Last update: 2026-08-09_Sun_21.12h (Amsterdam time)

Change your preferences in LoyceV's notification bot.
See Notifications for others.

LoyceV receives Notifications when he's quoted or mentioned

Ignore list:
Posts from these users are ignored:
1. Timelord2067
2. LoyceV
3. wolwoo
4. Bitcoin SV
5. The-One-Above-All
6. Excimer
7. truth or dare
8. bonesjonesreturns
9. KaneVWE
10. Laudanum
11. Quantum_Resolve7987V
Posts in these topics are ignored:
1. [ТОП-200] Щедрые пользователи, дающие мериты
2. [TOP-200] Members who support newbies - Thanks!
3. [TOП-200] Пoльзoвaтeли, пoддepживaющиe нoвичкoв - Cпacибo!
4. Time Series Analysis on Distributed Merits in the forum (daily, weekly, monthly)
5. [CLUBS] Top Merited-Users Classified into 4 Clubs
6. Interquartile range of intra-day merits with time series plot
7. Timelord2067's Timely Test and Main-neT LighTning Loans to a "T"
8. Weekly earned merits (median) of top 100 merited users
9. The active levels of sent/earned merits of users , excludes autobanned/ nuked
10. Bitcointalk Merit Dashboard


Username "LoyceV" occurred in the following posts (quoted and/or mentioned):


1. Post 67027473 (unedited backup) (by asUHWEceyc) (scraped on Sun Aug 9 21:06:20 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: LoyceV on Today at 08:27:01 AM
The thing is, at first it all looks very nice and generates a lot of excitement, but when you start to see the real impact, things change a bit.
I'm not saying he's going to return the stolen coins, but at least he might be going through a period of reflection.
That's why I came up with this theory:
Or could it just be an amateur who's in way over his head? Someone who accidentally stumbled upon this weakness, and suddenly ended up with $70 million in stolen funds?

Perhaps we need to look again at the master Satoshi and see how he created his wallets.
They've been sitting there for over 15 years without suffering any problems, despite probably being the most attacked wallets in the world.
Satoshi used Send to Pubkey transactions, whilch may become quantum vulnerable in the future. That's not the best example for the long term. But his random generation must have been pretty good Smiley

Surprisingly good for a Windows XP VM

But, a big bag of private keys also has certain advantages

Also-

How many NVK proximal influencer-podcaster-types (bent, odell) and their investment project operators (1031) that funded coinkite lost money in this thing? What about secondary corporate operators that used coldcards for key handholding services? 

Did they "know better" or get a heads up?



2. Post 67027397 (unedited backup) (by Stalker22) (scraped on Sun Aug 9 20:40:50 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: fillippone on Today at 11:15:33 AM

He could keep them still for a month or two and then send them back
To return the stolen funds, he'll need to identify each owner first, and you can bet many scammers will claim to be the owners. No single person can do that on his own.

The addresses are now compromised.
Everyone could claim the ownership of the sending addresses (the private keys).
Identifiying the original and authentic owner is almost impossible (it would require checking upon the possession of the physical hw, something that looks very impractical to me).

Even verifying possession of the physical HW will not be definitive proof.  It is theoretically possible for someone in possession of the ColdCard HW to recreate the wallet by importing a compromised seed.  How would that differ from the original wallet of the real victim?

I think on-chain history is the only real proof.  To verify a claim, someone would have to trace where the funds originally came from - like an CEX withdrawal, or from some other KYC-ed account.  Doing that manual forensics for thousands of separate victim addresses is an insane amount of work though.



3. Post 67026537 (unedited backup) (by notocactus) (scraped on Sun Aug 9 15:28:07 CEST 2026) in Has ai changed the way you merit?:

Quote from: LoyceV on August 08, 2026, 09:21:36 AM
I really hate how "Merit" is now bringing shitposters to the boards that used to be okay. Until 2 years ago, I didn't frequently have to Ignore users who posted in Meta or the tech boards.
The problems of spam in last four years and it has increased with time are all from merit system failures. When shitposters ranked up easily, with shitposts, they will spam everywhere.

I noted about it.
Quote from: notocactus on July 24, 2026, 10:23:01 AM
Think:
If we force spammers to rank up by posting good, we force them to have a good writing habit, and when they ranked up already, they will more likely post good, or at least better than spammers.

A person who ranked up from posting good will make it a writing and posting habit and will not lose it after ranking up to Hero member or Legendary member rank, whereas the spammers who ranked up by shitposts to Hero/ Legendary member rank will continue his habit (writing shitposts). While with time, the farm becomes bigger and more shits around.

Quote
The number of Merit sent per week didn't go down, but the number of posts dropped a lot:
About 8 years ago, Bitcointalk had 353813 posts per week, now it's 23065. That's 93.5% less (although not all of those posts were spam).
That means there's about 15-20 times more Merit per post now. That explains why shitposters can rank up, and I think there's too much Merit going around, and in the wrong places.
Before this post, I remember someone posted that total new accounts did not increase too much, but spam increased a lot. If my memory serves me, you made that post some days after the signature ban kick-off.

That information is right because I saw they woke up newbie accounts then farmed merits and it has become more popular when they got more merits in their circles, from merit sources and years later, it's what we have witnessed recent months with shitposts around.

I also posted somewhere that they have a trick to create threads, waiting a merit source to merit it, then they will use their accounts to merit that thread/ post. They take advantage of merit source like a quality guarantee for that post/ thread, and honestly it's a clever strategy but when it is abused, it's easily realized.



4. Post 67026494 (unedited backup) (by SensitiveEyes) (scraped on Sun Aug 9 15:10:07 CEST 2026) in Upcoming Bitcoin Hard Fork, which chain will you stay on?:

Quote from: pooya87 on Today at 03:52:52 AM
2% support is a joke. They must have more than 2% support to shift support away from bitcoin. If the fork comes to existence how can I extract the new coins from my wallet? Which name is the latest fork called. I will dump them if I can extract them. Which exchanges are recommended to dump the malicious coins?
Like most shitforks, they will most probably try to call themselves "bitcoin" as well. Similar to what bcash guys did in early days back in 2017 like having it listed as bitcoin on bitcoin.com website (Roger Ver owned the site).

I don't think this chain would come to existence considering it only has ~2% support from miners but hypothetically the process to claim the "airdrop"! is similar to the past ones. Read the LoyceV topic (the link is in the comment above mine).

The biggest problem is that since this is an exact copy of bitcoin (blockchain and code) the risk is the lack of what's known as "Replay Protection". That means if you create a bitcoin transaction and send it out (on bitcoin network), the same exact transaction is valid on this forked chain and vice versa.
So if for example you find an exchange that sells this shitforkcoin and send your shitforkcoins to an address generated on that exchange (on the shitfork network), your bitcoins could also be sent to the same address (on bitcoin network) as well; and getting them back from the exchange could be a problem if the exchange doesn't want to cooperate which they usually don't.

That makes dumping such forkcoins complex. You first need to generate 2 addresses that you control and then simultaneously send the same coins on both chains to different addresses on each chain (eg. bitcoin to address_1 and shitfork to address_2). If that failed due to replay attacks, you should repeat that until you succeed in separating your coins. Then you spend your shitforkcoins from address_2 to the exchange.

The other difficulty you'll face is the slowness since as I said this malicious fork doesn't have any support and with low hashrate blocks could only be found at very large intervals which makes confirmation a nightmare not to mention such a chain would be susceptible to 51% attacks.
The risks are high so the message to btc people is clear. You must not support any fork which is supported by ~2%. Tempted people must not risk their valuable bitcoins for new forked coins unless Replay Protection is in place but dumping them in exchanges is going to be strenuous. If the forked coins come to existence they will be worthless because exchanges do not waste precious time on worthless forks.



5. Post 67026428 (unedited backup) (by joker_josue) (scraped on Sun Aug 9 14:34:37 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: LoyceV on Today at 10:48:34 AM
Quote
I'm talking about the seed (so to speak), because to date that's what's guaranteeing the security of these coins.
I wasn't around back then, but I assume Bitcoin-qt back then used the computer's random number generator. Satoshi didn't reuse addresses, so he simply created (give or take) 20,000 different random private keys. There was no "seed" yet.

That's why he said "so to speak".

Back then, seeds weren't used. I had a wallet like that. 10 years later, I went back to that wallet and everything was there, all in order. Without seeds and "complex things".

Perhaps what's needed is to relearn how to build wallets without adding more and more extras.

I once read something very interesting: "The more security a person seeks, the less security they end up having. Confidence increases, and you become careless about simple things."




Quote from: knowngunman on Today at 11:36:25 AM
Nah, he meant business. Considering the effort put on this, he did it deliberately.

I don't know if such a great effort was needed at the beginning.

Entropy was quite low. The good fortune of quickly finding a wallet with substantial funds motivated him to go further and allocate more resources.

But of course, I don't think he's an amateur. It was certainly well-planned, but you can't have spent too much time planning, for fear of someone else discovering the flaw first.



6. Post 67026371 (unedited backup) (by pbies) (scraped on Sun Aug 9 14:09:01 CEST 2026) in List of all Bitcoin addresses with a balance:

Quote from: LoyceV on Today at 11:55:28 AM
While there is entry about each GET in the logs, not each one of them is downloading whole file.
It logs the size downloaded. I didn''t block you, did I?

Quote
I am checking for file size before download, so you get entry in log file, but the file is not fully downloaded (in fact nothing is downloaded, only size checked).
Isn't that what HEAD is for?

I didn't checked for both of those. You may be right. Last download was yesterday morning (08-08 8:30am my time). I will let you know if I am blocked.



7. Post 67026263 (unedited backup) (by fillippone) (scraped on Sun Aug 9 13:15:37 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: LoyceV on Today at 10:48:34 AM

He could keep them still for a month or two and then send them back
To return the stolen funds, he'll need to identify each owner first, and you can bet many scammers will claim to be the owners. No single person can do that on his own.

The addresses are now compromised.
Everyone could claim the ownership of the sending addresses (the private keys).
Identifiying the original and authentic owner is almost impossible (it would require checking upon the possession of the physical hw, something that looks very impractical to me).



8. Post 67026229 (unedited backup) (by pbies) (scraped on Sun Aug 9 12:59:37 CEST 2026) in List of all Bitcoin addresses with a balance:

@LoyceV

While there is entry about each GET in the logs, not each one of them is downloading whole file.

I am checking for file size before download, so you get entry in log file, but the file is not fully downloaded (in fact nothing is downloaded, only size checked).



9. Post 67026109 (unedited backup) (by examplens) (scraped on Sun Aug 9 12:04:19 CEST 2026) in Mixers to be banned:

Quote from: AB de Royse777 on August 08, 2026, 09:34:03 AM
That's already the campaign manager's job Wink
Manager tempban himself and the participants? Wink
Yesterday I received a notification from your ANN thread, and frankly it seems to me that you are playing on thin ice. Some reference links could be considered a violation of mixer ban rules. (I think I drew your attention to that earlier). I advise you to revise it or at least talk to theymos about it.
You yourself know that there are many members who would be happy to start a new drama against you, and it would probably be good for your health and the health of your business if you solved it preventively.



10. Post 67025936 (unedited backup) (by joker_josue) (scraped on Sun Aug 9 10:38:19 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: LoyceV on Today at 08:27:01 AM
The thing is, at first it all looks very nice and generates a lot of excitement, but when you start to see the real impact, things change a bit.
I'm not saying he's going to return the stolen coins, but at least he might be going through a period of reflection.
That's why I came up with this theory:
Or could it just be an amateur who's in way over his head? Someone who accidentally stumbled upon this weakness, and suddenly ended up with $70 million in stolen funds?

I don't think he's exactly an amateur, but I understand the point.

I can imagine the situation: he discovers the flaw and goes to test it to see if it's really true.
Start running the script, perhaps with the goal of verifying if your own wallets are affected. Within minutes, they begin targeting third-party wallets with hundreds of BTC being transferred to your account.
I believe the first reaction will be one of shock, but at the same time, incredibly exciting.
Suddenly 1000 BTC appears in your account. You must be ecstatic in your basement.
You're probably already thinking of a thousand and one things you'll want to do with that money.

As the hours tick by and the news breaks, the dilemma begins: how are you going to move the money without getting caught? I stole hundreds of BTC from people who saved their whole lives. What have I done!?

Now you may be debating whether to return everything, return part of it, or ignore the matter altogether.



Quote from: LoyceV on Today at 08:27:01 AM
Perhaps we need to look again at the master Satoshi and see how he created his wallets.
They've been sitting there for over 15 years without suffering any problems, despite probably being the most attacked wallets in the world.
Satoshi used Send to Pubkey transactions, whilch may become quantum vulnerable in the future. That's not the best example for the long term. But his random generation must have been pretty good Smiley

I'm talking about the seed (so to speak), because to date that's what's guaranteeing the security of these coins.



11. Post 67025812 (unedited backup) (by NotATether) (scraped on Sun Aug 9 09:32:37 CEST 2026) in LoyceV's Merit data analysis (full data since Jan. 24, 2018; not just 120 days):

Quote from: LoyceV on Today at 06:43:11 AM
I have this blockdata project that's outgrown my server space, but in the past year I haven't heard from anyone who misses it.

Interesting, I'll grab a copy of it's only a terabyte.  Smiley



12. Post 67025582 (unedited backup) (by NotATether) (scraped on Sun Aug 9 06:20:19 CEST 2026) in LoyceV's Merit data analysis (full data since Jan. 24, 2018; not just 120 days):

LoyceV, can I create a mirror of your data on my new baremetal server?

I unexpectedly received more storage.



13. Post 67025560 (unedited backup) (by pooya87) (scraped on Sun Aug 9 05:52:55 CEST 2026) in Upcoming Bitcoin Hard Fork, which chain will you stay on?:

Quote from: legiteum on August 08, 2026, 03:35:19 PM
chain that the US government allows to still be called "Bitcoin" without being prosecuted for trademark violations.
It's funny how delusional some people are Cheesy

Quote from: SensitiveEyes on August 08, 2026, 11:17:14 PM
Quote
So which chain will you choose and which chain will you sell your duplicate coins on?
Isn't it obvious? A malicious fork that only has 2% support is not something to even think about. It may not even come to existence.
2% support is a joke. They must have more than 2% support to shift support away from bitcoin. If the fork comes to existence how can I extract the new coins from my wallet? Which name is the latest fork called. I will dump them if I can extract them. Which exchanges are recommended to dump the malicious coins?
Like most shitforks, they will most probably try to call themselves "bitcoin" as well. Similar to what bcash guys did in early days back in 2017 like having it listed as bitcoin on bitcoin.com website (Roger Ver owned the site).

I don't think this chain would come to existence considering it only has ~2% support from miners but hypothetically the process to claim the "airdrop"! is similar to the past ones. Read the LoyceV topic (the link is in the comment above mine).

The biggest problem is that since this is an exact copy of bitcoin (blockchain and code) the risk is the lack of what's known as "Replay Protection". That means if you create a bitcoin transaction and send it out (on bitcoin network), the same exact transaction is valid on this forked chain and vice versa.
So if for example you find an exchange that sells this shitforkcoin and send your shitforkcoins to an address generated on that exchange (on the shitfork network), your bitcoins could also be sent to the same address (on bitcoin network) as well; and getting them back from the exchange could be a problem if the exchange doesn't want to cooperate which they usually don't.

That makes dumping such forkcoins complex. You first need to generate 2 addresses that you control and then simultaneously send the same coins on both chains to different addresses on each chain (eg. bitcoin to address_1 and shitfork to address_2). If that failed due to replay attacks, you should repeat that until you succeed in separating your coins. Then you spend your shitforkcoins from address_2 to the exchange.

The other difficulty you'll face is the slowness since as I said this malicious fork doesn't have any support and with low hashrate blocks could only be found at very large intervals which makes confirmation a nightmare not to mention such a chain would be susceptible to 51% attacks.



14. Post 67025534 (unedited backup) (by tbct_mt2) (scraped on Sun Aug 9 05:24:13 CEST 2026) in Upcoming Bitcoin Hard Fork, which chain will you stay on?:

Quote from: NotATether on Today at 01:05:00 AM
Don't care, all I want to do is redeem my BIP-110 fork coins. Hopefully they have some value in them.

Anyone want to point me to some exchanges supporting both?
Claiming forked coins is a very dangerous action because it will need private keys of your bitcoins. That means if people are greedy to get forked coins, but they do their fork claiming carelessly by leaking their Bitcoin private keys in a wallet that still stores bitcoins, their bitcoins will possibly be stolen. It's not only just risky but very stupid, being greedy to get forked coins that still don't know about their values while firstly and very quickly, they might lose their valuable bitcoins.

LoyceV's Bitcoin Fork claiming guide (and service).



15. Post 67024828 (unedited backup) (by Meuserna) (scraped on Sat Aug 8 22:53:37 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: LoyceV on Today at 08:13:37 PM
I believe it's wiser to use a simple passphrase as a decoy wallet. One word, easily cracked, for a decoy wallet. And leave the seed-only wallet untouched, never used.
I like this option! In Coldcard's case, it would likely have taking the attacker a very long time to search the entire seed word space for simple passphrase options.

Question: how do brute-force attacks typically work? Do they check against the first address in a wallet, or the first N addresses?

It depends on what's being brute forced and how the attacker tries to do it.

Seed Phrases:

The ColdCard firmware flaw caused ColdCard to only generate seeds from a small number of possibilities. It's still in the billions though.

What the original attacker surely did was run a script to generate the same list of seed phrases. Billions. The script then generated wallets from those seed phrases and searched addresses for a balance. Evidence suggests the attacker's script stopped searching a seed when it found an empty address and moved on to the next seed.

Normally, hunting for wallets by searching random seeds is impossible. There are too many possible seed phrase combinations to search. It's in the quadrillions of quadrillions of quadrillions. But the ColdCard firmware bug meant all seeds generated by ColdCard came from a much smaller list unless the user used dice rolls. This made it possible to hunt for ColdCard seed phrases.

And by the way... I'm sure attackers are trying to find 2-of-3 multisigs this way. They're generating seed phrases and testing combinations to see if any generate wallets with a balance. That's a much slower process, but for attackers, it just means running a script and letting it churn away as it tests combinations. I do think 2-of-3 multisig wallets created on ColdCards will be found.

Passphrases:

Trying to crack a passphrase is different.

The first thing an attacker will probably do is a dictionary search. They'll run a script to try all words to see if any are being used as a passphrase. Anything more than 4 or 5 words isn't going to be easily found. Anything more than 6 words isn't going to be found at all.

Again, to be clear: They'll generate a wallet at the seed+abandon to see if they get an address with a balance. No? They'll generate a wallet for the seed+ability to see if they get an address with a balance. Etc. They have to generate and check every wallet, one at a time.

Th next thing an attacker will probably try is a charachter search. This is slower. They have to generate a wallet for the seed+a... then the seed+b... then the seed+c. And they have to test every wallet for every number and symbol too. Then they start over to check wallets for the seed+aa and the seed+ab and the seed+ac... etc. They'll be running a script that churns away until it finds something.

Here's the thing:

Brute force attacking passphrases is only feasible if the attacker has a reason to check that specific seed phrase.

If a seed phrase has never been used by itself as a wallet, an attacker has no way of knowing if it's been used with a passphrase or as part of a multisig... unless the attacker found the paper/metal backup of course. That's an obvious clue the seed was probably used. But in the ColdCard attacks, the thieves are searching seed phrases based on the list of billions of possible seeds the borked ColdCard firmware could generate.

If your seed phrase was truly random, it cannot be found by seed phrase hunting. Bu ColdCard's seeds weren't truly random, so they can be found by using the same borked method ColdCard used.



16. Post 67024812 (unedited backup) (by d5000) (scraped on Sat Aug 8 22:48:49 CEST 2026) in Mixers to be banned:

Quote from: LoyceV on Today at 08:10:14 PM
This discussion started after a campaign manager (who had been caught promoting banned mixers several times already) asked about promoting it again:
I don't see anything bad in "asking" about it if the platform removed the mixer from the website. Currently I don't see a mixer link there - only I see something about a "coming" privacy/CoinJoin feature. (The repeated knowing promoting of mixing services instead would, in contrast, be a reason for a ban.) However I don't know the details of the case.

The proposal of a hard deadline of a week I made was only because the discussion shifted to a more generalized question, away from the Omnisee case. And I think this is good, it would be best to have a clear rule (even if "unofficial" Wink like most rules in the forum), instead of reacting to every case individually.

Quote from: PrivacyG on Today at 07:57:05 PM
The one week rule is unnecessary in my opinion.  If theymos already knows when the website started 'offending', it would be an unnecessary extra effort to count down to 1 week, notify everyone about it, launch bans et cetera when he could simply delete the Topic and remove the signatures of all participants in the first moment he finds out.
The idea is that theymos' involvement would not even be needed. The rule would generate the incentives for the managers to handle these cases fastly and with the least possible drama. theymos would be simply notified to include the link in the blacklist, but the signatures then would already have disappeared.

Quote from: PrivacyG on Today at 07:57:05 PM
Because other than money, what stops a multi million Mixer industry from constantly creating multiple websites that appear to have no thing to do with Mixers, advertising them through signature campaigns on Bitcoin Talk and silently adding the feature later on?
Thus in my past post I clarified that I would support a ban for repeating offenders if they know (that can be proven with archive.org links for example) that they should have detected that website as a mixer.

Anyway I don't expect this to happen too often.

Quote from: PrivacyG on Today at 07:57:05 PM
An option I am thinking of is platforms escrow a monetary guarantee that they do not own a 'prohibited' service and that they will not silently add one to their platform.  Most of the campaigns already have an escrowed guarantee, this could be added as part of the escrow terms.
If the problem becomes bigger then it's an idea to consider, but otherwise I don't consider it necessary - as I wrote I think the hard 1 week deadline would provide the needed incentives already to react fast.



17. Post 67024534 (unedited backup) (by d5000) (scraped on Sat Aug 8 21:20:55 CEST 2026) in Mixers to be banned:

Quote from: LoyceV on Today at 09:30:41 AM
That's already the campaign manager's job Wink
I agree, but practically speaking ... how can a manager detect a service in advance that later will change their product portfolio and offer a "prohibited" service? If you have a customer who wants to do something fishy with the good you're selling to them, they probably won't tell you.

Most rules for offenses in social networks and forums are of the type: if you detect malicious behavior X, you have time until time/date Y to react to it (e.g. remove offending links or content).

Technically it would be optimal if the managers had some option to sigban their own participants indeed. But I don't think this is feasible or desirable.

I think also if we had the strict 1-week rule followed by a credible ban threat, then admin intervention normally would be minimal, because managers would be as fast as possible to close the affected campaigns. And normally 80-90% of the participants would also react faster, because if they see that the campaign is paused, they would remove their signature and search a new one.

What I could imagine was a stricter rule for serial offenders, i.e. if a manager is suspected to knowingly admit offending services he could have detected (e.g. because their advertising wording was already close to a mixer's from the start on), or has already repeatedly campaigns for offending services before, they could be banned instantly. Same for participants who advertised offending services repeatedly.



18. Post 67024255 (unedited backup) (by Meuserna) (scraped on Sat Aug 8 19:43:49 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: flatt on Today at 09:55:35 AM
some people have a non passphrase wallet as a decoy with passphrases behind it.
I wonder how many people realize that in this case, a "decoy" wallet have increased the risk, as it tells the attacker they found a used seed phrase. That gives them the possibility to start brute-forcing the passphrase. If you would have used the weak seed phrase only in combination with a passphrase, it would have been many orders of magnitude more difficult to find.

You missed 2 real things: the perspective of hacker & the function of decoy.

it's called decoy for a reason. once the owner see their decoy is gone , the owner can immediately move the funds. it does not increased the risk at all, it literally does increased the security for the funds. and in this case (the worst case ever displayed on this day UNTIL probably 100 next years), the hacker knows well brute-forcing into passphrase is such a waste of time because the owner could be already moved the real funds within no-time.

FYI, brute-forcing passphrase for a single wallet most likely TOOK MORE TIME than brute-forcing the whole ColdCard default seed.

I've changed my mind about decoy wallets. I now think using the seed-only wallet as a decoy isn't a good idea.

Using the seed-only wallet as a decoy lets whoever finds that seed know the seed phrase has been used. That gives them a reason to start searching passphrases.

The ColdCard attackers had to search billions of seed phrases to find coins. Searching billions of seed phrases isn't hard since the attacker was surely running automated scripts to generate wallets and check addresses. Almost all of the seeds were empty. Maybe a few thousand out of billions of seeds had wallets.

Even in the ColdCard situation, where the total number of possible seeds is limited and known, it's still billions of seeds. It isn't feasible for thieves to try to crack passphrases for billions of wallets, since they don't know which of the billions of seeds might have passphrase wallets except for those which had something at the main seed-only wallet. Those thieves are trying to crack passphrases of seeds they know have been used.

I believe it's wiser to use a simple passphrase as a decoy wallet. One word, easily cracked, for a decoy wallet. And leave the seed-only wallet untouched, never used.



19. Post 67024155 (unedited backup) (by snipie) (scraped on Sat Aug 8 19:03:08 CEST 2026) in Has ai changed the way you merit?:

Quote from: LoyceV on Today at 09:21:36 AM
I am very surprised to see a poster like you can discuss about post quality.
Just one post and a quick look at Silikiem's post history was enough to add him to my Ignore list.

I avoid putting people in my ignore list so I can watch what they say without additional clicks. Well, some exceptions are made.
I believe having a script or an option to filter or restrict sending merit to a specific user would be better than ignoring them. I am talking especially about staff with the ability to ban members mainly.

By the way, members of some signature campaigns should be double checked because having a long post and 2 - 3 quoted texts in the same post are classic ways to avoid suspicions and make their posts look good while they are empty inside.



20. Post 67023734 (unedited backup) (by flatt) (scraped on Sat Aug 8 16:40:49 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: LoyceV on Today at 02:24:10 PM
This still doesn't increase the risk as you claim.
You're still missing the point: if someone added a passphrase to his weak Coldcard without funding a decoy wallet, his funds wouldn't have been taken. It's the decoy that makes the seed words and thus potential passphrase light up.

Good point, but at that point, there's no such decoy thing if you're not funding on it.



21. Post 67023679 (unedited backup) (by flatt) (scraped on Sat Aug 8 16:22:43 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: philipma1957 on Today at 01:30:05 PM
some people have a non passphrase wallet as a decoy with passphrases behind it.
I wonder how many people realize that in this case, a "decoy" wallet have increased the risk, as it tells the attacker they found a used seed phrase. That gives them the possibility to start brute-forcing the passphrase. If you would have used the weak seed phrase only in combination with a passphrase, it would have been many orders of magnitude more difficult to find.

You missed 2 real things: the perspective of hacker & the function of decoy.
Nope, I didn't miss that. A decoy works if someone finds your (physical) seed phrase backup. In this case, the decoy is like a big flag that says: "there could be more money here".

perhaps there is a script that monitors the decoy addy. the decoy gets swept: tons of warnings in real life start happening. gives a head start to move the passphrased coins out.

one works from real life attacks, one works from cyber attacks.. half dozen of one is 6 of the other, pick yer poison


[...] if a simple paper wallet outlives a hardware wallet, why even bother with the hardware?.

pretty much this. and i started with one of the 1st trezors. i still trust trezor but i bring my own entropy now.

Yeah I ended up adding passphrase to my trezors.

3 washers with 8 characters each

I decided on 32 of my 36 punches knock out 0OIL

so my passphrases are 32 to the 8th cubed or

1099511627776 x 1099511627776 x 109951162776

that's 121 bits and the 1099511627776 is all the cold card had as that is 40 bits.


as for convinent well the trezor has a standard wallet with say 0.04 BTC and the each of the 3

passphrases have say 0.32BTC total 1 of  btc

what's nice is keeping the passphrase in my banks safety deposit box slows .96 btc from my own spending

issues.

do I like it no






I would never make myself harder than before like that, but currently I choose my favorite signature, hashes it and put it as my extra passphrase, which I can access it from anywhere anytime.



22. Post 67023598 (unedited backup) (by flatt) (scraped on Sat Aug 8 15:56:19 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: LoyceV on Today at 12:22:57 PM
some people have a non passphrase wallet as a decoy with passphrases behind it.
I wonder how many people realize that in this case, a "decoy" wallet have increased the risk, as it tells the attacker they found a used seed phrase. That gives them the possibility to start brute-forcing the passphrase. If you would have used the weak seed phrase only in combination with a passphrase, it would have been many orders of magnitude more difficult to find.[/quote]
You missed 2 real things: the perspective of hacker & the function of decoy.[/quote]
Nope, I didn't miss that. A decoy works if someone finds your (physical) seed phrase backup. In this case, the decoy is like a big flag that says: "there could be more money here".

Quote
the hacker knows well brute-forcing into passphrase is such a waste of time because the owner could be already moved the real funds within no-time.
There have already been reports of 2-word passphrases being compromised.

Quote
FYI, brute-forcing passphrase for a single wallet most likely TOOK MORE TIME than brute-forcing the whole ColdCard default seed.
That completely depends on the passphrase. If someone uses just 2 BIP39 words, that only gives 4 million possibilities, which is many orders of magnitude easier to brute-force than the weak seed words.
[/quote]

In this case, and many similar cases to come, a passphrase is still a good way to secure your funds, and letting hackers eat the decoy as a warning to move your funds immediately. This still doesn't increase the risk as you claim. The rest depends on how the user uses the "passphrase." The user could even use a one-word passphrase with 64 hexadecimal characters, and the funds would still be there until next Christmas when the user is ready to move the funds.

In short, it depends on:
1. How the attacker detects whether it's a decoy address and decides to invest all their resources in a single wallet that they believe "It's a decoy, got a correct passphrase and you'll get the whale." which there's no script / tools exist for detecting such things.
2. (MOST IMPORTANTLY) how the user leverages the passphrase instead of entering their Instagram password to secure their real funds.

I still believe in SHA256, and accessing my funds from anywhere I want without letting a company give me the keys to my funds or storing my own keys in SDB is far worse.



23. Post 67023513 (unedited backup) (by philipma1957) (scraped on Sat Aug 8 15:30:08 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: vapourminer on Today at 12:43:16 PM
some people have a non passphrase wallet as a decoy with passphrases behind it.
I wonder how many people realize that in this case, a "decoy" wallet have increased the risk, as it tells the attacker they found a used seed phrase. That gives them the possibility to start brute-forcing the passphrase. If you would have used the weak seed phrase only in combination with a passphrase, it would have been many orders of magnitude more difficult to find.

You missed 2 real things: the perspective of hacker & the function of decoy.
Nope, I didn't miss that. A decoy works if someone finds your (physical) seed phrase backup. In this case, the decoy is like a big flag that says: "there could be more money here".

perhaps there is a script that monitors the decoy addy. the decoy gets swept: tons of warnings in real life start happening. gives a head start to move the passphrased coins out.

one works from real life attacks, one works from cyber attacks.. half dozen of one is 6 of the other, pick yer poison


[...] if a simple paper wallet outlives a hardware wallet, why even bother with the hardware?.

pretty much this. and i started with one of the 1st trezors. i still trust trezor but i bring my own entropy now.

Yeah I ended up adding passphrase to my trezors.

3 washers with 8 characters each

I decided on 32 of my 36 punches knock out 0OIL

so my passphrases are 32 to the 8th cubed or

1099511627776 x 1099511627776 x 109951162776

that's 121 bits and the 1099511627776 is all the cold card had as that is 40 bits.


as for convinent well the trezor has a standard wallet with say 0.04 BTC and the each of the 3

passphrases have say 0.32BTC total 1 of  btc

what's nice is keeping the passphrase in my banks safety deposit box slows .96 btc from my own spending

issues.

do I like it no







24. Post 67023377 (unedited backup) (by vapourminer) (scraped on Sat Aug 8 14:43:19 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: LoyceV on Today at 12:22:57 PM
some people have a non passphrase wallet as a decoy with passphrases behind it.
I wonder how many people realize that in this case, a "decoy" wallet have increased the risk, as it tells the attacker they found a used seed phrase. That gives them the possibility to start brute-forcing the passphrase. If you would have used the weak seed phrase only in combination with a passphrase, it would have been many orders of magnitude more difficult to find.

You missed 2 real things: the perspective of hacker & the function of decoy.
Nope, I didn't miss that. A decoy works if someone finds your (physical) seed phrase backup. In this case, the decoy is like a big flag that says: "there could be more money here".

perhaps there is a script that monitors the decoy addy. the decoy gets swept huge, tons of warnings in real life start happening. gives a head start to move the passphrased coins out.



25. Post 67023273 (unedited backup) (by Cricktor) (scraped on Sat Aug 8 14:09:13 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: joker_josue on Today at 07:23:16 AM
The only way to be prepared anywhere in the world is to always have your seed with you.
How many of us have all the seeds with us 365 days a year, always?
If that were actually necessary, we should consider the whole setup to be terribly wrong and faulty. I find this very very wrong to have to carry my mnemonic seeds with me all the time. Sorry, no, this should NOT be necessary! And it is not necessary if we knew that entropy generation wasn't screwed up completely.

Apparently there's more due diligence needed to verify that entropy generation isn't flawed. Easier said, than done, though...


Quote from: NotATether on Today at 07:26:21 AM
The necessary step is, and I'll keep yelling this from rooftops until it reaches mass adoption, to generate your own seed phrase yourself, without any hardware wallet.

And also make a BIP39 passphrase for your seed.
This can only work if users learn and understand how to safely and properly generate their own mnemonic seeds. There are many ways to screw this up without being easily able to notice it.

A mnemonic passphrase (the additional thing) needs to be complex enough to withstand brute-force attacks (it's also computationally somewhat expensive as each guess iteration requires 2048 rounds of PBKDF2 with HMAC-SHA512), but it adds a security layer with no margin for error if you fail to document it properly and highly recommended also redundantly. Commonly you should also separate it from your mnemonic recovery words, so it needs separate secure storage places.

That's quite a (necessary) burden with many possibilities for people to screw up.

On the other hand, with the necessary knowledge and understanding, I'm with you. I just have doubts it will work out for the masses.


Quote from: LoyceV on Today at 08:07:50 AM
I wonder how many people realize that in this case, a "decoy" wallet have increased the risk, as it tells the attacker they found a used seed phrase. That gives them the possibility to start brute-forcing the passphrase. If you would have used the weak seed phrase only in combination with a passphrase, it would have been many orders of magnitude more difficult to find.
If the additional mnemonic passphrase is brute-forceable, the creator has failed already badly. It does not make sense to me, e.g. to use just a few additional words from the BiP39 wordlist. The mnemonic passphrase needs to be complex enough that brute-force attacks are not feasible.

With a complex enough mnemonic passphrase I consider the "decoy" wallet as a valuable canary indicator of compromise. Users of such a setup should of course pay very much attention to not link their "decoy" UTXOs with their "hidden" main stash(es).



26. Post 67022968 (unedited backup) (by flatt) (scraped on Sat Aug 8 11:55:37 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: LoyceV on Today at 08:07:50 AM
some people have a non passphrase wallet as a decoy with passphrases behind it.
I wonder how many people realize that in this case, a "decoy" wallet have increased the risk, as it tells the attacker they found a used seed phrase. That gives them the possibility to start brute-forcing the passphrase. If you would have used the weak seed phrase only in combination with a passphrase, it would have been many orders of magnitude more difficult to find.

You missed 2 real things: the perspective of hacker & the function of decoy.

it's called decoy for a reason. once the owner see their decoy is gone , the owner can immediately move the funds. it does not increased the risk at all, it literally does increased the security for the funds. and in this case (the worst case ever displayed on this day UNTIL probably 100 next years), the hacker knows well brute-forcing into passphrase is such a waste of time because the owner could be already moved the real funds within no-time.

FYI, brute-forcing passphrase for a single wallet most likely TOOK MORE TIME than brute-forcing the whole ColdCard default seed.



27. Post 67022965 (unedited backup) (by AB de Royse777) (scraped on Sat Aug 8 11:55:07 CEST 2026) in Mixers to be banned:

Quote from: LoyceV on Today at 09:42:23 AM
Manager tempban himself and the participants? Wink
Do I really have to explain it? The campaign manager's job is to prevent reaching the point where Admin has to step in.
I thought we are talking about un-promotable condition (sudden discover) and handing out harsh ban.



28. Post 67022905 (unedited backup) (by AB de Royse777) (scraped on Sat Aug 8 11:34:07 CEST 2026) in Mixers to be banned:

Quote from: LoyceV on Today at 09:30:41 AM
That's already the campaign manager's job Wink
Manager tempban himself and the participants? Wink



29. Post 67022509 (unedited backup) (by promise444c5) (scraped on Sat Aug 8 08:23:37 CEST 2026) in [Userscript] Bitcointalk Merit Automation: Queue & Schedule Merit Distribution:

Quote from: vapourminer on August 07, 2026, 08:32:00 PM

lets see how it handles > 50 merits a month as i can only send one more to you this 30 day period.. ill try to send 10

*click*


edit: seems to of tripped on this when it tried.. nice

Quote
Error: You can only send 1 merit to this user.

Yes.. I added this line of code in the last update:
Code:
else if(lowerHtml.includes("you can only send 50 merit ")) {
                const match = lowerHtml.match(/you have already sent (\d+) merit to that user/i);

                const sentMerit = match && !Number.isNaN(Number.parseInt(match[1], 10))? Number.parseInt(match[1], 10) : 0;
                errorMsg = sentMerit >= 50 ? "You have already sent the maximum amount of merit to this user."
                            : sentMerit === 0 ? "You cant send merit to this user right now."
                            : `You can only send ${50 - sentMerit} merit to this user.`;
                }

when you posted this :

Quote from: vapourminer on June 08, 2026, 12:24:22 PM
hit the 50 merits per month limit.. blame it on loycev
I followed LoyceV suggestion, reproduced the error and added it.

The second check and the greater than  were just extra extra [/url]



30. Post 67017933 (unedited backup) (by JayJuanGee) (scraped on Thu Aug 6 19:56:19 CEST 2026) in The paranoid user's security guide for using Electrum safely.:

Quote from: satscraper on Today at 07:31:39 AM
Hundreds of years to thousands of years might be enough difficulty, perhaps?
In some cases the length of the search space really matters, especially when you use the "pattern" approach. My passphrase that extends SEED is 32 characters long filled with  small letters, cups, digits and special characters, and at the same time there is no effort for me at all in reproducing it even with my eyes closed because I use Gibson's trick.

I had to look up Gibson's trick and I think that it is good up to a point- even though it takes away from some randomness, but the filling in of characters likely ends up helping with difficulties to guess the password by others or difficulties to break by password guessing machines.



For example, sometimes we might have created some passwords and then we cannot remember the exact details of how we had varied the base word(s), so maybe if the password base starts out as:

Great Mary

So then we try to consider how to vary our base word, so then maybe we might vary it, yet without practice we cannot recall the exact details of how we had varied it. Maybe the end result looks like this:

34gGgGr88ea88t##mMmM@@ry43 

That seems pretty hard to break, even though it is not random, and we might have to create some kind of a note to ourself to remind us of our password and how we had varied our password within some formula that we will remember based on a note to ourself, no?

Quote from: nc50lc on Today at 07:42:10 AM
The passphrase does not even have to be very long in order to get somewhere between light orange and dark orange, and yeah of course, guys might choose even higher levels of protection.
That's if it's totally random characters, adding a dictionary word can be used as an attack vector even if that word is 10 letters long.
Then the chart can be used for the additional symbols and numbers in consideration of how many dictionary words are currently available.

But since NotATether said 12-24 "words" long, that length is practically a requirement since otherwise, it'll be susceptible to dictionary attack.
- NEW: You should definitely use BIP39 passphrases for your seeds. In fact, if I were you, I'd make it at least 12 or 24 words long, just like your seed.
Alternatively, just make it a combination of real words plus random letters, numbers and symbols so it wont have to be 12 words long to be strong against bruteforce.
Either way (12-24 word passphrase or that), the user has to write it down on a separate paper anyways.

I think that it is good to make clear that there is a difference when we are talking about our passwords and our passphrase.

The recent Coldcard issue ended up causing the initial passwords to be easily crackable, so then the passphrase ended up giving a second layer of protection, and of course, if we knew that our passwords were going to be so vulnerable, then we need even higher levels of protection for our passphrase.

I doubt that in normal cases we need our passphrase to be treated the same as our passwords so 12 characters or more with a combination of characters, numbers, letters, and capital letters is better, even though maybe there might be some lacking in our randomness in the sake of our also wanting to have some abilities to have some memory of it out of convenience and also not wanting to lock ourselves out of our own coins.  And, surely our own level of paranoia might cause us a lot of inconvenience if we end up overdoing it.

Quote from: LoyceV on Today at 02:51:28 PM
Hundreds of years to thousands of years might be enough difficulty, perhaps?
It depends Tongue A password that would have taken thousands of years to crack in 1990 won't be secure now, and the same can probably be said for a password that's currently safe if you add another 36 years of computing improvements.
I'd say this is an argument for using much heavier encryption: BIP38 for instance is still very expensive to brute-force. Passwords become annoying to type and remember if they're too long. If "one attempt" takes 0.1 seconds, an attacker can't test millions of even billions of passwords per second.


Anything that takes a "normal" hacker a thousand years to brute-force, will still be peanuts to someone with (very expensive) access to an (AI) data center.

I agree that a lot of us are likely rethinking the level of complexity of our previous passwords and the extent to which we need to improve them for modern times, as the times are ongoingly evolving.



31. Post 67017877 (unedited backup) (by ryzaadit) (scraped on Thu Aug 6 19:38:07 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: Bullethead21 on Today at 10:32:39 AM
I have a TREZOR? I am still save?


Best thing to do, add your own entropy my friend. Learn about entropy.

Quote from: LoyceV on Today at 02:29:00 PM
Was that a new hardware wallet with a newly created seed phrase, or a seed phrase that was compromised before?
If it's the former, that means someone (or multiple entities) are now racing through all ~trillion possible seed phrases to detect any new incoming funds.
Unfortunately, it's new.

Quote from: pawanjain on Today at 02:44:08 PM
At this point, I have stopped trusting these hardware wallets. Are there even any option left for really good hardware wallets?
Just because of one stupid manufacturer mistake, don't lose your belief in hardware wallets. There are so many good hardware wallets out there.

People forget some important things, mostly new people. They think that owning a hardware wallet their fund 100% secure, and this is the reason by using hardware wallet removes the feeling of safety, especially for anyone who has not learned more about safety risk.

Hardware wallets are just one key element; you can add more security risks to your stored system.
- Learn entropy
- Make your own key
- Create a multi-signature transaction
- Store your funds not just in one single bucket



32. Post 67017176 (unedited backup) (by Stalker22) (scraped on Thu Aug 6 15:47:37 CEST 2026) in nvK c0inkite c0ldacrd is Anti-OpenSource nutcase:

Quote from: LoyceV on Today at 01:21:58 PM
Anyway, I'm sorry that I have promoted ColdCard in the past.
You might want to update your feedback on this guy.

I agree.  @DireWolf, it is obviously totally your choice whether you keep that positive rating on his account.  But you should at the very least correct the facts that have been proven wrong in the meantime.



33. Post 67016803 (unedited backup) (by Wind_FURY) (scraped on Thu Aug 6 13:22:13 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: decodx on August 05, 2026, 06:56:46 AM

The community in general is still "lucky" that the stupidity came from the ColdCard developers.


This is one of the reasons I'm always careful paranoid when a new wallet (be it hardware or software) is released. It took me years to trust Ledger (until they broke that trust), and now I only have Trezor left on my personal preferred list of hardware wallets.
The fact that this Coldcard flaw was around for 5 years makes it only harder to trust anything.


But for the truly paranoid, install Bitcoin Core/Electrum in a computer that will NEVER connect to the internet FOREVER, and generate your keys/seed phrase there. Write it down, then keep it in a safe place. The same for the computer, keep it locked in a vault.

Keep sending Bitcoin to that address.

To be honest, I don't think this is a good solution for the truly paranoid (or even for the mildly paranoid).   You've just switched from using hardware wallets over to Electrum as your preferred solution.

What if there was some vulnerability exposed within the Electrum development? It really wouldn't make that much difference to the final outcome.


Read my post again. I believe you didn't understand that it's one of the original solutions for cold-storage before hardware wallets were invented. PLUS Electrum is one of the truly tested wallets in the Bitcoin ecosystem.

It's not a debate. It's a FACT.

 Cool

Shower thought. The ColdCard situation might be an inside job.

Quote

Coinkite CTO having a conversation with himself using a pseudonym.



https://x.com/DylanLeClair/status/2085074383773581570




34. Post 67016236 (unedited backup) (by Daniel91) (scraped on Thu Aug 6 08:54:31 CEST 2026) in Is there a limit to the number of PMs in the Inbox/Outbox?:

Quote from: MarryWithBTC on August 05, 2026, 10:19:37 PM
~snip
Now that you mentioned I just checked my PMs and it's already at page 29.  Have I gotten any lag when trying to load any? Well none that I can remember. The difference in load speed is very small and chances have it that you may not even notice it. Probably it could get more obvious if you constantly try to visit different old pages.

I guess the load speed he was probably referring to is just a couple extra seconds. Yahoo made some statements about his PMs too and even with that much PM he has I don't think the wait time is unbearable.

Just above your post, ico mentioned that above 500 pages, everything still works fine. I don't think there's much to bother here. Op created the thread out of curiosity and not that they were facing a serious pm loading issue.

About theymos post of pm loading becoming really slow after 30 pages, and suggesting umboxing, he was probably trying to help the server. Just as he wouldn't recommend clicking "load all pages" when you are in a 7k+ pages thread

Yes, that's right. Currently I have no problems with loading PMs and based on the reports of other members, who have a lot more messages, like icopress, I see that this will not be a problem in the future either.
With that, I got the answer to my main question, but considering that some other useful information for members appeared in the thread, such as the suggestion to use TryNinja's user script or LoyceV's PM publisher to get PMs, I think that this discussion is still useful for forum members, so I will leave this thread open.



35. Post 67015765 (unedited backup) (by Churchillvv) (scraped on Thu Aug 6 01:47:49 CEST 2026) in Has ai changed the way you merit?:

Quote from: LoyceV on Today at 08:25:33 AM
I admit that I rarely merit someone because nowadays I'm not spending much time here.
You've made 14093 posts in total, and about 200 in the last 2 months. The only way to not spend much time here is if you're only posting without reading anything, which explains why you're barely earning any Merit.
I looked at his first 5 pages of his post history and I can say above 89% of his post from the first to the fifth page is mostly gambling related post few post on other boards, which justifies him not earning enough merit.

Quote from: LTU_btc on Today at 03:15:44 PM
I still remember recommendations that had the use of AI pages that helps in correcting sentences but today it’s not longer a correction but a complete use for generation of walls of text,
Yeah, fixing grammar, spelling and style is correct use of AI, but unfortunately, good tool now is used for bad purpposes too much.
The truth is that abusers always remain abusers once they see the opportunity to abuse. Infact the world today uses thing for the wrong purpose you can relate that to every industry in the world.




36. Post 67014177 (unedited backup) (by LTU_btc) (scraped on Wed Aug 5 17:15:49 CEST 2026) in Has ai changed the way you merit?:

Quote from: LoyceV on Today at 08:25:33 AM
You've made 14093 posts in total, and about 200 in the last 2 months. The only way to not spend much time here is if you're only posting without reading anything, which explains why you're barely earning any Merit.
200 posts in 2 months - you made it to look like it would be a lot, but it's 3-4 posts a day. And you're completely wrong that I'm posting without reading. Usually I post in same old topics that I follow each day, or in fresh topics that has maybe 15-20 replies - it doesn't takes much time to read every post there. I don't see much point to post in longer topics because with my 45th reply there I can't add anything new. Or of it's continous discussion, most of time I don't have time to read everything from beginning till the end to add my input.
But anyway, this topic isn't about me.

Quote from: Churchillvv on August 04, 2026, 09:59:17 PM
I still remember recommendations that had the use of AI pages that helps in correcting sentences but today it’s not longer a correction but a complete use for generation of walls of text,
Yeah, fixing grammar, spelling and style is correct use of AI, but unfortunately, good tool now is used for bad purpposes too much.

Quote from: snipie on Today at 02:09:29 PM
LTU_btc, you were away from troubles and with your post, you brought problems.
Soon we will see some known users and their alts posting and replying for themselves with signature enabled 🍿
I don't think that I brough problems for myself there



37. Post 67014089 (unedited backup) (by Catenaccio) (scraped on Wed Aug 5 16:53:02 CEST 2026) in Is there a limit to the number of PMs in the Inbox/Outbox?:

Quote from: Daniel91 on Today at 08:52:37 AM
He also re-shared the instructions If anyone wants an mbox dump of all of incoming/outgoing PMs.
https://bitcointalk.org/index.php?topic=5570043.msg66240630#msg66240630
If you want to get all your PMs (inbox and outbox), you can try TryNinja's user script or LoyceV's PM publisher.

https://bitcointalk.org/index.php?topic=5481421.msg63489687#msg63489687]TryNinja's user script
https://gist.github.com/ninjastic/bc568895778132e1414564147d3a9aaf

LoyceV's PM Publisher's description.



38. Post 67013938 (unedited backup) (by snipie) (scraped on Wed Aug 5 16:09:31 CEST 2026) in Has ai changed the way you merit?:

Quote from: LoyceV on Today at 08:25:33 AM
I admit that I rarely merit someone because nowadays I'm not spending much time here.
You've made 14093 posts in total, and about 200 in the last 2 months. The only way to not spend much time here is if you're only posting without reading anything, which explains why you're barely earning any Merit.

I missed so much fun apparently when I enslaved myself in the gambling section. I will have a nice vacation over here watching all of you with my unhealthy popcorn.
LTU_btc, you were away from troubles and with your post, you brought problems.
Soon we will see some known users and their alts posting and replying for themselves with signature enabled 🍿



39. Post 67013913 (unedited backup) (by philipma1957) (scraped on Wed Aug 5 16:03:43 CEST 2026) in So with the cold wallet hack I am thinking about using core 29 to store.:

Quote from: LoyceV on Today at 09:50:29 AM
yeah I am going to make 10 passphrases using a set of punches

the punches are
A to z     thus 26  
 0 to 8    thus  9
and *     thus 1
Can you easily distinguish between the ones that look similar, like O<>0 and I<>1 ? If not, it's better to leave them out of the pool.

one is  1
I     is  l

so they are easy

0 and O may not be easy

I am waiting on a brass plate for fast easy back up sheet {in house}

the washers in bank vault



40. Post 67012983 (unedited backup) (by hedgeh0g) (scraped on Wed Aug 5 10:24:31 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: LoyceV on August 04, 2026, 01:03:42 PM
The community in general is still "lucky" that the stupidity came from the ColdCard developers.
This is one of the reasons I'm always careful paranoid when a new wallet (be it hardware or software) is released. It took me years to trust Ledger (until they broke that trust), and now I only have Trezor left on my personal preferred list of hardware wallets.
The fact that this Coldcard flaw was around for 5 years makes it only harder to trust anything.

Unfortunately, there is a misconception in our psychology that if something has worked for a long time before us, then we consider it proven, although it may not be so. Every new incoming user thinks, "if everyone is using it so calmly, then someone has checked everything for sure." But it turns out that the system has not been properly tested in five years. And in the age of AI, we will hear more than once about the secrets of systems that were in plain sight, but only the latest AI model will be able to find it.



41. Post 67012965 (unedited backup) (by Rikafip) (scraped on Wed Aug 5 10:18:08 CEST 2026) in Has ai changed the way you merit?:

Quote from: LoyceV on August 04, 2026, 05:58:58 PM
It's the (deleted) post Lucius linked to, see my earlier quote.
I understand that, but as I said, that's not the post I was referring to, as he linked another post that was also deleted and person who wrote it got tagged. That's the one I believe was made with AI.



42. Post 67012817 (unedited backup) (by decodx) (scraped on Wed Aug 5 08:56:49 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: Wind_FURY on Today at 06:40:55 AM

The community in general is still "lucky" that the stupidity came from the ColdCard developers.


This is one of the reasons I'm always careful paranoid when a new wallet (be it hardware or software) is released. It took me years to trust Ledger (until they broke that trust), and now I only have Trezor left on my personal preferred list of hardware wallets.
The fact that this Coldcard flaw was around for 5 years makes it only harder to trust anything.


But for the truly paranoid, install Bitcoin Core/Electrum in a computer that will NEVER connect to the internet FOREVER, and generate your keys/seed phrase there. Write it down, then keep it in a safe place. The same for the computer, keep it locked in a vault.

Keep sending Bitcoin to that address.

To be honest, I don't think this is a good solution for the truly paranoid (or even for the mildly paranoid).   You've just switched from using hardware wallets over to Electrum as your preferred solution.

What if there was some vulnerability exposed within the Electrum development? It really wouldn't make that much difference to the final outcome.



43. Post 67012771 (unedited backup) (by Wind_FURY) (scraped on Wed Aug 5 08:41:01 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: LoyceV on August 04, 2026, 01:03:42 PM

The community in general is still "lucky" that the stupidity came from the ColdCard developers.


This is one of the reasons I'm always careful paranoid when a new wallet (be it hardware or software) is released. It took me years to trust Ledger (until they broke that trust), and now I only have Trezor left on my personal preferred list of hardware wallets.
The fact that this Coldcard flaw was around for 5 years makes it only harder to trust anything.


But for the truly paranoid, install Electrum in a computer that will NEVER connect to the internet FOREVER, and generate your seed phrase there. Write it down, then keep it in a safe place. The same for the computer, keep it locked in a vault.

Keep sending Bitcoin to that address.



44. Post 67012740 (unedited backup) (by stompix) (scraped on Wed Aug 5 08:28:01 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: Lucius on August 04, 2026, 01:51:55 PM
What's wrong with a laminated paper wallet rolled up in a sealed PVC pipe filled with rice and buried in backyard?

It's okay if you don't have a dog that likes to dig, and you haven't dug deep enough - or if you have a neighbor who watches you just for fun and decides to dig around your yard when you're not home.

Flood, earthquakes, some company coming out of nowhere and digging in your yard for an emergency gas/electric line repair and many others.
Also, about the rice thing, just grab a pair of new sneakers and use the silica gel from them, rice that absorbs humidity will be a problem itself.

There is no perfect solution for anything, there is always a risk.

Quote from: BlackHatCoiner on August 04, 2026, 06:51:25 PM
Hypothetical: it just occurred to me that even if Coldcard knew about this vulnerability, they couldn't have warned users about it. The moment they issue a warning, potential attackers would know about it too, and their warning would have been the catalyst to losing funds.
So once the bug was out there, all they could reasonably do was offer updated firmware and remove the vulnerability from newly sold devices.
They could have taken most of the coins though, and give it back to the soon-to-be-victims though. Regardless, however, I agree that either way their business would be completely over.

And nobody would have believed them when they said they were giving all the coins back to the owners, everyone would have said they are preying on people who can't prove they are the owners of those coins.
A cold wallet manufacturer taking your money without your knowledge would have been the end of any company.





45. Post 67011693 (unedited backup) (by Alone055) (scraped on Tue Aug 4 22:16:13 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: BlackHatCoiner on Today at 06:51:25 PM
Hypothetical: it just occurred to me that even if Coldcard knew about this vulnerability, they couldn't have warned users about it. The moment they issue a warning, potential attackers would know about it too, and their warning would have been the catalyst to losing funds.
So once the bug was out there, all they could reasonably do was offer updated firmware and remove the vulnerability from newly sold devices.
They could have taken most of the coins though, and give it back to the soon-to-be-victims though. Regardless, however, I agree that either way their business would be completely over.

And yes, they could have warned the user of a vulnerability, but that should be worded in a way that it does not reveal your cold storage is at risk, or attackers would have got sooner than the victims by just scanning the codebase.

Would it be illogical to think that this might not be just a random attack but a preplanned one? For which the bug or vulnerability was planted years ago, and was never found or patched on purpose to keep collecting information for a major attack, but doing it in a way that shouldn't make it suspicious for those in control of everything? Because there are cases unfolding where users reported similar problems years ago, but the developers or their support never took them seriously or looked into it. Maybe those few people who got their funds stolen back then were just victims of a few test tries if it actually works or not?  Roll Eyes



46. Post 67011424 (unedited backup) (by tvbcof) (scraped on Tue Aug 4 21:01:07 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: negotiation4 on Today at 06:32:28 PM
Hypothetical: it just occurred to me that even if Coldcard knew about this vulnerability, they couldn't have warned users about it. The moment they issue a warning, potential attackers would know about it too, and their warning would have been the catalyst to losing funds.
So once the bug was out there, all they could reasonably do was offer updated firmware and remove the vulnerability from newly sold devices.
Not true, they could have advised moving funds without disclosing the vulnerability up front.

The only feasible way to 'get the word out' would be via an 'emergency' such as we are seeing now.

Of course I am very interested in whether these guys are crooks or not, so I try to look at things from all angles.  What if there was an even better reason (e.g., and even bigger back-door.)  The 'responsible' thing to do would be to scare the shit out of people with a relatively bogus defect and a dose of social media engineering.  In that way, everyone would hear it pretty soon, and would take the desired action of draining their Coldcard-based wallets ASAP while in the scheme of things the userbase would not actually lose all that much.  I'm pleasantly surprised that non of my stuff I was not hit.

Anyway, that's a charitable hypothetical excuse for Coinkite's activities and proclivities.

---

As for keeping this particular vulnerability undisclosed, it's not real practical.  The problem was really a pretty basic one which happens all the time.  [There may be some code running in space built against header files inappropriate for the Linux kernel installed due to problems much like this one.  Who knows?]

I don't do almost any coding any more, but my friends who do are ga-ga over AI.  All I can say is that if AI missed a very common pre-processor issue like this, it's not very good at code checking.  Did they forget to teach the model that RNG was extra critical?  Do they even need to?  Not impressed!




47. Post 67011387 (unedited backup) (by BlackHatCoiner) (scraped on Tue Aug 4 20:51:25 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: LoyceV on Today at 05:41:33 PM
Hypothetical: it just occurred to me that even if Coldcard knew about this vulnerability, they couldn't have warned users about it. The moment they issue a warning, potential attackers would know about it too, and their warning would have been the catalyst to losing funds.
So once the bug was out there, all they could reasonably do was offer updated firmware and remove the vulnerability from newly sold devices.
They could have taken most of the coins though. Regardless, however, I agree that either way their business would be completely over.



48. Post 67011324 (unedited backup) (by negotiation4) (scraped on Tue Aug 4 20:32:31 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: LoyceV on Today at 05:41:33 PM
Hypothetical: it just occurred to me that even if Coldcard knew about this vulnerability, they couldn't have warned users about it. The moment they issue a warning, potential attackers would know about it too, and their warning would have been the catalyst to losing funds.
So once the bug was out there, all they could reasonably do was offer updated firmware and remove the vulnerability from newly sold devices.
Not true, they could have advised moving funds without disclosing the vulnerability up front.



49. Post 67010992 (unedited backup) (by xLays) (scraped on Tue Aug 4 18:45:19 CEST 2026) in Satofan44: moron of the year 2025:

Quote from: LoyceV on Today at 11:15:31 AM
Freedom of speech ends where the "freedom" of others begins.
I don''t think that's true, at least on Bitcointalk. But freedom of speech doesn't mean I have to listen to it Wink

Yeah I don't think bitcointalk is 100% free speech but because is it of the trust system. User can say what they want, but some may hesitate if they think it could lead to negative trust rating. Whether that's justified or not is a different discussion.
Telling this based on personal experience. lol I even got neutral tag with ref "asshole" by just meriting a post.



50. Post 67010592 (unedited backup) (by m2017) (scraped on Tue Aug 4 16:14:31 CEST 2026) in Satofan44: moron of the year 2025:

Quote from: LoyceV on Today at 11:15:31 AM
Freedom of speech ends where the "freedom" of others begins.
I don''t think that's true, at least on Bitcointalk. But freedom of speech doesn't mean I have to listen to it Wink
That's why there's a magic ignore button. By the way, if he's already on your ignore list, why are you discussing someone on that list in a topic dedicated to him? Admit it, you don't get enough of he's attention? Wink

Quote from: LoyceV on August 02, 2026, 07:06:46 PM
I'd Merit those posts, but in this case, I won't read them anymore as he's on my Ignore list. His good technical posts are wasted because of his trolling and drama.


Quote from: lovesmayfamilis on Today at 08:07:54 AM
All those people who cheat the forum only seem well-mannered and decent,
Not caught is not a thief. I'm sure you know this proverb. Smiley

This world is full of hypocrisy. It can't be eradicated. But when someone starts behaving inappropriately, everyone starts to shun them. This form of "honesty" is unpopular.

Quote from: lovesmayfamilis on Today at 08:07:54 AM
You said it well, and I'll add a quote from a Russian actress who once said, "It's better to be a good person who swears obscenities than a quiet, well-mannered scum." Faina Ranevskaya.
Are you suggesting we put Satofan44 on this forum's honor roll? Smiley With the note "he's a very good person at heart"? Smiley



51. Post 67010350 (unedited backup) (by Rikafip) (scraped on Tue Aug 4 14:50:37 CEST 2026) in Has ai changed the way you merit?:

Quote from: LoyceV on Today at 11:27:03 AM
I'll read my archived version again: it reads like an open letter to "the attacker". It still doesn't sound like AI to me, and I've seen open letters like this long before AI was able to do this.
That's not the post I was referring to. When talking about another merit abuse, Lucius was talking about this post, to which I said that it "reeks of AI". User in question even tried to save himself by throwing someone else under the bus, but it didn't end up as he planned.



52. Post 67009519 (unedited backup) (by Shishir99) (scraped on Tue Aug 4 09:24:37 CEST 2026) in Unfair Multi-Account Accusation and My Experience with Xyes.com Casino":

Quote from: nutildah on Today at 06:15:07 AM
Can you explain a little bit more about what a "local MFS" is? I'm just curious. You made several deposits to a Binance deposit address shared by several red tagged accounts.

Local MFS stands for Mobile Financial Services. We have several of them, like bKash, Nagad, Rocket, and more. These MFS are backed by real banks. It's the same as a Cash App type thing, but it is kind of more regulated here. Can be used on all kinds of devices that support a SIM card. Most MFSs have their dedicated apps, and they support the USSD dial system as well. So, I am kinda sure he meant that he paid in fiat using one of these services.

As for the accounts and the usernames, these names seem Bangladeshi. I have no idea how many names a person can think of while creating an account. These names seem like real names, and not just usernames like LoyceV.



53. Post 67006675 (unedited backup) (by crypto_curious) (scraped on Mon Aug 3 13:53:43 CEST 2026) in Large-scale coldcard compromise underway. 600 BTC drained so far :

Quote from: LoyceV on August 01, 2026, 10:39:51 AM
this is partly your own fault.
Victim blaming isn't helping anyone.

Quote
Using a passphrase should be mandatory for all 24-word seed wallets.
That adds the risk of losing your passphrase. Storing keys is always a compromise between the risk of someone else gaining access, and the risk of losing access by yourself.

The victim does bear some responsibility here. There is no denying that, no matter how much people dislike hearing it.

When a passphrase is optional and users choose not to use it, they significantly increase the risk of becoming victims sooner or later. Unfortunately, that's the direction it almost inevitably leads.



54. Post 67006051 (unedited backup) (by babo) (scraped on Mon Aug 3 09:25:25 CEST 2026) in [Meta] Andamento sezione italiana:

Quote from: Theymos DT update [thread]
Agosto 2026
Lista New Users:

Code:
theymos (CONFIRMED)
HostFat (CONFIRMED)
gmaxwell (CONFIRMED)
OgNasty (CONFIRMED)
vapourminer (CONFIRMED)
Foxpup (CONFIRMED)
philipma1957 (CONFIRMED)
babo (CONFIRMED)
Cyrus (CONFIRMED)
ibminer (CONFIRMED)
d5000 (CONFIRMED)
joker_josue (CONFIRMED)
Pmalek (CONFIRMED)
Mitchell (CONFIRMED)
albon (CONFIRMED)
wwzsocki
Timelord2067
jeremypwr (CONFIRMED)
gbianchi (CONFIRMED)
EFS (CONFIRMED)
hybridsole
stompix (CONFIRMED)
hilariousandco (CONFIRMED)
buckrogers (CONFIRMED)
Buchi-88 (CONFIRMED)
Lesbian Cow
JayJuanGee (CONFIRMED)
NeuroticFish (CONFIRMED)
achow101
DaveF
examplens (CONFIRMED)
nutildah (CONFIRMED)
irfan_pak10 (CONFIRMED)
yahoo62278 (CONFIRMED)
bitbollo (CONFIRMED)
zazarb
pooya87 (CONFIRMED)
LFC_Bitcoin (CONFIRMED)
o_solo_miner
mocacinno (CONFIRMED)
Real-Duke (CONFIRMED)
klarki (CONFIRMED)
LoyceV (CONFIRMED)
SFR10 (CONFIRMED)
Lucius
Lafu (CONFIRMED)
tweetious (CONFIRMED)
AakZaki (CONFIRMED)
giammangiato
buwaytress (CONFIRMED)
crwth (CONFIRMED)
Ale88 (CONFIRMED)
Kryptowerk
hosemary (CONFIRMED)
krogothmanhattan (CONFIRMED)
JollyGood (CONFIRMED)
igebotz (CONFIRMED)
roycilik (CONFIRMED)
CryptopreneurBrainboss (CONFIRMED)
hugeblack (CONFIRMED)
El duderino_ (CONFIRMED)
KTChampions (CONFIRMED)
Trofo (CONFIRMED)
icopress (CONFIRMED)
JeromeTash (CONFIRMED)
logfiles (CONFIRMED)
Bitcoin_Arena (CONFIRMED)
GazetaBitcoin (CONFIRMED)
tvplus006 (CONFIRMED)
mole0815
bitmover (CONFIRMED)
DdmrDdmr (CONFIRMED)
Husna QA (CONFIRMED)
Bthd
fillippone (CONFIRMED)
cryptofrka (CONFIRMED)
abhiseshakana (CONFIRMED)
The Cryptovator (CONFIRMED)
lovesmayfamilis (CONFIRMED)
DireWolfM14 (CONFIRMED)
notblox1 (CONFIRMED)
Little Mouse (CONFIRMED)
YOSHIE (CONFIRMED)
inspace (CONFIRMED)
jokers10 (CONFIRMED)
Awaklara (CONFIRMED)
geophphreigh
zasad@ (CONFIRMED)
Rikafip (CONFIRMED)
Etranger (CONFIRMED)
NotATether (CONFIRMED)
Stalker22 (CONFIRMED)
decodx
BlackHatCoiner (CONFIRMED)
Charles-Tim (CONFIRMED)
Lillominato89 (CONFIRMED)
Free Market Capitalist (CONFIRMED)
ZAINmalik75
YodasRedRocket (CONFIRMED)
SirJohnVonSlotty (CONFIRMED)


. . . . Lista Utenti Italiani:

USER.............DT....DT.July 2026.BPIPNinjastic
Ale88
(DT)
SI
arulbero
SI
babo
(DT)
SI
coinlocket$
no
fillippone
(DT)
SI
gbianchi
(DT)
SI
bastisisca
no
bitbollo
(DT)
SI
giammangiato
(DT)
no
mendace
no
mars78
no
simpic
no
Lillominato89
(DT)
SI


Link Utili:





55. Post 67005995 (unedited backup) (by shahzadafzal) (scraped on Mon Aug 3 08:47:55 CEST 2026) in Pakistan:

Quote from: UmerIdrees on August 02, 2026, 02:42:09 PM
Many Congratulations to you bhai on becoming DT1, and also aus c phelay you got Legendary rank too. Bohat Bohat Mubarak ho.

By the way, in this update, shahzadafzal was removed from the list and ZAINmalik75 was added.

Theymos reshuffled DT1.

Removed:
10. Copper Member shahzadafzal (Trust: +4 / =0 / -0) (3484 Merit earned) (Trust list) (BPIP)

Added:
16.Legendary ZAINmalik75 (Trust: +4 / =1 / -0) (1005 Merit earned) (Trust list) (BPIP)

Well deserved, ZAINmalik75. 👏

To be honest, I've been on the his list for quite some time, but I've never really utilized that responsibility. In all that time, I didn't tag a single user. 🙂

That's probably one of the reasons. To be fair, I don't visit the Reputation board very often, even though that's where the trust system matters the most.

We need someone who is active and uses the trust system fairly, and I think ZAINmalik75 deserves to be on the list.



56. Post 67005797 (unedited backup) (by m2017) (scraped on Mon Aug 3 05:24:43 CEST 2026) in Satofan44: moron of the year 2025:

Quote from: lovesmayfamilis on August 02, 2026, 09:33:14 AM
Hmm, I wouldn't agree with that. People are usually judged by their friends. There are no friends on this forum, but a user's merits can be judged by those who give them to them. Can you call those who helped him rise in rank (very quickly, if you noticed) idiots? Imagine the situation offline. Would you appreciate the words of an idiot if he explained something to you? No. But here you see a completely different picture. His merits were given to him by very smart people.
Some people (up to a point) manage to carefully hide their idiocy. Smiley I can assume that at the time of his credit, Satofan44 wasn't displaying any negative qualities (did he lack the courage at the time? Smiley), and in that case, the users who credited him for quality posts can't be blamed for anything.


Quote from: LoyceV on August 02, 2026, 07:06:46 PM
I'd Merit those posts, but in this case, I won't read them anymore as he's on my Ignore list. His good technical posts are wasted because of his trolling and drama.
Here is LoyceV's explanation regarding previously merits.

Quote from: lovesmayfamilis on August 02, 2026, 09:33:14 AM
I would say that in Satofan's case, the problem is his lack of restraint, and that's very bad. He also has problems accepting the imperfections of the world, which no one can change, and he just can't accept them.🤷‍♀️
If a lack of restraint is disrupting the BTC-community, or worse, is breaking (does it break?) the forum rules, then isn't that a reason to take some action?


Quote from: Satofan44 on August 02, 2026, 08:35:14 PM
I literally do not give a fuck about races, the 3rd world consists of every single race that is present on the planet. As you see, most members including yourself can't even get the criticism of me right. You could accurately say that I am extremely rude, or provide an opinion that I am evil -- sure, but you can't claim that I am racist. My history is in fact from a very specific combination of races of the 3rd world, I have great experience with these parasitic fuckers many of which need swift and legal execution (our laws are too weak).
Quote from: Satofan44 on August 02, 2026, 08:35:14 PM
None of the terms that I regularly use refer to any kind of "race". How about users first familiarize themselves what it actually means to be racist. 3rd world parasites, pieces of shit, pajeets, Islamic goat fuckers and so forth -- none of these are any kind of racism. Do you mean to blame me for describing the truth of the world, that an extremely disproportionate amount of people from the 3rd world are pieces of shit? Of course, it is the fault of Satan44 and not of the people themselves for committing whatever actions that they commit. Dare he not speak the truth of the world.
I understand freedom of speech and all that, but is this kind of commentary acceptable? Especially since it's clearly off-topic on a technical forum.

Freedom of speech ends where the "freedom" of others begins.

Yes, you can ignore this user (and turn a blind eye) to avoid seeing their unfriendly posts, but other users and forum guests will see it. Why would users interested in bitcoin need this shit?


Quote from: lovesmayfamilis on August 02, 2026, 09:33:14 AM
Sometimes we have to choose how to respond to insults. If you're not the person they're writing about in trust, then just move on, but by yelling, you're putting yourself on the same level as such people. The OP, having raised the topic, also talks about himself, showing his character, which sometimes reminds me of a trader at the market, who starts a fight every time he sees someone who has slightly offended him.
Normal people don't squat down and bark back at a barking dog. Smiley But if people create discomfort for others, they are usually isolated. At least for a while, to "cool down" and reconsider behavior.

I wonder if Satofan44 enjoys the BTC-community's attention being directed at him? Wink



57. Post 67005768 (unedited backup) (by BlackBoss_) (scraped on Mon Aug 3 04:50:13 CEST 2026) in For nontechnical people, how are we supposes to know Trezor, Ledger, are safe:

Quote from: RoseAPT on Today at 12:01:22 AM
Based on what I’ve read, it seems non coldcard wallets are safe. But how do we know if these other mainstream wallets are safe from other exploits that we currently are not aware of?

Luckily, I do not have a coldcard. But I am not sleeping easy right now with my setup.

Has there been real academics or non crypto related researchers (unbiased) that have published findings on the open source Trezor software?
You and most users who are not wallet developers are all unable to check things in wallet codes (even codes are open source or public for verification). We have to rely on reviews from wallet developers, security experts but developers and experts can make mistakes or bias.

But if you still want to know where to get wallet reviews, here.
https://walletscrutiny.com/
Type a wallet brand and find reviews

You have to trust wallet manufacturers, wallet reviews while bad things can still happen. Sayings are like "don't trust, verify", but because you can not verify wallets by yourself in security, you have to trust third-parties like wallet reviewers.
Quote from: LoyceV on July 31, 2026, 12:02:28 PM
At a n00b on firmware, it's shocking to read a firmware update can change such basic functionality. I guess it makes sense, without firmware no working hardware wallet, but still....

I've never owned a Coldcard, but have used hardware wallets. One of the things I dislike about them is the "black box" feeling it gives me: I have no idea what it's doing in there, and I basically have to trust the manufacturer (and some reviewers). And "trusting" is what I don't like when it comes to Bitcoin.



58. Post 67005425 (unedited backup) (by libert19) (scraped on Mon Aug 3 00:47:49 CEST 2026) in Satofan44: moron of the year 2025:

Quote from: Satofan44 on Today at 08:35:14 PM
Of course you should, that was the whole point of the merit system -- I sometimes use my limited merits with people who I strongly disagree with where appropriate. Meanwhile most of the senior members that would be considered here "respected" turned the merit system into a popularity contest as found on Instagram, where they merit-bomb their friends on mediocre posts but refrain from meriting someone who they don't like or whose opinion they don't like or agree with in that particular thread, even if the post is extremely substantial. Of course, such retards such as LoyceV hate it when they are called out for abusing the system especially by a new user who has better technical knowledge than 99.9% of the seniors here.  Cheesy It is the classic case of status quo corruption, but most would prefer to be silent lest they not risk their positions of power or income from signature campaigns.  Wink

Aren't you tired of dickriding yourself? As for merit distribution, I do agree that users may merit familiar faces more, but look at yourself, aren't you where you are solely due to your knowledge!?

Quote
None of the terms that I regularly use refer to any kind of "race". How about users first familiarize themselves what it actually means to be racist. 3rd world parasites, pieces of shit, pajeets, Islamic goat fuckers and so forth -- none of these are any kind of racism.

Breh, the terms you mentioned literally SCREAMS racism.

Quote
Do you mean to blame me for describing the truth of the world, that an extremely disproportionate amount of people from the 3rd world are pieces of shit? Of course, it is the fault of Satan44 and not of the people themselves for committing whatever actions that they commit. Dare he not speak the truth of the world.

People are result of circumstances (brain is fragile thing, and as such garbage environments create more garbage). Although, certainly it does not exempt one from wrong acts that one may commit.

Quote
I have great experience with these parasitic fuckers many of which need swift and legal execution (our laws are too weak).

Looks like, if you had any powers, you would have already become next Hitler.



59. Post 67005279 (unedited backup) (by ranlo) (scraped on Sun Aug 2 23:51:55 CEST 2026) in FreeBitco.in-$200 FreeBTC⭐Win Lambo🔥0.2BTC DailyJackpot🏆$32,500 Wager Contest:

Quote from: Zwei on July 28, 2026, 09:44:04 PM
Has anyone verified the PF system on FBTC by the way? Asking as some sites (cryptoplay and luckybird come to mind) have/had fake systems where the rolls were either verified server-side or just not verified at all. I haven't tested FBTC's though.
i just checked and the rolls are verifiable, they don't fake that.

but the way they implemented the system is in a way that if they wanted to, they can try give users server seeds that can't hit the big prizes, because server seeds are rotated after every roll. (the client seed rn is rotated too if you refresh the page, which is a big no no in any PF system, maybe it's bugged?)
the only way you could make their system 100% fair, is if you change your client seed after they reveal the next roll hashed server seed, which let's be real, 99.99% of users on freebitco.in don't do that.



in a normal provably fair system, the server seed gets committed and is never changed unless the player asks for it to be , which makes me believe they made it this way specifically so they can rig it. and the thing is, you can't prove or disprove they did it.

@LoyceV did some math on the free roll wins that have been shared on the forum before, and the numbers didn't add up:
Math time!
118 rolls (and correcting my mistake from 2018):
1 number pays $200 for every 4 numbers that pay $20 (I'm ignoring all rolls other than the 2 highest winners).
Expected outcome: around 23.6 times $200, and 94.4 times $20.
Reality: 2 times $200, and 116 times $20.
What are the odds of this happening?
My statistical math is rusty so I'm taking shortcuts: let's say it took 59 rolls to hit $200.
Odds of hitting $20 at the first roll: 0.8
Odds of hitting $20 in the first 2 rolls: 0.82=0.64
....
Odds of hitting $20 in the first 58 rolls: 0.858=0.00000239452. That's 0.000239% chance. Note that I ignored the other half of the counted rolls.
So, and correct me if my math is wrong: this doesn't have a 5% chance of happening, it's 20,000 times less! And this is exactly what I meant when I said the bad signs were there, but were massively ignored. The odds of this happening twice in a row are several orders of magnitude lower. Count the rest of the topic, and you'll see this pattern continues.

Thanks for that. This makes a lot of sense. I was still new when I started there long ago and kept running into very rare statistical abnormalities but didn't know nearly as much about this stuff as I do now. For example, at 2x my longest loss streaks there were 49x, 48x, 48x, 47x. The 49x has a 1 in 130 trillion chance on its own. I also had 32 loss streaks twice in one day (1 in 11 billion chance) only about 5k rolls apart, which I found interesting.



60. Post 67005033 (unedited backup) (by Satofan44) (scraped on Sun Aug 2 22:35:19 CEST 2026) in Satofan44: moron of the year 2025:

Quote from: Cricktor on Today at 01:52:22 PM
I gave Satofan44 some merits for good posts that didn't include insults but were worthy and helpful in my opinion from a technical and content point of view. Not sure how many merits, apparently not enough to get listed on his BPIP profile, as I'm hesitant to merit someone who is known for his racist insults or other destructive forum habits. He's clearly capable of producing good content posts when he leaves out his rage.

The question is, can or should you merit a "good post" even when the poster is known for bad behavior? Sitting between chairs here...

I try to judge posts mostly by their content, not by the poster itself. Though, I tend to refuse to give merits to people with questionable behavior and habits who act like part- or full-time trolls. It feels wrong to me when it sticks, the accumulated merits, to the poster in the end and not only to the posted content.
Of course you should, that was the whole point of the merit system. Meanwhile most of the senior members that would be considered here "respected" turned the merit system into a popularity contest as found on Instagram, where they merit-bomb their friends on mediocre posts but refrain from meriting someone who they don't like or whose opinion they don't like in that particular thread, even if the post is extremely substantial. Of course, such retards such as LoyceV hate it when they are called out especially by a new user who has better technical knowledge than 99.9% of the seniors here.  Cheesy It is the classic case of status quo corruption, but most would prefer to be silent lest they not risk their positions of power or income from signature campaigns.  Wink

Quote from: Cricktor on Today at 01:52:22 PM
Calling out shitposters, spammers, non-declared AI vomit and fighting those who spoil and leech the forum, is one thing, another is doing it in a civilized, non-racist fashion, in my opinion.
None of the terms that I regularly use refer to any kind of "race". How about users first familiarize themselves what it actually means to be racist. 3rd world parasites, pieces of shit, pajeets, Islamic goat fuckers and so forth -- none of these are any kind of racism. Do you mean to blame me for describing the truth of the world, that an extremely disproportionate amount of people from the 3rd world are pieces of shit? Of course, it is the fault of Satan and not of the people themselves. Dare he not speak the truth of the world.