Reddit Posts
A Tamagotchi for your crypto savings.
BigDice Mnemonic Seed Generator (llm slop, with details)
👀 Sneak peek at this year's Cryptocurrency Village badge for DEF CON 34!
DIY Jade + Camera - Low Cost Bitcoin Hardware Wallet running Blocksteam Jade Firmware (ESP32-Cam, WROVER-CAM and T-Camera-Plus)
Thoughts on buying a m5stack ESP32 and putting blockstream Jade firmware on it to run a hardware wallet?
🔵Save Seas Token 🔵 | The Eco-deflationary token | Dev dox 💯 | tech audit✅
🌊$SaveSeas🚀 | 🚨Presale today - 21:00 UTC at DxSale 💰 | Dev dox 💯 | Tech audit✅ | absolute gem💎
🌊Save Seas $SaveSeas🌊 | 🚨Pre-sale September 18 at DxSale 💰 | Is going to be the crypto project with a powerful start 🚀
🌊Save Seas $SaveSeas🌊 | 🚨Pre-sale September 18 at DxSale 💰 | Is going to be the crypto project with a powerful start 🚀
I've subtitled the famous Cardano Whiteboard video to ENG, PT and ESP to help non-native English Speakers
401X 💎 First Insurance Token!! Dev is transparent! He’s in VC RN!
How I make free crypto every month - low maintenance version
$DevilMoon || Launch Today 6 PM Utc + A.m.a || New token + Pools & Yield Farming || Big Apr
$ DevilMoon || Fairlaunch + Hellmoon's Yield Farming || The Next Level
Father Shiba $FATHERSHIBA 🐶 | 🚨Pre-sale TODAY at 22:00 UTC | Is going to be the crypto project with a powerful start 🚀
$ Hmoon prepares its great premiere, Online Store + App + yield Farmimg. Useful project in your real life.
Hellmoon🔥 [ $HMOON ] || 180K Mk || Liq locked 🔐 forever || Ownership renounced ✅ || 💎 Solid & Legit
Hellmoon🔥 [ $HMOON ] || 180K Mk || Liq locked 🔐 forever || Ownership renounced ✅ || 💎 Solid & Legit
[ $Hmoon ] || 400K Mk || Liq locked 🔐 forever || Ownership renounced ✅ || Solid & Legit || Great Marketing || Spanish Devs❤️
😈Hellmoon😈 [ $HMOON ] || 480K Mk || Liq locked 🔐 forever || Ownership renounced || x100 Potential 💎 Solid & Legit
ESP is totally on another level. Load up while u can ;)
I made a cryptocurrency ticker for Bitcoin. Helps me keep a watch on the current prices without opening any application or website. You can check the code on my github https://github.com/aniketkatkar/ESP32CryptocurrencyTicker if you wanna make it. Thinking of adding more features later
I made a cryptocurrency ticker for Bitcoin and Dogecoin. Helps me keep a watch on the current prices without opening any application or website. You can check the code on my github https://github.com/aniketkatkar/ESP32CryptocurrencyTicker if you wanna make it. Thinking of adding more features later.
🛰Elon’s SpaceStation ($ESP) 🛰 Going live on PCS in 20 Mins!
RUNE.FARM - The first NFT Diablo 2 themed hyperfarm on Binance Smart Chain
Mentions
Jade plus covers most of those except for the secure element it uses a blind oracle instead. You can DIY it as well on to a cheap ESP32 device, worth doing even if you get something else as you can build them cheap $10-50
ESP32 vulnerabilities are well known and OP's apps and software are basically just misusing those in order to do surveillance (for "expensive packages") on a large scale. I wouldn't stick that app or software into any of my devices even if they would pay me a bitcoin a day.
how long have you being in this for. Its just not that exciting lol. ESP esp when you expect it to be eventaully a lot higher
last update Dec 2020 :( https://github.com/TinyChipHub/ESP-Miner-TCH/releases/tag/v2.11.4-TCH
I've grabbed the Waveshare ESP32-P4-WIFI6-Touch-LCD-4B, 1/3 the price of coldcard, we'll see what we can make for everyone! Maybe we can source version without wireless and maybe can disable wi-fi/bt in kernel or at low level. I have also this week used hot air to pull the wireless chips from a raspi4b, I believe the wifi/bt chip on this device shows as separate from the main chip maybe I can pull it off.
Additional Vulnerability Report: Source: https://x.com/bitk0rns/status/2084774443113664618?s=20 Real risks to the network: 1. A permanent outbound beacon from your home. The device holds an always-on HTTPS connection to the configured backend (default na.blockclockmini.com). That means Coinkite (or whoever runs/compromises that backend) sees your public IP continuously, and the traffic profile fingerprints "a BlockClock lives here" to anyone observing your egress. If the backend is ever repointed via the open WebSocket, that channel becomes attacker-controlled C2 from inside your perimeter — and because it's just HTTPS outbound, your firewall lets it through by default. 2. Bitcoin-activity correlation leaking from your network. Tx broadcast and Opendime UTXO lookups go to blockstream.info over HTTPS. Content is encrypted, but the SNI and destination IP are visible to your ISP / any on-path observer, and Blockstream sees your IP paired with a specific transaction or address. This is a signal your network emits that wouldn't exist without the device. 3. Physical credential carrier. The device stores your WiFi PSK(s) in NVS-cur.cbor on its flash. A BlockClock mounted on a wall is now a physical WiFi-key exfiltration target — steal the device, recover the PSK from flash (unless it was wiped). Your network perimeter now has a $200 gadget-shaped weak point. 4. ESP32 / ESP-IDF / lwIP network-stack surface. It's a network-attached device running an older MicroPython on an older ESP-IDF (the internal source paths and tcpip_adapter/nvs strings indicate a pre-flash-encryption-default IDF). It listens on a socket and processes HTTP/WebSocket/multipart input. Any current or future lwIP/WiFi/HTTP-parsing CVE in that stack is reachable from the LAN. Contained in impact (the device has low lateral value — it mainly has your WiFi PSK, which the LAN already shares), but it's a live exploit target sitting on your segment. 5. Network-traffic fingerprint. The periodic backend fetches on a fixed cadence are a detectable signature. An attacker scanning your network can identify "BlockClock present" and target it specifically — useful reconnaissance, not a vulnerability itself.
It's an ESP32, you can probably program it to do that
not how it works. in low entropy RNG you see that some bits are correlated. in this case there are 40 bits of information and all the other bits are derivative math functions of these bits. there are plenty of RNG test tools that exist solely to detect entropy issues with random number and hash function generation. in the case of the coldcard, even if you're not looking to reverse engineer the code or look at the source or whatever, it would still be relatively easy to construct a system to test the RNG weakness, because the resulting random number (wallet address) is an output of the system. you'd load the code into an ESP32 simulator on your high power desktop and let it reboot the card a million times (simulating whatever key presses are needed to generate a new seed) and see what wallet address comes out. you'd then insert those million numbers into an entropy checker and see that entropy is not great. at this point you don't even have to hack anything, you can literally just use the million addresses you already created to start scanning actual wallets (because with a low entropy system, it's highly likely you already stumbled on some collisions).
I mean thats bad. Should have been 100% be found in testing/auditing ESP for the product they were building
This aspect stands on a spectrum. On something like a Ledger, you are given a blackbox device and a binary. You know nothing about either. It's all trust and they could be doing anything. On the other end you have Jade DIY, which runs on an off-the-shelf ESP32 chip. You can literally design your own PCB (or use a pre-existing design), get it fabricated (or even fabricate it yourself), source all components from various vendors, pretty much all of which will have no idea you're even trying to build a hardware wallet, solder all components, then you have the code that's fully open source, that you'll build yourself and then flash. Even farther on that end of the spectrum would be you building your own design from scratch. In the end a hardware wallet's most tedious job is to perform hashes. The rest is largely trivial.
Even better is DIY Jade. Both software AND hardware are fully open source. You can build one out of off-the-shelf parts, with the core being an ESP32. Even safer than Seedsigner as the codebase is much smaller and easier to audit.
With wallets that are entirely open source, you compile and flash your own firmware. A lot of vendors have what's called a reproducible build. It's a method to compile the firmware package from source to get the exact same file as they publish. You start with their code on Github, follow the build process, and end up with a file that you can then compare to their prebuilt binaries. With devices like Jade DIY and Seedsigner, you literally start with off-the-shelf hardware. An ESP32 for Jade, and a Raspberry Pi for Seedsigner. And then you flash your hardware wallet firmware on them. You can literally have anything you want running on these.
cheapest option is 2 of 3 multisig: \- iphone wallet (seed stamped into steel plate, stored at safe place A) \- USB stick with TailOS, Electrum wallet pre-installed, storage protected by passphrase (seed stamped into steel please, stored at safe place B) \- DIY Jade wallet with Liligo T-Display, just a ESP32 development board, under $10 (seed stamped into steel plate, stored at safe place C)
Yep, it is an unfortunate event, but the fundamentals do work. "Don't trust, verify" is not optional. Simpler devices with simpler codebases always were more desirable. This is why I always recommended Jade over any other wallet. That thing runs on an ESP32 and the codebase can genuinely and realistically be verified by a single individual. The wallet itself can even be self-built from off the shelf components. This is similar to how NASA takes as few chances as possible by prefering simpler tech. But past the tech, going analog has always been essential with Bitcoin. The more stuff you do by hand, the better. It's the irony of the most advanced form of money in the world. Every step that requires hashing (like deriving public addresses and signing transactions) will arguably require some form of digital processing, but mnemonic selection is not one of them, outside of the last word. My hope with this incident is that it helps people better understand the non-negotiables of self-custody.
To be honest I'm a bit surprised they run MicroPython at all. I've run it on an ESP32 in the past, and it's a fun party trick to evaluate a high-level language on something so underpowered, but it didn't seem like the kind of thing I'd even trust with my shitty IOT firmware, let alone a device for sensitive crypto applications.
TL;DR: 1. SeedSigner (Raspberry Pi based), best for air gapped multisig 2. DIY Jade (ESP32 based), multiple hardware options, can be as cheap as $10 3. Krux (RISC-V based), nice small compact case already with built in battery and camera 4. Specter (ARM based), expensive but feature rich hardware with big screen 5. PiTrezor (Raspberry Pi based), similar idea to DIY Jade but for Trezor
For ETH I use my old trusted ATECC608B with a ESP3. Not possible to get the key out nor shards out of it. Max 2 attempts and you can throw it away.. No custom firmware possible, tamper proof in any way you can think of. 0.90$ USD a piece when i bought them in a pack of 25. Cheap ESP to control the IC 2.25$. Needed about a week fot the code and about 5 USD to get it in a nice enclosure.
Made a DIY piTrezor since I already have the materials for it. Also bought a $10 TTGO ESP32 to make a DIY Jade.
That's a good point. But maybe not an apt comparison as a RPI is a SBC and the ESP is just a microcontroller. They have some overlap but typically serve different purposes. In this type of application, the ESP wins handily though.
Except if you need a good ADC. The ESP32's ADC is garbage.
So if it's besides the point, then whats the point? A 330Mh USB Asic will DESTROY an esp-32 running at 22Kh but you still want one? So it can't be hashrate. It can't be a chance at winning a btc(the 330Mh would win) Education? You'd learn more off the 330Mh also. The only "point" I can think of is learning the ESP-32 protocols and learning from Wifi Modules. Dude wants a tricycle to travel on the hiway, I show him an electric moped and he/she scoffs: "No, I'll take the tricycle on the hiway" smfh, how long have you been around?
Which sense are you using to make that determination? Sight? Smell? ESP?
So you’re saying, there should be no retribution for all of the rugpull scams in DEFI? DEFI is 99.99999999% scams and rugpulls. ESP how easy it is to initiate (and copy and paste) a SC and make it look legitimate but tweak one small thing so one can print coins to scam
DIY Bitcoin Hardware Wallet running Jade (Low Cost, Open Source ESP32 Project) https://www.youtube.com/watch?v=PeqP6oVnlIs Prosperity that comes with hard money awaits
>How many of you know how your dishwasher works? Your cars? Your computer? The internet? I dont. >I do, in great details, to the point i can build them and tune them (that includes, in a car, everything engine related including engine management, and everything suspension related. I cant do torque vectoring ESP for now though) >I know internet uses protocols and i think i can name one of them: html. It is not a protocol. HyperText Markup *Language* . http(s) is a protocol. I do agree people dont need to know how it works, just like they dont need to know how the SWIFT network operates for fiat wire transfers.
Easily the biggest bull case for moons. ESP if it becomes more accessible to trade them
ESP since they sought out to make the people whole but said fuck the shareholders
First thing would be to buy a ticket to space to realize a childhood dream. Then buy a tonne of guitars, I'm thinking a Gibson LP Custom, a custom ESP, a Skervesen 8 string, a Gibson ES 335 etc. Then pull a Threatin', buy a night in a stadium, pay people to attend my gig and put it up on YT for posterity - another childhood dream realized.