.
Is that a hardware limitation, or is it just the firmware telling you you need to authorize it? I'm pretty sure a cracked firmware wouldn't need your consent, and thousands of hackers can peacefully try to hack the device from their own home.

This is how it was designed. Without your PIN, the seed doesn't leave the device.

Quote
Plus, your Ledger will only allow your seed phrase to leave the wallet as encrypted fragments when you permit it. Setting up Ledger Recover requires you to enter the device PIN and consent to start the process on the device. Without your permission, the device will not (and cannot) fragment or send the encrypted fragments anywhere. That means if someone wants to exploit Ledger Recover to steal your seed phrase, they would need to have your PIN in the first place, which would already give them access to your wallet.
https://www.ledger.com/academy/what-is-ledger-recover

Surely you realize quoting Ledger about their closed source code is the same as quoting Coinkite about ColdCard's closed source code. In May, they said it was the best. How'd that work out?

I do not understand why people trust code that isn't open source. It makes no sense.

In theory, you know how Ledger's code is supposed to function, according to Ledger. But hackers aren't going to use the code as intended. They're going to find exploits. And since Ledger devices have the ability to export the seed out of the device over the internet (which for years they swore wasn't even possible!), their code is one heck of a honeypot just waiting to be hacked.

And I do not understand why people trust companies after they lied. Ledger said this:

Quote
"Private data, such as your private keys will be protected and never leave the device due to the combination of BOLOS and the Secure Element."

That was a lie. It's one of many lies they had to scrub from their website because their firmware contains an API to extract keys from their devices over the internet, which for years they swore was not possible.

Here's a lie that cracks me up.

Quote
"WE ARE OPEN SOURCE"

That's printed on the box of a closed-source Ledger hardware wallet:
https://i.redd.it/dysdk6j9516b1.jpg

And here's a great quote from BTChip, Ledger owner & co-founder

Quote
There's no backdoor and I obviously can't prove it

He obviously can't prove it, because his code isn't open.

Trusting Ledger's word today is like Trusting Coinkite's word in May.



21. Post 67090087 (unedited backup) (by albert0bsd) (scraped on Fri Aug 28 19:17:55 CEST 2026) in List of all Bitcoin addresses with a balance:

Quote from: LoyceV on Today at 05:03:56 PM
I can rsync them to you the second I update them if you want.

Yes, absolutely. That would be great.

I can set up a dedicated account/SSH key with access only to the mirror directory, so you can rsync the files whenever you update them.

Let me know what you need from my side. Send me a DM if you like



22. Post 67090050 (unedited backup) (by BlackHatCoiner) (scraped on Fri Aug 28 19:09:37 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: LoyceV on Today at 05:05:35 PM
I've never used those, but I've always been curious: how do you know for sure the QR isn't compromised? I'd wouldn't feel completely safe without decoding the QR on another air-gapped system.
The signing device displays on its little screen what inputs you spend and what outputs you create (which addresses are being paid), therefore you don't trust the coordinator software for sending a compromised QR image. 

Unless you're asking how do you know that the compromised QR image doesn't exploit a vulnerability that would allow the attacker to compromise your funds. For example, a compromised QR image could be a series of bytes that disable something in the firmware, but this is another level of paranoia for the sake of the discussion. What matters is that it can't steal your randomly generated seed phrase.



23. Post 67090028 (unedited backup) (by stupid123) (scraped on Fri Aug 28 19:03:31 CEST 2026) in 9 Accounts - Members Report Together - Ask Mods To Remove Their Membership:

Request that members report repeated off-topic posting

Names: collectorbob hybridsole nutildah DireWolfM14 owlcatz Lesbian Cow anonymousminer JollyGood ChiBitCTy.

The same accounts keep showing up in Collectibles Marketplace-related threads Reputation and Meta. They pull the discussion off the original topic. The unofficial guidelines still cover low-value posts off-topic replies and trolling.

Rule 2 is off-topic. Rule 3 is trolling. That means personal remarks baiting pile-ons and turning a listing or policy thread into a fight about another member.

Trust figures below are from the public Default Trust snapshot on LoyceV dated 22 August 2026 (positive / neutral / negative). The last number is default-visible red trust received. On that snapshot these accounts show 0 red trust received and I found no flags received on them. Open the live Trust page when you are logged in. Custom lists can show comments Default Trust does not. I am asking staff to review specific posts. I am not claiming a removal has already been decided.



collectorbob
profile
No public Trust score. 0 posts. 0 activity. Rule 1: zero-value account with no history.
No public posts to cite for Rule 3 yet. Report the account if it starts the same pattern as the others.

hybridsole
profile | trust
Trust received: +20 / =0 / -0
Rule 2: replies in Collectibles and related threads that leave the listing.
Rule 3: those replies turn the thread into a personality dispute instead of answering the original post. Report the exact reply that left the subject.

nutildah
profile | trust
Trust received: +21 / =2 / -0
Rule 2 / Rule 3 examples. Threads that became about this account and other members instead of a listing:
topic 5582921
topic 5118010
Report the posts in those threads that attack the person instead of the original topic.

DireWolfM14
profile | trust
Trust received: +19 / =1 / -0
Rule 2 / Rule 3 example:
topic 5573321
That thread is a rules poll. Replies there leave the poll and go after other members writing and character. Report those replies.

owlcatz
profile | trust
Trust received: +49 / =0 / -0
Rule 3 example. Reputation thread that treats this account as the subject and keeps a personal fight going:
topic 5286509
Report posts that bait or pile on instead of documenting a trade.

Lesbian Cow
profile | trust
Trust received: +45 / =0 / -0
Rule 3 example. Reputation thread that became about the person:
topic 5475948
Report replies that turn a notice or listing into a personal fight.

anonymousminer
profile | trust
Trust received: +39 / =0 / -0
Rule 2 / Rule 3. Named in Collectibles and Reputation discussions that leave the original listing and become about the member. Report the specific posts that do not address the topic.

JollyGood
profile | trust
Trust received: +20 / =2 / -0
Rule 3. Replies that turn a listing into a general argument about other members. Report the exact post that left the subject.

ChiBitCTy
profile | trust
Trust received: +37 / =1 / -0
Rule 3. Pile-on replies after the original subject has already been addressed. Report those follow-ups.



How to report

If you agree a post left the topic or added a personal fight report that post to the moderators and include:
Trading disputes belong in Reputation with dates links and what was agreed.

Work together on this

One report is easy to ignore. A stack of reports with the same profile links the same Trust pages and the same off-topic and trolling posts is harder to set aside. If you have seen these accounts pull threads off the subject or bait a personal fight do not argue it out in the thread. Copy the post link. Open a report to the moderators. Ask them to review whether these members should remain active in Collectibles Marketplace-related boards Reputation and Meta.

Stay on the guidelines. Stay on the record. Send the examples. That is how staff see a pattern instead of nine separate complaints that never get joined together.



24. Post 67089921 (unedited backup) (by MisFoxie) (scraped on Fri Aug 28 18:33:13 CEST 2026) in [Userscript] Highlight to Profile- highlight any username to get profile links.:

Many times, users mention each other but their profile link is not added. However, sometimes we want to visit that profile and at that time we have to copy the username, go to another platform then search for it and then view it. This takes some time and I think it is a bit of a hassle. I suggested this feature before but since I didn’t get any response, I decided to try it myself to see if it was actually possible so I get the help of powerful AI model. I hope you like it.

What this does
When a username is selected, a small box appears just below it showing three types of profiles: a Bitcoin profile, a BPIP profile, and another Bitlist profile.

 Demo:


Install

1. Install Tampermonkey or Violentmonkey (works on desktop Chrome/Firefox/Edge, and on Firefox for Android)
2. Create a new script, paste the code below, save. Or you can directly install from Greasy Fork

https://greasyfork.org/en/scripts/593347-highlight-to-profile-bitcointalk-username-lookup

3. Reload any Bitcointalk page and highlight a username

Code

Code:
// ==UserScript==
// @name         Highlight to Profile - Bitcointalk Username Lookup
// @namespace    https://bitcointalk.org/
// @version      1.1.0
// @description  Highlight any username in a Bitcointalk post to instantly get links to that user's Bitcointalk, BPIP and BitList profiles.
// @author       MisFoxie
// @match        https://bitcointalk.org/*
// @match        http://bitcointalk.org/*
// @run-at       document-idle
// @grant        GM_xmlhttpRequest
// @grant        GM.xmlHttpRequest
// @connect      bpip.org
// @connect      api.ninjastic.space
// @noframes
// ==/UserScript==

/*
 * How the lookup works (endpoints verified live):
 *
 * 1) Ninjastic exact match (JSON, sends access-control-allow-origin: *):
 *      GET https://api.ninjastic.space/users/<username>
 *      -> {"result":"success","message":null,"data":{"author":"LoyceV","author_uid":459836,"posts_count":35579}}
 *      -> {"result":"success","message":"User not found","data":null}
 *    Case-insensitive. Response header x-ratelimit-limit: 100.
 *
 * 2) BPIP username search (HTML, no CORS headers -> needs GM_xmlhttpRequest):
 *      GET https://bpip.org/search.aspx?q=<text>
 *    Result rows contain:
 *      <td data-label="Name"><a href="Profile?p=LoyceV">LoyceV</a> ...</td>
 *      <td data-label="User ID">459836</td>
 *      <td data-label="Position">Legendary</td>
 *    This is a prefix search (max 50 rows), so it also returns near-matches.
 *
 * All three profile links are built from the numeric UID, which is unambiguous
 * and avoids the URL-encoding problems usernames cause:
 *      https://bitcointalk.org/index.php?action=profile;u=<uid>
 *      https://bpip.org/Profile?id=<uid>
 *      https://bitlist.co/user/id/<uid>
 * (bpip.org/Profile?p=<name> works too, but breaks on names with spaces: it
 *  renders the title as "Profile for Sceptical%20Spectacles".)
 *
 * Not used, and why:
 * - BPIP api2/ProfileInfo (the endpoint the official BPIP extension calls)
 *   only accepts numeric user IDs, so it cannot resolve a name to a profile.
 * - BitList has no public API (/api/* and /rpc return 404, and both are
 *   robots-disallowed), so BitList is linked to but never queried. Its route
 *   table (_app/immutable/entry/app.*.js) defines the profile route as
 *   /user/id/[id] -- a numeric Bitcointalk UID, not a username. The older
 *   /user/<username> form does not exist, which is why those links 404'd.
 */

(function () {
    "use strict";

    // ---------------------------------------------------------------- config

    const CFG = {
        NINJASTIC_USER: "https://api.ninjastic.space/users/",
        BPIP_SEARCH: "https://bpip.org/search.aspx?q=",
        BPIP_PROFILE: "https://bpip.org/Profile?id=",
        BCT_PROFILE: "https://bitcointalk.org/index.php?action=profile;u=",
        BITLIST_PROFILE: "https://bitlist.co/user/id/",

        // A selection must look like a username to be worth a request.
        MIN_LEN: 2,
        MAX_LEN: 25,
        // Wait this long after the selection settles before firing requests.
        DEBOUNCE_MS: 350,
        // Never fire more often than this (protects the Ninjastic rate limit).
        MIN_REQUEST_GAP_MS: 700,
        REQUEST_TIMEOUT_MS: 12000,
        MAX_CANDIDATES: 6,
        CACHE_MAX: 300,
    };

    const ICONS = {
        bct: "https://bitcointalk.org/favicon.ico",
        bpip: "https://bpip.org/favicon.ico",
        bitlist: "https://bitlist.co/favicon.ico",
    };

    // ------------------------------------------------------------ GM bridge

    // Tampermonkey exposes GM_xmlhttpRequest, Violentmonkey also exposes
    // GM.xmlHttpRequest. Normalise both into one promise-based helper.
    const gmRequest = (function () {
        const legacy = typeof GM_xmlhttpRequest === "function" ? GM_xmlhttpRequest : null;
        const modern = typeof GM !== "undefined" && GM && typeof GM.xmlHttpRequest === "function"
            ? GM.xmlHttpRequest.bind(GM)
            : null;
        const impl = legacy || modern;

        return function (url) {
            if (!impl) {
                return Promise.reject(new Error("GM_xmlhttpRequest unavailable"));
            }
            return new Promise(function (resolve, reject) {
                impl({
                    method: "GET",
                    url: url,
                    timeout: CFG.REQUEST_TIMEOUT_MS,
                    headers: { Accept: "text/html,application/json;q=0.9,*/*;q=0.8" },
                    onload: function (res) {
                        if (res.status >= 200 && res.status < 300) resolve(res.responseText);
                        else reject(new Error("HTTP " + res.status));
                    },
                    onerror: function () { reject(new Error("Network error")); },
                    ontimeout: function () { reject(new Error("Timed out")); },
                });
            });
        };
    })();

    // ---------------------------------------------------------------- helpers

    function esc(text) {
        return String(text).replace(/[&<>"']/g, function (c) {
            return { "&": "&amp;", "<": "&lt;", ">": "&gt;", '"': "&quot;", "'": "&#39;" }[c];
        });
    }

    // Bitcointalk usernames allow letters, digits, spaces and punctuation.
    // Reject anything that looks like a sentence rather than a name.
    const STOPWORDS = new Set([
        "a", "an", "and", "are", "as", "at", "be", "but", "by", "for", "from", "has", "have",
        "he", "her", "his", "i", "if", "in", "is", "it", "its", "me", "my", "no", "not", "of",
        "on", "or", "our", "she", "so", "than", "that", "the", "their", "them", "then", "there",
        "they", "this", "to", "up", "was", "we", "were", "what", "when", "which", "who", "will",
        "with", "you", "your",
    ]);

    function looksLikeUsername(text) {
        if (text.length < CFG.MIN_LEN || text.length > CFG.MAX_LEN) return false;
        if (/[\r\n\t]/.test(text)) return false;
        if (/[,.;:!?"\u201c\u201d]\s/.test(text)) return false;
        if (!/^[A-Za-z0-9][A-Za-z0-9 ._\-~!@#$%^&*()+='|\\/\[\]{}<>?]*$/.test(text)) return false;

        const words = text.split(/\s+/);
        if (words.length > 4) return false;
        // Lowercase filler words mean it is prose, not a username. Capitalised
        // words are kept so names like "The Sceptical Chymist" still work.
        if (words.some(function (w) { return STOPWORDS.has(w); })) return false;
        return true;
    }


    const cache = new Map();

    function cacheGet(key) {
        return cache.has(key) ? cache.get(key) : null;
    }

    function cacheSet(key, value) {
        if (cache.size >= CFG.CACHE_MAX) cache.delete(cache.keys().next().value);
        cache.set(key, value);
        return value;
    }

    // ------------------------------------------------------------- lookups

    function ninjasticExact(name) {
        return gmRequest(CFG.NINJASTIC_USER + encodeURIComponent(name))
            .then(function (text) {
                let json;
                try { json = JSON.parse(text); } catch (e) { return null; }
                if (!json || !json.data || !json.data.author_uid) return null;
                return {
                    name: json.data.author,
                    uid: String(json.data.author_uid),
                    position: "",
                    posts: json.data.posts_count,
                    source: "ninjastic",
                };
            })
            .catch(function () { return null; });
    }

    // Parses the BPIP search result table with DOMParser so markup tweaks are
    // less likely to break the script than with regex scraping.
    function parseBpipRows(html) {
        const doc = new DOMParser().parseFromString(html, "text/html");
        const rows = [];

        doc.querySelectorAll("tr").forEach(function (tr) {
            const link = tr.querySelector('td[data-label="Name"] a[href*="Profile?p="]');
            const uidCell = tr.querySelector('td[data-label="User ID"]');
            if (!link || !uidCell) return;

            const uid = uidCell.textContent.trim();
            if (!/^\d+$/.test(uid)) return;

            const posCell = tr.querySelector('td[data-label="Position"]');
            const postsCell = tr.querySelector('td[data-label="Posts"]');
            rows.push({
                name: link.textContent.trim(),
                uid: uid,
                position: posCell ? posCell.textContent.trim() : "",
                posts: postsCell ? postsCell.textContent.trim() : "",
                source: "bpip",
            });
        });

        return rows;
    }

    function bpipSearchRaw(text) {
        return gmRequest(CFG.BPIP_SEARCH + encodeURIComponent(text))
            .then(parseBpipRows)
            .catch(function () { return []; });
    }

    // BPIP's search box matches a single token only: q=Sceptical finds
    // "Sceptical Spectacles", but q=Sceptical%20Spectacles returns 0 rows.
    // Its matching is also prefix-based, so only the *first* word of a
    // multi-word name finds it. Try each word (longest first) until the full
    // selection matches a returned row.
    function bpipSearch(text) {
        const words = text.split(/\s+/).filter(Boolean);
        if (words.length === 1) return bpipSearchRaw(text);

        const key = text.toLowerCase();
        const tokens = words.slice().sort(function (a, b) { return b.length - a.length; });

        function narrow(rows) {
            return rows.filter(function (r) {
                const name = r.name.toLowerCase();
                return name === key || name.startsWith(key) || name.indexOf(key) !== -1;
            });
        }

        // Note: the loop variable is named "idx" rather than a bare letter so
        // the source contains no bracketed single letter, which some forums
        // treat as BBCode italics when the script is pasted into a post.
        function attempt(idx) {
            if (idx >= tokens.length) return Promise.resolve([]);
            return bpipSearchRaw(tokens[idx]).then(function (rows) {
                const hit = narrow(rows);
                return hit.length ? hit : attempt(idx + 1);
            });
        }

        return attempt(0);
    }

    // Exact hit first, then BPIP near-matches, de-duplicated by user ID.
    function lookup(text) {
        const key = text.toLowerCase();
        const hit = cacheGet(key);
        if (hit) return Promise.resolve(hit);

        return Promise.all([ninjasticExact(text), bpipSearch(text)])
            .then(function (results) {
                const exact = results[0];
                const rows = results[1];

                const seen = new Set();
                const candidates = [];

                function push(entry) {
                    if (!entry || seen.has(entry.uid)) return;
                    seen.add(entry.uid);
                    candidates.push(entry);
                }

                push(exact);
                rows.filter(function (r) { return r.name.toLowerCase() === key; }).forEach(push);
                rows.filter(function (r) { return r.name.toLowerCase().startsWith(key); }).forEach(push);
                rows.forEach(push);

                return cacheSet(key, {
                    query: text,
                    exact: candidates.some(function (c) { return c.name.toLowerCase() === key; }),
                    candidates: candidates.slice(0, CFG.MAX_CANDIDATES),
                    truncated: candidates.length > CFG.MAX_CANDIDATES,
                });
            });
    }

    // ------------------------------------------------------------------- UI

    const CSS = [
        ".h2p-box{position:absolute;z-index:2147483000;max-width:330px;font:12px Verdana,Arial,sans-serif;",
        " background:#fff;color:#000;border:1px solid #8fa1c0;border-radius:6px;",
        " box-shadow:0 3px 12px rgba(0,0,0,.28);padding:6px 8px;line-height:1.5}",
        ".h2p-box *{box-sizing:border-box}",
        ".h2p-head{display:flex;align-items:center;gap:6px;margin-bottom:4px;font-weight:bold}",
        ".h2p-head .h2p-q{flex:1;overflow:hidden;text-overflow:ellipsis;white-space:nowrap}",
        ".h2p-close{cursor:pointer;border:0;background:transparent;font-size:15px;line-height:1;padding:0 2px;color:#666}",
        ".h2p-close:hover{color:#000}",
        ".h2p-row{display:flex;align-items:center;gap:6px;padding:3px 0;border-top:1px solid #eee}",
        ".h2p-row:first-of-type{border-top:0}",
        ".h2p-name{flex:1;min-width:0;overflow:hidden;text-overflow:ellipsis;white-space:nowrap}",
        ".h2p-meta{color:#777;font-size:10px;font-weight:normal}",
        ".h2p-links{display:flex;gap:4px;flex:0 0 auto}",
        ".h2p-links a{display:inline-flex;align-items:center;justify-content:center;",
        " width:26px;height:22px;border:1px solid #cfd8e6;border-radius:4px;background:#f7f9fc;text-decoration:none}",
        ".h2p-links a:hover{background:#e8eff9;border-color:#8fa1c0}",
        ".h2p-links img{width:16px;height:16px;display:block}",
        ".h2p-msg{color:#666;font-style:italic}",
        ".h2p-more{color:#777;font-size:10px;padding-top:3px}",
        "@media (prefers-color-scheme:dark){.h2p-box{background:#20242b;color:#dfe3ea;border-color:#3c4450}",
        " .h2p-row{border-top-color:#333a44}.h2p-links a{background:#2a3038;border-color:#3c4450}",
        " .h2p-links a:hover{background:#343c46}.h2p-close{color:#9aa4b2}.h2p-close:hover{color:#fff}}",
    ].join("\n");

    let styleInjected = false;
    function injectStyle() {
        if (styleInjected) return;
        styleInjected = true;
        const style = document.createElement("style");
        style.textContent = CSS;
        (document.head || document.documentElement).appendChild(style);
    }

    let box = null;

    function hideBox() {
        if (box) {
            box.remove();
            box = null;
        }
    }

    function bindClose() {
        if (!box) return;
        const btn = box.querySelector(".h2p-close");
        if (btn) btn.addEventListener("click", hideBox);
    }

    function showBox(rect, html) {
        injectStyle();
        hideBox();

        box = document.createElement("div");
        box.className = "h2p-box";
        box.innerHTML = html;
        // Interacting with the popup must not clear the selection or re-trigger.
        ["mousedown", "mouseup"].forEach(function (evt) {
            box.addEventListener(evt, function (e) { e.stopPropagation(); });
        });
        box.addEventListener("touchstart", function (e) { e.stopPropagation(); }, { passive: true });

        bindClose();
        document.body.appendChild(box);
        position(rect);
        return box;
    }

    function position(rect) {
        if (!box) return;
        const pad = 6;
        const w = box.offsetWidth;
        const h = box.offsetHeight;

        let left = window.scrollX + rect.left;
        let top = window.scrollY + rect.bottom + pad;

        const maxLeft = window.scrollX + document.documentElement.clientWidth - w - pad;
        if (left > maxLeft) left = maxLeft;
        if (left < window.scrollX + pad) left = window.scrollX + pad;

        // Flip above the selection when there is no room below.
        if (rect.bottom + h + pad > document.documentElement.clientHeight) {
            const above = window.scrollY + rect.top - h - pad;
            if (above > window.scrollY) top = above;
        }

        box.style.left = left + "px";
        box.style.top = top + "px";
    }

    function headerHtml(query, note) {
        return '<div class="h2p-head"><span class="h2p-q" title="' + esc(query) + '">' +
            esc(query) + "</span>" +
            (note ? '<span class="h2p-meta">' + esc(note) + "</span>" : "") +
            '<button class="h2p-close" title="Close" type="button">&times;</button></div>';
    }

    function linkHtml(href, icon, alt, title) {
        return '<a href="' + esc(href) + '" target="_blank" rel="noopener noreferrer" title="' +
            esc(title) + '"><img src="' + icon + '" alt="' + alt + '"></a>';
    }

    function linksHtml(entry) {
        const name = entry.name;
        return '<span class="h2p-links">' +
            linkHtml(CFG.BCT_PROFILE + entry.uid, ICONS.bct, "Bitcointalk",
                "Bitcointalk profile of " + name + " (UID " + entry.uid + ")") +
            linkHtml(CFG.BPIP_PROFILE + encodeURIComponent(entry.uid), ICONS.bpip, "BPIP",
                "BPIP profile of " + name + " (UID " + entry.uid + ")") +
            linkHtml(CFG.BITLIST_PROFILE + encodeURIComponent(entry.uid), ICONS.bitlist, "BitList",
                "BitList profile of " + name + " (UID " + entry.uid + ")") +
            "</span>";
    }

    function resultHtml(result) {
        if (!result.candidates.length) {
            return headerHtml(result.query) + '<div class="h2p-msg">No Bitcointalk user found.</div>';
        }

        let html = headerHtml(result.query, result.exact ? "" : "similar names");

        result.candidates.forEach(function (entry) {
            const meta = [entry.position, "UID " + entry.uid].filter(Boolean).join(" \u00b7 ");
            html += '<div class="h2p-row"><span class="h2p-name">' + esc(entry.name) +
                '<br><span class="h2p-meta">' + esc(meta) + "</span></span>" +
                linksHtml(entry) + "</div>";
        });

        if (result.truncated) {
            html += '<div class="h2p-more">More matches on <a href="' +
                esc(CFG.BPIP_SEARCH + encodeURIComponent(result.query)) +
                '" target="_blank" rel="noopener noreferrer">BPIP search</a></div>';
        }

        return html;
    }

    // -------------------------------------------------------- event handling

    let debounceTimer = null;
    let lastRequestAt = 0;
    let currentQuery = "";
    let requestSeq = 0;

    function selectionRect() {
        const sel = window.getSelection();
        if (!sel || sel.isCollapsed || sel.rangeCount === 0) return null;
        const range = sel.getRangeAt(0);
        const rects = range.getClientRects();
        if (rects.length) return rects[rects.length - 1];
        const r = range.getBoundingClientRect();
        return r && (r.width || r.height) ? r : null;
    }

    function renderInto(html, rect) {
        if (!box) return;
        box.innerHTML = html;
        bindClose();
        position(selectionRect() || rect);
    }

    function handleSelection() {
        const sel = window.getSelection();
        if (!sel || sel.isCollapsed) {
            hideBox();
            currentQuery = "";
            return;
        }

        // Ignore selections inside our own popup or inside form fields.
        const anchor = sel.anchorNode;
        const anchorEl = anchor && anchor.nodeType === 1 ? anchor : anchor && anchor.parentElement;
        if (anchorEl && anchorEl.closest && anchorEl.closest(".h2p-box, input, textarea, select")) return;

        const text = sel.toString().trim().replace(/\s+/g, " ");
        if (!looksLikeUsername(text)) {
            hideBox();
            currentQuery = "";
            return;
        }
        if (text === currentQuery && box) return;

        const rect = selectionRect();
        if (!rect) return;

        currentQuery = text;
        const seq = ++requestSeq;

        const cached = cacheGet(text.toLowerCase());
        if (cached) {
            showBox(rect, resultHtml(cached));
            return;
        }

        showBox(rect, headerHtml(text) + '<div class="h2p-msg">Searching\u2026</div>');

        const wait = Math.max(0, CFG.MIN_REQUEST_GAP_MS - (Date.now() - lastRequestAt));
        setTimeout(function () {
            if (seq !== requestSeq) return;
            lastRequestAt = Date.now();
            lookup(text)
                .then(function (result) {
                    if (seq === requestSeq) renderInto(resultHtml(result), rect);
                })
                .catch(function (err) {
                    if (seq === requestSeq) {
                        renderInto(headerHtml(text) +
                            '<div class="h2p-msg">Lookup failed: ' + esc(err.message) + "</div>", rect);
                    }
                });
        }, wait);
    }

    function scheduleSelectionCheck() {
        clearTimeout(debounceTimer);
        debounceTimer = setTimeout(handleSelection, CFG.DEBOUNCE_MS);
    }

    // Desktop: mouseup ends a drag-selection.
    document.addEventListener("mouseup", scheduleSelectionCheck, true);
    // Mobile: touchend plus selectionchange cover tap-hold and handle dragging.
    document.addEventListener("touchend", scheduleSelectionCheck, true);
    document.addEventListener("selectionchange", scheduleSelectionCheck);
    // Keyboard selection (shift+arrows, ctrl+A, ...).
    document.addEventListener("keyup", function (e) {
        if (e.shiftKey || e.key === "Shift" || e.ctrlKey) scheduleSelectionCheck();
    }, true);

    document.addEventListener("mousedown", function (e) {
        if (box && !box.contains(e.target)) hideBox();
    }, true);

    document.addEventListener("keydown", function (e) {
        if (e.key === "Escape") hideBox();
    }, true);

    function reposition() {
        if (!box) return;
        const r = selectionRect();
        if (r) position(r); else hideBox();
    }

    window.addEventListener("scroll", reposition, true);
    window.addEventListener("resize", reposition);
})();

I did not want this to hammer anyone's site so

Quote


Privacy
Only ninjastic Api and bpip.org and only the text you selected are sent nothing else. No analytics, no accounts, no keys, no external libraries, no data stored anywhere except an in-memory cache that dies when you close the tab.
The whole thing is one file of plain readable JavaScript - please read it before you install it and don't take my word for any of the above.



All Credit goes to BPIP and Ninjastic.space because this tool made entirely based on the data collected by BPIP and Ninjastic.space. I only glued their lookups to a text highlight.

I know there are many bugs I will try to solve it if people get interested in this tool.



25. Post 67089870 (unedited backup) (by Pmalek) (scraped on Fri Aug 28 18:09:01 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: LoyceV on Today at 03:51:58 PM
How does that work? Say you have a Trezor: do you enter that complex seed extension each time you use the device, using those 2 small keys scrolling through characters?
Something like that. It's inconvenient, I know, but so is self-custody. As you know, every increase in security decreases convenience and ease of use. With Trezor Model One, you don't enter passphrases on the device. You do it on the computer the hardware wallet is connected to. It's far from the best approach but it's ok if you are careful and use a dedicated computer just for bitcoin, for example. A Jade is also pretty nightmarish for passphrase entries. It uses a wheel as navigation that you flick left or right. Inconvenient and time-consuming but an increase in security. 



26. Post 67089534 (unedited backup) (by albert0bsd) (scraped on Fri Aug 28 16:07:01 CEST 2026) in List of all Bitcoin addresses with a balance:

I just try to download the lastest file and sadly the server is down, reading the recent messages i think i wil put a mirror ot the files as soon i can get a copy of them.

@LoyceV I will let you know when my mirror is ready.



27. Post 67089314 (unedited backup) (by Lucius) (scraped on Fri Aug 28 15:00:07 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: LoyceV on Today at 12:46:33 PM
This is how it was designed. Without your PIN, the seed doesn't leave the device.
I'm not buying it. The initial story was that your seed can't leave the device at all. Now it needs your PIN. What's stopping the firmware from not asking the PIN at all?

Quote
I am not using it, and i think it is a terrible feature.
But I see too much misinformation about this.
You're quoting Ledger, the company that lied that seed phrases could not leave the device. They're in the trust business, lying once means I'll never trust a word they say again.
~snip~

He's probably the only member of this forum who still thinks everyone else is spreading conspiracy theories when it comes to Ledger - the very fact that the seed can be remotely extracted from that device should have been a warning sign the moment the news was confirmed.

It's not a question of whether this "feature" will be abused one day, it's just a question of when it will happen. Given that this company still produces and sells devices, I would conclude that a very large number of those who use hardware wallets have no idea what risks they are exposed to.



28. Post 67089187 (unedited backup) (by bitmover) (scraped on Fri Aug 28 14:18:56 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: LoyceV on Today at 08:55:10 AM
And I firmly believe Ledger's key extraction scheme is a disaster waiting to happen.
For now, the extraction must be physically authorized in the device.
Is that a hardware limitation, or is it just the firmware telling you you need to authorize it? I'm pretty sure a cracked firmware wouldn't need your consent, and thousands of hackers can peacefully try to hack the device from their own home.

This is how it was designed. Without your PIN, the seed doesn't leave the device.

Quote
Plus, your Ledger will only allow your seed phrase to leave the wallet as encrypted fragments when you permit it. Setting up Ledger Recover requires you to enter the device PIN and consent to start the process on the device. Without your permission, the device will not (and cannot) fragment or send the encrypted fragments anywhere. That means if someone wants to exploit Ledger Recover to steal your seed phrase, they would need to have your PIN in the first place, which would already give them access to your wallet.
https://www.ledger.com/academy/what-is-ledger-recover

I am not using it, and i think it is a terrible feature.
But I see too much misinformation about this.


Quote
Quote
Trezor looks to work in a poor RNG
What makes you say that?

This. But I agree that it looks to have "enough" entropy, specially with a strong passphrase. But not as good as ledged for example.




29. Post 67086597 (unedited backup) (by Forsyth Jones) (scraped on Thu Aug 27 17:39:08 CEST 2026) in 2TB or 4TB drive upgrade?:

Luckily I bought my 02 Samsung 990 Pro SSDs around 2023 (before all this shit happened). I had bought one with a heatsink for my PS5 and another without it, but I made the mistake of selling my PS5 in 2024, and wow it's more than double the price  Cheesy I'm trying to see if I can get a used one... all to get GTA 6 at launch.

Regarding the one with the heatsink, I'm thinking of removing the heatsink to put the SSD without a heatsink in my notebook. This SSD with the heatsink also has 2TB, the one I'm using in my notebook to run Bitcoin Core. The one I'm currently using in my notebook already has 2TB of SSD and runs in a Linux environment, it will serve me well for at least 7 years...

I also have a 2TB SATA SSD for backups, currently I'm well served. Speaking of which, I need to resolve the issue of block and chainstate backups using the rsync tool on Linux, which @LoyceV taught me in a post months ago...

I should also try running an electrum server again using electrs or fulcrum, currently I only use Bitcoin Core or Sparrow connected to Core to connect directly to my node.



30. Post 67086278 (unedited backup) (by DaveF) (scraped on Thu Aug 27 16:01:19 CEST 2026) in 2TB or 4TB drive upgrade?:

Quote from: LoyceV on Today at 12:18:57 PM
Just did a test for the heck of it. 6th gen i5 *4* GB of ram 2TB ssd that is really old.
From a couple of hours of when you made this post till now. Still syncing, should be done when I get home from work. Shows 98% as of now but I have to run out the door to get to the office.
Can you check how many TB was written to that SSD? I tried this a while ago with 8 GB RAM, and it wrote several TB already due to the lack of RAM.
I must say I'm surprised this takes 8-ish days. Assuming your internet speed isn't the limiting factor: do you have one of those SSDs with bad sustained write performance? You make me want to test this again.

It's a 10 year old system with an 8 or 9 year old SSD. Was not a great performer back then. Will see what I can see about writes when I get home, more likely over the weekend.

But, it was more of a proof that people who complain about they needed all this hardware to run a full node with core are either spouting BS or doing something wrong or at this point are using hardware that is more then a decade old.

Which TBF you should not be doing anyway unless you are prepared for the fact that 10 year old consumer hardware can just go 'poof' and have smoke come out of it for no reason other then it's that old. Server class / industrial hardware is better but still not much.

It's just the nature of what it is.

-Dave




31. Post 67086193 (unedited backup) (by JustBeKause) (scraped on Thu Aug 27 15:26:19 CEST 2026) in This place is peacful again.:

'SCUSE ME PARDON ME COMING THROUGH *sits down*

lemme just put this here. for the record and shit.

https://loyce.club/archive/topics/559/5591090.html
https://loyce.club/archive/posts/6708/67083758.html

Well, we almost got through the month of August.  That's something.  It was a great few weeks but it appears that he is already heading down a path to his old ways within a week of returning.  Sort of makes you wonder what would actually make him stop this troublesome behavior.  I guess we'll find out eventually.  Until then, thanks to the folks who encouraged peace.  I thought for a moment we might actually achieve it in this situation.

^ y u delete this mr og? y did you even post it in the first place? you got all this riches and wealth but you cant pay for a attorney worth his salt who will tell you to shut your mouth about the subject?

what do you even know about peace? ur not striving to make peace AT ALL. just the other day you were whining and crying about LoyceV supporting Vod lawsuit over you, when he hasn't even uttered words remotely close to that, in a thread that wasnt even ABOUT you: https://loyce.club/archive/posts/6697/66972568.html

you stop huffing whatever it is thats making you post bullshit and then wake up the next morning realizing it might hurt you so you delete it. its bad form, hombre Smiley

*fucks off into the wind*




32. Post 67085920 (unedited backup) (by DaveF) (scraped on Thu Aug 27 13:47:31 CEST 2026) in 2TB or 4TB drive upgrade?:

Quote from: LoyceV on August 18, 2026, 09:11:37 PM
fries the 8GB of maxed out ram on this laptop.
You can still run it: the IBD will take a while, but after it's done, 8 GB RAM and SSD is more than enough to process 6 new blocks per hour.

Just did a test for the heck of it. 6th gen i5 *4* GB of ram 2TB ssd that is really old.

From a couple of hours of when you made this post till now. Still syncing, should be done when I get home from work. Shows 98% as of now but I have to run out the door to get to the office.

Base OS & core nothing else. Just took time.

-Dave



33. Post 67085836 (unedited backup) (by vapourminer) (scraped on Thu Aug 27 13:04:43 CEST 2026) in So with the cold wallet hack I am thinking about using core 29 to store.:

Quote from: LoyceV on August 23, 2026, 05:51:31 PM
I've been thinking about physically removing anything I don't need from an old laptop for a while now, but never actually did it. But like you said: business laptops with full Youtube explanation of how to open them are generally much easier than consumer laptops.
For the truly paranoid:
But again, I haven't done this yet Smiley



when in use: tape over the webcam, a blank 1/8 in plug inserted into the mic socket disables the built in mics (generally via hardware contact in the socket) and remove the drives and wifi/bluetooth module. glues the network ports with superglue. thats kinda it.. ok ok so im lazy. boot via CDROM with tails. run colemans and electrum doing whatever needed. print anything needed via ancient HP laserjet from forever ago that only is used for that stuff. i always print a few garbage pages at the end even though im sure that thing has no persistent memory but hey.



34. Post 67085384 (unedited backup) (by ABCbits) (scraped on Thu Aug 27 09:10:02 CEST 2026) in How do we define "airgap" around here?:

Quote from: vapourminer on August 26, 2026, 09:55:37 AM
What do you consider "old"? Anything older than Bitcoin itself will lack processing power, anything a few years old won't be much different than anything you buy new now.

"old"=32 bit to me

It's more than old. From quick search, AMD Athlon XP is last AMD CPU without 64-bit instruction, which released from 2001 to 2003. The next generation (AMD Athlon 64) released from 2003 to 2009 and support 64-bit instruction. We're looking at single core CPU with probably up to 2GB RAM support.

how about "old" as in core 2 duo era. dual/quad core, 8 gb mem maxed out on desktop class mobos. my e8400 was a workhorse for its time. but some distros balk at it now.

8GB RAM is fine, even newer laptop/computer type start using 8GB again. But core 2 duo along with older CPU lack certain CPU instruction.

Quote from: https://www.linux.org/threads/how-to-check-x86_64-versions-in-linux.55095/
Intel Core 2 Duo  laptop:
Code:
$ ./x86_64_check.sh
Current level: x86-64-v1
Missing for x86-64-v2: popcnt sse4_2

Unlike 32-bit or 64-bit, it's harder to check actual compatibility of the app or OS.



Quote from: puck2 on August 26, 2026, 08:47:40 PM
The last word includes a checksum, that's a bit more tricky.
That's where I'm stuck and feel like I need to use my old coldcard or iancoleman.

Since it's not mentioned yet, you can enter your own or custom entropy when using iancoleman. Just tick/click "Show entropy details", choose the format (such as hex, binary or even dice) and enter the entropy on the text box.



35. Post 67085113 (unedited backup) (by nc50lc) (scraped on Thu Aug 27 05:39:01 CEST 2026) in How do we define "airgap" around here?:

Quote from: puck2 on August 26, 2026, 08:47:40 PM
The last word includes a checksum, that's a bit more tricky.
That's where I'm stuck and feel like I need to use my old coldcard or iancoleman.
Unless you can manually calculate SHA256, you'll need a calculator tool/script/program for that.

While you're at it, use something reliable that can complete the whole process, from your entropy to mnemonic.
And as a precaution, don't rely on one tool, try to compare the result of two or more and see if the seed phrase matches in case one has a bug.

I recommend IanColeman's BIP39 tool on Tails, completely Air-Gap and will be automatically wiped on shutdown.
For the other tool, your own choice (DYOR).

Quote from: puck2 on August 26, 2026, 08:47:40 PM
BTW, I checked my brain memory bank and I think I rolled dice when I created the seed on CC.
This is most likely what happened, CC automatically calculated the checksum from your dice rolls that's why you don't remember doing all those other stuffs.



36. Post 67084448 (unedited backup) (by puck2) (scraped on Wed Aug 26 22:47:43 CEST 2026) in How do we define "airgap" around here?:

Quote from: LoyceV on August 24, 2026, 06:33:44 PM
The last word includes a checksum, that's a bit more tricky.
That's where I'm stuck and feel like I need to use my old coldcard or iancoleman.

BTW, I checked my brain memory bank and I think I rolled dice when I created the seed on CC. At the time, I was like "this is cool" now I'm like "wow I saved my a$$".



37. Post 67084380 (unedited backup) (by suzanne5223) (scraped on Wed Aug 26 22:17:31 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: Wind_FURY on Today at 07:52:49 AM
I imagine there is likely more than one class action being cooked up.
Would they have deep enough pockets for this? I can imagine they spent a lot of money on marketing, sales and the actual product, while they didn't sell that many devices. So if all buyers want their money back, they don't have that amount. If the victims want their losses compensated, they won't have that kind of money it either.

I wonder if they will be able to find the users who now hold those 1500 btc. One small mistake when spending, even in a kyc free exchange (like an ip leak),  might expose their identities

Tell will tell if someone from coldcard is involved


That ColdCard CTO who made an anonymous account and he was talking to the account - HIMSELF, in Github is already a red flag in my opinion.

This issue should definitely be investigated. Users have lost their savings because of developer-INCOMPETENCE or developers being BAD ACTORS.
Yes, he's a red flag, but we can talk about the unprofessional service provided by the Coldcard team and not talk about people who spent weeks assisting Bitcoin holders who were affected by the Coldcard vulnerability by helping them to transfer their funds to safety, with the estimation of tens of millions of dollars worth of BTC protected during the period the Coldcard vulnerability occurred.
https://x.com/BitcoinNewsCom/status/2092703792944808228



38. Post 67084085 (unedited backup) (by DireWolfM14) (scraped on Wed Aug 26 20:25:01 CEST 2026) in How do we define "airgap" around here?:

Quote from: LoyceV on Today at 05:59:35 AM
Thanks. This once again shows how annoyingly tricky it is to do things manually (I started by typing 8 times, then wanted to change it to 11). Of course I can manually convert binary to seed words, but doing it 24 times, chances are I make a mistake somewhere along the way.

I used live debian with a desktop environment, so I had a libreoffice calc formula do conversations from binary to decimal, and vlookup to populate the word from the bip39 word list.  Still, there's plenty of opportunities to mess up entering the binary values into the spreadsheet... 

But wouldn't that just add more entropy?   Cheesy Cheesy

Quote from: LoyceV on Today at 05:59:35 AM
I was talking about an airgapped system

Point taken, for an off-line system you can use almost any 64bit system that can handle a modern OS.  If your CLI fu is strong, you wouldn't even need a desktop environment to overly tax the system.  Linux CLI commands can convert the binaries to text, can extract the words from the bip39 list, and there's even a python CLI tool to find the 12th/24th word.



39. Post 67083769 (unedited backup) (by OrangeFren) (scraped on Wed Aug 26 18:46:02 CEST 2026) in OrangeFren.com - instant, KYC-free, exchange comparison:

Quote from: LoyceV on Today at 04:38:21 PM
You people wouldn't believe the amount of hate and cope we've received after publishing the results of this experiment Grin
Overcharging 8% of the total, and sharing the money buys a lot of supporters Wink
I would just quietly distance myself from them and switch to a new swapper. Isn't that easier? Rather than reminding everyone of how you're associated with this scam?

For the sake of transparency, we never got paid by any service to attack another or to promote any service. OrangeFren.com never had sponsors (despite many offers). We only ever accepted money to sponsor the dozens of meetups we've hosted over the years in which case the sponsorship is plain as day and strictly limited to the meetup itself.

Speaking of, last one was sponsored by Cake Wallet in Krakow, Poland.
Next 3(!) are sponsored by our friends from WizardSwap.io. They're taking place in South America. Announcing tomorrow hopefully Smiley



40. Post 67082679 (unedited backup) (by EstherBtc) (scraped on Wed Aug 26 12:06:20 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: avp2306 on August 25, 2026, 03:35:44 PM
Would they have deep enough pockets for this? I can imagine they spent a lot of money on marketing, sales and the actual product, while they didn't sell that many devices. So if all buyers want their money back, they don't have that amount. If the victims want their losses compensated, they won't have that kind of money it either.

I wonder if they will be able to find the users who now hold those 1500 btc. One small mistake when spending, even in a kyc free exchange (like an ip leak),  might expose their identities

Tell will tell if someone from coldcard is involved
Well, there are indications that the hacker made a mistake and exposed information about himself. Activities were recognised where the operator used a paid account on a "well-known" blockchain service. A pattern of querying the original addresses was observed during the attack and this was repeated.

https://www.cryptotimes.io/2026/08/19/block-and-galaxy-research-give-lead-to-law-enforcement-in-111m-coldcard-bitcoin-theft/

Now that they already traced the hacker, its good to see what other action they made. Because many people are so curious about this case, they want those people involve in this hacking issue to get captured.

Maybe this is also the reason why the funds stolen has left unmoved? https://crypto.news/coldcard-hackers-leave-87-of-stolen-bitcoin-unmoved-after-114m-theft they are maybe afraid to do transaction because it can create fresh traces to the authorities.

They should act fast, so they can still recover the funds and return it back to those proven victims.

The question now remains, how will the victims prove that their bitcoin was stolen?
Since there is no kyc to be able to identify owners?



41. Post 67082675 (unedited backup) (by OrangeFren) (scraped on Wed Aug 26 12:04:31 CEST 2026) in OrangeFren.com - instant, KYC-free, exchange comparison:

Quote from: LoyceV on Today at 09:15:52 AM
After adjusting for how the market moved all except NanSwap, Quickex and of course SplitNOW paid more than their initial promise.
Now I'm curious if this is a one-time inconsistancy, or that it can be reproduced (for instance when the market moves up instead of down).
I think we'll make the "mystery swapper" a regular, monthly, test.

My working hypothesis is NanSwap isn't great, because as the name suggests they're mostly about Nano. The other currencies they just resell from ChangeNow, last time I checked. Also they undersold by a very small margin all things considered. Could be explained by sourcing the rates elsewhere.

As for Quickex, they displayed "150 confs required" for the XMR deposit, but processed the swap after just 11 or 12. Maybe they're just buggy? Regardless, they clearly don't use their own service an awful lot with omissions this big.

SplitNOW is simply a scam. I presume their business model is rip-off users with 8% fees then funnel half of that to their influencer affiliates that push this scam down the throat of users that don't know any better.



42. Post 67082638 (unedited backup) (by vapourminer) (scraped on Wed Aug 26 11:55:37 CEST 2026) in How do we define "airgap" around here?:

Quote from: ABCbits on Today at 07:21:59 AM
What do you consider "old"? Anything older than Bitcoin itself will lack processing power, anything a few years old won't be much different than anything you buy new now.

"old"=32 bit to me



It's more than old. From quick search, AMD Athlon XP is last AMD CPU without 64-bit instruction, which released from 2001 to 2003. The next generation (AMD Athlon 64) released from 2003 to 2009 and support 64-bit instruction. We're looking at single core CPU with probably up to 2GB RAM support.

how about "old" as in core 2 duo era. dual core, 16 gb mem maxed out. my e8400 was a workhorse for its time.



43. Post 67082338 (unedited backup) (by Wind_FURY) (scraped on Wed Aug 26 09:52:49 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: bitmover on August 24, 2026, 09:13:25 PM
I imagine there is likely more than one class action being cooked up.
Would they have deep enough pockets for this? I can imagine they spent a lot of money on marketing, sales and the actual product, while they didn't sell that many devices. So if all buyers want their money back, they don't have that amount. If the victims want their losses compensated, they won't have that kind of money it either.

I wonder if they will be able to find the users who now hold those 1500 btc. One small mistake when spending, even in a kyc free exchange (like an ip leak),  might expose their identities

Tell will tell if someone from coldcard is involved


That ColdCard CTO who made an anonymous account and he was talking to the account - HIMSELF, in Github is already a red flag in my opinion.

This issue should definitely be investigated. Users have lost their savings because of developer-INCOMPETENCE or developers being BAD ACTORS.



44. Post 67082279 (unedited backup) (by ABCbits) (scraped on Wed Aug 26 09:22:01 CEST 2026) in How do we define "airgap" around here?:

Quote from: vapourminer on August 25, 2026, 11:52:21 AM
What do you consider "old"? Anything older than Bitcoin itself will lack processing power, anything a few years old won't be much different than anything you buy new now.

"old"=32 bit to me



It's more than old. From quick search, AMD Athlon XP is last AMD CPU without 64-bit instruction, which released from 2001 to 2003. The next generation (AMD Athlon 64) released from 2003 to 2009 and support 64-bit instruction. We're looking at single core CPU with probably up to 2GB RAM support.

And FWIW, Electrum version 4.5.8 (Oct 23, 2024) is probably last version that may support 32-bit OS or CPU. But i could be wrong, since i don't actually test it.

Quote from: https://github.com/spesmilo/electrum/blob/master/RELEASE-NOTES
# Release 4.6.0 (July 16, 2025)
 * Builds/binaries:
   - new minimum OS requirements:
     - Windows: x86_64, Windows 10 (1809)
         note: 32-bit Windows is no longer supported.
     - macOS: 11 "Big Sur"
     - Linux AppImage: x86_64, glibc 2.31 ("debian 11"-equivalent)

# Release 4.5.8 (Oct 23, 2024)



Quote from: dkbit98 on August 25, 2026, 07:50:38 PM
For laptops you can remove wifi/bluetooth chips, that is possible in Thinkpad or similar older devices.

In case it's not possible or have high risk damaging the laptop itself, at least completely uninstall the network driver. Certain BIOS also let you disable some or all network functionality.



45. Post 67080863 (unedited backup) (by DireWolfM14) (scraped on Tue Aug 25 21:14:25 CEST 2026) in How do we define "airgap" around here?:

Quote from: puck2 on August 24, 2026, 05:26:59 PM
~

I define Airgapped as relying on as little technology as possible.  No computer needed if you can convert binary into decimal on paper.  The trouble is, I don't know how to generate the last word/checksum of the seed without a computer or a hardware wallet.  The ColdCard and many other hardware wallets can do that for you.  The iancolman tool on an off-line computer as well.

Since you have a ColdCard, use it just for that purpose after turning off the USB and NFC features.  It can still safely function to sign transactions, but whether you want to trust it going forward is up to you. 

Personally, I've retired my ColdCard.  Unless they change the licensing of their firmware and attract more legitimate contributors examine and validate their code, it's gong to collect dust in my safe.  I'll rely on my Foundation Passports instead.


Quote from: LoyceV on August 24, 2026, 06:33:44 PM
flip 11 times: 10011101001. That's binary. Make it decimal: 1257.

FIFY.


Quote from: LoyceV on Today at 03:35:46 PM
More unused cores doesn't make it any faster.

My current desktop has 8 cores, and I tax it regularly.  It's my home office engineering workstation, and not even my professional Dell laptop with the same processor and ram can keep up with it.  It does have an 11GB GPU, however.  Since I recently switched my main OS to Debian and I still have to run some software in a Windows VM from time to time, even my desktop has been complaining.



46. Post 67080130 (unedited backup) (by avp2306) (scraped on Tue Aug 25 17:35:49 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: examplens on Today at 08:50:08 AM
Would they have deep enough pockets for this? I can imagine they spent a lot of money on marketing, sales and the actual product, while they didn't sell that many devices. So if all buyers want their money back, they don't have that amount. If the victims want their losses compensated, they won't have that kind of money it either.

I wonder if they will be able to find the users who now hold those 1500 btc. One small mistake when spending, even in a kyc free exchange (like an ip leak),  might expose their identities

Tell will tell if someone from coldcard is involved
Well, there are indications that the hacker made a mistake and exposed information about himself. Activities were recognised where the operator used a paid account on a "well-known" blockchain service. A pattern of querying the original addresses was observed during the attack and this was repeated.

https://www.cryptotimes.io/2026/08/19/block-and-galaxy-research-give-lead-to-law-enforcement-in-111m-coldcard-bitcoin-theft/

Now that they already traced the hacker, its good to see what other action they made. Because many people are so curious about this case, they want those people involve in this hacking issue to get captured.

Maybe this is also the reason why the funds stolen has left unmoved? https://crypto.news/coldcard-hackers-leave-87-of-stolen-bitcoin-unmoved-after-114m-theft they are maybe afraid to do transaction because it can create fresh traces to the authorities.

They should act fast, so they can still recover the funds and return it back to those proven victims.



47. Post 67080114 (unedited backup) (by vapourminer) (scraped on Tue Aug 25 17:30:43 CEST 2026) in How do we define "airgap" around here?:

Quote from: LoyceV on Today at 02:48:29 PM
"old"=32 bit to me
That's old Tongue There aren't much wallets that still run on 32 bit systems. But even the oldest 64 bit PCs were very limited on RAM capacity.

less than 4 cores?



48. Post 67079702 (unedited backup) (by Mek) (scraped on Tue Aug 25 14:46:19 CEST 2026) in List of all Bitcoin addresses with a balance:

Quote from: LoyceV on August 22, 2026, 12:36:43 PM
If someone wants to sponsor or even donate a server: feel free to contact me Smiley
Maybe if people could contribute with their server as a mirror... of the "latest" file... for example I have a trial server but it's going to last only a few more days... could help in the meantime.



49. Post 67079700 (unedited backup) (by Lucius) (scraped on Tue Aug 25 14:46:19 CEST 2026) in AI Spam Report Reference Thread:

Quote from: LoyceV on Today at 07:40:25 AM
~snip~

What's the verdict on shitposter Rebirth01? He's created many low-value topics, like this one:
Bitcoin is one of the greatest innovation ever to have come to human race. From the distributive aspect of the Bitcoin to the control of it is amazing. This is the only one thing i know that is outside government control and has not broken down despite pressure from the various government. The scarcity of the Bitcoin is another thing that is good about the whole thing because if something is scarce,it add value to it. Another fascinating aspect of Bitcoin is this, inflation has no grip over it and this where it beats Fiat hands down. Bitcoin also serve as assets for the future

It looks like his copy/paste was cut off mid-sentence.

Copyleaks - No AI Content Found
GPTZero - We are highly confident this text is entirely human



When it comes to user @CinderellaScarlet, his posts are too short for both detectors, but when any random words are added, GPTZero detects that the text is AI generated with high security. I guess it's a tactic to avoid detection.



50. Post 67079577 (unedited backup) (by vapourminer) (scraped on Tue Aug 25 13:52:25 CEST 2026) in How do we define "airgap" around here?:

Quote from: LoyceV on August 24, 2026, 06:33:44 PM
What do you consider "old"? Anything older than Bitcoin itself will lack processing power, anything a few years old won't be much different than anything you buy new now.

"old"=32 bit to me




51. Post 67079434 (unedited backup) (by bitmover) (scraped on Tue Aug 25 12:58:07 CEST 2026) in How do we define "airgap" around here?:

Quote from: puck2 on August 24, 2026, 05:26:59 PM
Alternatively, what is the consensus around using an old Coldcard with dice rolls? Still considered untrustworthy?

I would just throw them into the trash.

There is no reason to risk your funds in such bad software and device.

Quote from: LoyceV on August 24, 2026, 06:33:44 PM
If I securely reinstall a barebones linux distro, or run Tails, do you folks consider this airgapped, even if at some point this computer was online?
I'd say airgapping is more about future actions than about past actions: make sure the data on it can never reach the internet in the future (including accidentally plugging in an ethernet cable).
[/quote]

I think this when a hardware wallet becomes handy. most users don't have the technical skills or patience to always be 100% offline when spending their coins safely.

I would buy a trezor, if I was going to buy a new HW.



52. Post 67079184 (unedited backup) (by examplens) (scraped on Tue Aug 25 10:50:14 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: bitmover on August 24, 2026, 09:13:25 PM
I imagine there is likely more than one class action being cooked up.
Would they have deep enough pockets for this? I can imagine they spent a lot of money on marketing, sales and the actual product, while they didn't sell that many devices. So if all buyers want their money back, they don't have that amount. If the victims want their losses compensated, they won't have that kind of money it either.

I wonder if they will be able to find the users who now hold those 1500 btc. One small mistake when spending, even in a kyc free exchange (like an ip leak),  might expose their identities

Tell will tell if someone from coldcard is involved
Well, there are indications that the hacker made a mistake and exposed information about himself. Activities were recognised where the operator used a paid account on a "well-known" blockchain service. A pattern of querying the original addresses was observed during the attack and this was repeated.

https://www.cryptotimes.io/2026/08/19/block-and-galaxy-research-give-lead-to-law-enforcement-in-111m-coldcard-bitcoin-theft/



53. Post 67078980 (unedited backup) (by ABCbits) (scraped on Tue Aug 25 09:11:13 CEST 2026) in How do we define "airgap" around here?:

Quote from: puck2 on August 24, 2026, 05:26:59 PM
So my next adventure is creating my own seed using dice. I have a coldcard, luckily skated by the most recent incident, and moved funds to an old standard wallet that I trust. Maybe I used dice rolls and I don't remember it!!! If my funds weren't stolen perhaps this is the case?

Another possibility is you generated the seed with coldcard, but without known vulnerable firmware.

Quote from: puck2 on August 24, 2026, 05:26:59 PM
Alternatively, what is the consensus around using an old Coldcard with dice rolls? Still considered untrustworthy?

At very least, make sure you update to latest firmware. I've seen people stop using their Coldcard, either because they no longer trust the device/company or fear another undiscovered vulnerability exist.

Quote from: LoyceV on August 24, 2026, 06:33:44 PM
Quote
I trust an old laptop with wifi disabled or removed, far more than I trust a new laptop purchased online.
What do you consider "old"? Anything older than Bitcoin itself will lack processing power, anything a few years old won't be much different than anything you buy new now.

Few distro also may not work properly with old laptop, at least without additional setting or installation.



54. Post 67078129 (unedited backup) (by bitmover) (scraped on Mon Aug 24 23:13:31 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: LoyceV on Today at 08:22:49 AM
I imagine there is likely more than one class action being cooked up.
Would they have deep enough pockets for this? I can imagine they spent a lot of money on marketing, sales and the actual product, while they didn't sell that many devices. So if all buyers want their money back, they don't have that amount. If the victims want their losses compensated, they won't have that kind of money it either.

I wonder if they will be able to find the users who now hold those 1500 btc.

Tell will tell if someone from coldcard is involved



55. Post 67077275 (unedited backup) (by Hispo) (scraped on Mon Aug 24 18:17:25 CEST 2026) in Help generating true 256-bits entropy wallet:

Thank you all for your comments and recommendations.
I think I now have a clearer idea on what I am supposed to do in order to generate better keys.

I definitely will take in consideration LoyceV's method, even though it could be considered to be time consuming.
It may be worth it if one is holding in the long term, after all.

And when I meant true-256 bits, I actually mean those bits of entropy don't have any chance to be faulty, in the same manner those generated by Coldcard were.



56. Post 67076764 (unedited backup) (by GazetaBitcoin) (scraped on Mon Aug 24 15:19:43 CEST 2026) in List of useful Bitcoin block explorers:

Quote from: SFR10 on August 19, 2026, 12:19:59 PM
@GazetaBitcoin
It appears that you missed my "previous update" Smiley Roughly 50 days have passed since I made that post and the situation remains the same for those explorers, so I think it's time to remove them from the list.

Oooops! 🤦‍♂️ Please forgive me, SFR10, I have no idea how I missed that for 50 DAYS Oo
I am in vacation right now and I have only the phone with me and it's difficult to make such changes from the phone... But I will apply them once I get home.

Quote from: SFR10 on August 19, 2026, 12:19:59 PM
BTW, I found another explorer

Yay! I will add it also after I get home, in case no objection will arise until then. Thank you, SFR10!



Quote from: LoyceV on Today at 12:12:52 PM
Can you confirm you're the owner of that site by posting your Bitcointalk username in learnmeabitcoin.com/bitcointalk.txt ? If you do, I'll leave you neutral feedback confirming it's yours. That will add a lot of credibility to your (Newbie) account

This made me think we can ask same thing from the other developers which wrote here before... Referring to people like daniosem, bitcointry or cloxy (I hope I didn't miss others).



57. Post 67076703 (unedited backup) (by ryzaadit) (scraped on Mon Aug 24 15:02:49 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: LoyceV on Today at 10:21:58 AM
Then someone will take over the bankrupt company and continue selling the same hardware, maybe after rebranding. The Ledger case shows that even if they can extract the seed from your device, people will still buy it.
In this case, I hope you don't mind borrowing some of your words.

Quote from: LoyceV on August 23, 2026, 08:31:56 AM
"Fool me once, shame on you. Fool me twice, shame on me."

"Fool me three times... with a different brand and company... I guess I’ll just straight send my BTC to them".

I agree with you. Some people will still buy it, but pretty sure even if someone takes over their company and sells the hardware with a different brand. The new one has a track record for it, which is COINKITE. The community will also dig them as well, and share just to make sure be aware about them.

If people still buy and use them even though they're on a different team or company. Just don't be surprised anymore if something like these are happening again.



58. Post 67076593 (unedited backup) (by in3rsha) (scraped on Mon Aug 24 14:28:38 CEST 2026) in List of useful Bitcoin block explorers:

Quote from: LoyceV on Today at 12:24:33 PM
Welcome to Bitcointalk! I've seen learnmeabitcoin.com linked here many times, so it's good to see you're here Smiley

Thank you, I appreciate it, and glad to be here.  Smiley



59. Post 67076561 (unedited backup) (by in3rsha) (scraped on Mon Aug 24 14:17:43 CEST 2026) in List of useful Bitcoin block explorers:

Quote from: LoyceV on Today at 12:12:52 PM
Thanks for including the learnmeabitcoin explorer.
I primarily made it as an accompaniment to the articles on the site
Can you confirm you're the owner of that site by posting your Bitcointalk username in learnmeabitcoin.com/bitcointalk.txt ? If you do, I'll leave you neutral feedback confirming it's yours. That will add a lot of credibility to your (Newbie) account.

Yes I should have added some proof to my post. I've added my username to that URL. Thank you.



60. Post 67076195 (unedited backup) (by ryzaadit) (scraped on Mon Aug 24 12:18:25 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: LoyceV on Today at 08:22:49 AM
Would they have deep enough pockets for this? I can imagine they spent a lot of money on marketing, sales and the actual product, while they didn't sell that many devices. So if all buyers want their money back, they don't have that amount. If the victims want their losses compensated, they won't have that kind of money it either.
Maybe the memes will decide.


If they are found guilty, will they have the ability to pay the victim? My answer: NO. But maybe they will pay the fine to Canada authority and get more financial damage. Other scenario, they declare bankruptcy and that means for us they will no longer offer any service at all. Which is good, since we don't want them anymore or deserve any space in here due to selling mallfunction product.

Now for the victim who at least joined the class-action, maybe in the future authority make an arrest and seize the funds. They offering a refund program for the victim, and they're qualified due joined the class action or reported their losses. At least even the chance are small, still worth to tried.



61. Post 67075512 (unedited backup) (by philipma1957) (scraped on Mon Aug 24 05:29:19 CEST 2026) in So with the cold wallet hack I am thinking about using core 29 to store.:

Quote from: LoyceV on August 23, 2026, 05:51:31 PM
The whole idea of buying a new laptop is that you are buying a fresh, untouched hardware.
Some people trust old hardware more than new hardware when it comes to Bitcoin. How sure are you the manufacturer didn't install a backdoor already?

Quote
Tails can protect you from infected OS but it can't protect you from compromised BIOS, physical keyloggers and altered hardware.
How likely is this if you buy a laptop from Craigslist? I'm not worried about a compromised BIOS, nor am I worried about physical keyloggers in an air-gapped laptop. If that's going to happen, it's going to be a targeted attack, and the attacker can just as well install it inside the laptop you have at home already.

Quote
If you have an old laptop at home, then no problem, use it. But if you don't have a laptop and you have to buy, I would still choose a new, cheap laptop over second-hand.
I prefer hardware that lasts many years, and I expect a new budget laptop to last less long than a (cheaper) second hand business laptop. And I don't want to pay $2000 for a laptop I'll only use for accessing cold storage once a year.
Let's agree to disagree on the details, I'm pretty sure both options are quite secure anyway.

From my personal experience with few consumer laptops, those were sometimes a pain in the ass to open to get access to various components and inspect them. While the experience was quite different and much more pleasant with decent business laptops from Dell, HP and ThinkPads (IBM or later Lenovo).
I've been thinking about physically removing anything I don't need from an old laptop for a while now, but never actually did it. But like you said: business laptops with full Youtube explanation of how to open them are generally much easier than consumer laptops.
For the truly paranoid:
But again, I haven't done this yet Smiley

I have a lenovo laptop running core 25.

Pulled the wifi card

Encrypted the ssd a 2tb nvme.2 Samsung

It runs mint os.

It has a 24 character passphrase .

So i think It has 32gb ram

I should check it it has been sitting with 0.001 btc In it.