Reddit Posts
Free Crypto Trading Research Tool (Works Better Than Paid Alternatives IMO)
Retail is panicking over Bitcoin, but the whale and dark pool data shows massive accumulation.
ZEC related retarded headlines galore today. This is what I know after my research last 24h.
Future of BTC/ALTS, Tax requirements, Ban Lists, Wallet-Identify Exposure, Small Spending Privacy.
PyroPlay, the only way you should be streaming
The Coinbase Premium Index has flipped back above zero, ending a 40-day negative stretch and indicating that the US is currently buying BTC at rates above the global average
All these "AI trading agents" are either bad or a scam... here's what I think we should do instead.
Why hasn’t anyone else asked this question about xrp?
Solana Meme Coin PATOS will likely outperform SOL ROi
Easiest BTCPay Server Setup With Bull Bitcoin Wallet - Full Tutorial (TLDW; IMO the best way to run BTCpay)
the cycle within the cycle: a quick breakdown
Possible that this drop could actually be a bullish setup for 2026?
Bitcoin doesn't require a galaxy-brain strategy. Stop overcomplicating it.
IMO we've been in a bear market since 2022 -- and the Bull Market Starts in 2026. What do you think?
[DD] UNITY aka the Roaring Kittys Next Play
The Federal Reserve is why Americans should buy Bitcoin
What's your favorite cryptocurrency besides BTC?
Learn Sparrow Wallet in this short 15 min tutorial. IMO it's the best tool out there.
Get ready for the Explosion of a ticking time bomb - HTR!
Bitcoin has fallen to its lowest level in a year
IMO: China fighting to keep gold price above $4000. It’s fighting to hold the line. The roll into crypto is inevitable.
Crypto tools that actually improved my workflow vs. ones everyone just talks about
been using my xrp as collateral instead of just letting it rot
Bull Bitcoin Wallet Tutorial - I cover onchain, L2, cold storage, privacy features, recovery and a bunch more. IMO a really solid option for mobile!
Any opinions or thoughts on Salvium/$SAL 11 days post-launch?
Serious question on the original "Ideology" behind BTC and how are you dealing with it?
Market Is Crashing and Many Coins Will Die
What is spx6900 and the similarities to Bitcoin IMO
Why I don't think now is the time to "Buy the Dip"
I can’t justify buying any stock or ETF knowing that there’s a very high chance that none of them will outperform BTC in the next 10 years.
Solfart (SOLF) Token Presale on Solana | SPL | New GoMemecoin Crypto Exchange & Upcoming CEX listing on CetoEx and BankCex | 1.80 Billion Tokens Sold
How to use Miniscript with Nunchuk Wallet (TLDW; super customizable multisig - IMO great for self sovereign inheritance)
Ethereum and Bitcoin Are Gearing Up - Here's My Advice
Bitcoin Dominance Is Dropping - Here's My Advice
What do you guys suggest to buy on Redtember Sales?
Which chain has come closest to covering all major verticals?
Which chain (excluding Ethereum & Solana) has come closest to covering all major verticals?
Which chain (excluding ETH & Solana) has come closest to covering all major verticals?
Which chain (excluding ETH & Solana) has come closest to covering all major verticals?"
$GNS - DeFi native Perp DEX covering all markets
$GNS, top revenue generating DeFi native perp with massive upgrade
Stablecoins are Overtaking Visa: Here is The Latest Data
Since the last Moon ATH in March of 2024, a total of 1,237,442 Moons have been burned. Which equates to roughly 1.5% of the supply.
The only thing stopping utilising DEFI to grow my BTC stack is the fear of a hack. What are considered the better DEFI platforms?
The cheapest way to buy and sell crypto that I have found.
Just looked up some charts on low/mid caps, IMO alt season might be upon us.
POWSCHE June Analysis & What’s Ahead | Well Worth a Read
JYAI Jerry the Turtle by Matt Furie on ETH
$HUNT's AI Feature Could Be Massive, Here's Why
The GENIUS Act -- My analysis. This bill is a big deal. [What I think many people are missing.]
The strongest fundamentals within real time tested communities is the real alpha
Reversal or continuation of yesterday's bear?
Is weakness of altcoins a bad sign for bitcoin itself?
OPEN ticketing ecosystem: Partnership fully functional. Real life ticketing solution.
Does anyone follow or believe COINCODEX ?
Mainstream media channel 9 Australia coverage of ATH
I built an AI trading partner you can try for free- looking for testers
Ethereum Technical Trading Opportunities – 05/2025
MoneyGlitchFun is a game changer, and now it's about to become even better
Mentions
>A hardware wallet’s most important feature is not its seed phrase creation, it’s just a convenient feature. Sorry, I get your point, but I cannot accept the argument here. The seed generator feature was flat out dangerous and shouldn't have been there in the first place, unless of course CoinKite made sure it actually worked as intended. Normally, rolling the dice wouldn't give you anything more besides the peace of mind that making sure your seed is random, because for most people it's easier than verifying the code. It's like the radio on a car... It is a convenience feature. If I say that's a crap car because my radio stopped working, yes you could argue that's unfair, because the car does great at performing its primary functions. But IMO the argument doesn't work if the convenience feature fails in such a way that it nullifies everything else that's working properly Let's imagine the radio goes crazy, and fucks up the car's other electronics, and I die in a crash.... Would you argue it's still a good car, I could simply have left the radio off and I would still be alive ?
It's fine to question, but IMO you're thinking about it backwards. AI output imitates info articles with a structured argument, which many of us have been writing long before the LLMs mined them to learn how to write. Maybe my style is too generic, but I also suspect people are trained to think a brief "hot take" is human and anything longer and more structured is AI.
That's what I did too. In fact, I bought 2 ETF's (using diff custodians) reasoning that the biggest risk was custodial failure/hacking/user error. Now we can add gross negligence to that list. Too many black swans IMO. At some point, one is going to occur.
Here's my take on self-custody: You should have some BTC in a hardware wallet, but only a small amount (say, 10%). The important part isn't how much is there, it's that you've built it should you ever really need it. Keep another 10% on a reputable exchange, 40% in an ETF using one custodian and 40% in another ETF using a different custodian. Presto - 80% of your BTC now enjoys institutional grade security. The .20 or .25 expense ratio you pay every year is money well spent IMO. Especially if you're no programmer/cyber-whiz. We are not there yet insofar as cold wallets. BTC itself takes a LOT of self-education and a cold wallet takes even more. Unless and until there's some recourse for a mistake, hack or coding error, self-custody will remain a fringe activity. We need better tools.
having a coldcard was not overcomplicating things IMO. The risk of technology getting better / additional bugs being identified so that funds from other wallets can be stolen in some years' time is not zero I guess
IMO the biggest takeaway is don't trust *any* HWW's. It's still ok to use them but only in trustless ways. Airgap + roll your own dice.
The grind starts with a regular job. Maybe consider becoming a tradesperson (plumber, contractor, Gardener, etc) Save money, invest in diverse assets (I'm not talking about alt coins, IMO crypto as a whole should only be a fraction, less than half of your savings). The only easy path is having the luck of being born a heir, or winning the lottery (don't bother participating on it). You'll have to endure a lot, including doing lots of hard or unfulfilling work. And may still fail like most do
IMO Bitkey is for the spouse/non-technical family/friends that supports your cause. It eliminates the barrier to entry into “self-custody” and is very new-friendly. Better than the ETF, better than holding on an exchange.
There’s actually no appeal to morality, which is why it’s actually a pretty apt message IMO.
It's bad enough to be choosing anything over Bitcoin and maybe a small handful of crypto projects. Choosing USWR is like buying magic beans. You can only be mad at yourself for that one IMO.
I do still think the device itself is the best, IMO. The software was just absolute garbage. Those 2 things can both be true.
It’s already priced in IMO as if it’s not passing.
No evidence they "knew about the vuln". James O'Beirne claims he warned them of a potential risk in 2025, that they did shrug off. If he's telling the truth, that's far from the best way to act as a security-based company. But getting warning of a potential risk is far from "knowing about the vuln". Shrugging off potential risk can be simple incompetence (and belief in their own competence - kind of Dunning-Kruger maybe). Shrugging off a known vuln is maliciousness. It might change as more info is uncovered, but I still tend to think the whole thing can (and therefore should, by Hanlon's Razor) be attributed to incompetence rather than maliciousness. There are a lot of weird points in the story if we assume maliciousness IMO. The bug itself is almost too simple as a backdoor, and since it was on the public code anyone else could have found it. One might say it's for "plausible deniability" but I think that's more risk than a malicious actor is likely to take for that. Assuming incompetence does require multiple points of failures and arrogance on the part of CoinKite - but it's similar to things I've seen as a former security researcher. It can and does happen.
I own one and it is all I have ever used and know. I’m not the most technical when it comes to self custody but Bitkey makes it easy even though yes you don’t have a seed phrase. IMO the multi sig seems pretty damn safe. It’s owned by Block which owns Cash App and square. They seem to have a pretty good understanding of security with transactions over the internet.
IMO I don’t care if it dumps again and again.
Man, I'm so split on that idea regarding a lack of competitive advantage. Yes it is easy to integrate, but doing so in performative manner is less easy. I'm a non-software engineer, and I've only ever worked in systems of systems whose most significant hurdle is integration with other systems. IMO, transformation of business processes to adopt AI is in many ways as difficult as starting from scratch. IMO, you can't expect significant performance improvements from injecting AI into individual systems; the whole operation needs a paradigm shift to reap game-changing performance. If I'm at all correct in this thinking, then it is the novel adversaries that have competitive advantage. In a given sector, the big boys will be reluctant to spend the capital to transform their operations, and if they do spend the money, the implementation will be by people who "have always done it this way." The young guns don't have those intellectual barriers. I suppose this isn't fundamentally much different from what we've seen come out of silicone valley in the last couple decades. But what I think will be different will be the profitability of future silicone valley unicorns. The next Uber won't take a decade to become profitable, and the average unicorn will be building bigger, more complex products than ever before. Consider Anduril, and the kind of products their building. I didn't use AI to write or edit this comment and it was exhausting lmao.
Good grief. Ledger's hardly gone well this week, has it... Cold storage with a paper wallet is best IMO. Then you don't have to put your trust in anything other than yourself.
It's been dead in the water for so long IMO. It is kept alive by speculation and "get rich quick" investors.
While I agree about trusting RNG, having a passphrase does make it more secure, IMO. Coldcard users with passphrases are most lickely safe right now (or at least, they have more time to react).
I plan to regen, but still on the fence about the 25th word. I think there is a *ton* of misconception about the impact of this 25th word, mostly due to our inability to comprehend large numbers and how elliptic curve cryptography actually works. I also admit limited technical knowledge and having a human brain which it turns out is not capable of aligning emotion (namely fear/worry) with the facts/logic behind the size of numbers we are dealing with. I might go back and read up on previous discussions on the 25th word ([example](https://www.reddit.com/r/ledgerwallet/comments/1hsfu3w/what_are_the_pros_and_cons_of_attaching_the/), [another](https://www.reddit.com/r/ledgerwallet/comments/ku00to/what_are_the_benefits_of_using_a_25th_word/); not saying these are excellent, just examples of previous posts) from *before* all this happened. I think you will be fighting an immense bias and misinformation by asking now in a time of widespread panic. That said, 24 words vs. 25 words is just... not relevant for *private key/address security* in a cryptographic sense *at all*, provided sufficient entropy was supplied. The utility is around someone gaining access to your seed words, hardware, or software wallet as you can have multiple addresses using the same seed + various 25th words (functionally, passwords) on top. And that certainly *is* something to consider for operational security. But IMO this is *not* what everyone is motivated by when asking about the 25th word: safety from the ability to guess your key/address. Any time you see "well, we might get the same 24 words, so a 25th is just extra protection against that"... No, no, no, no. The same mathematics that let us say things like "given 256 bits of entropy, your private key cannot be cracked *in the estimated remaining lifespan of the universe*" also means "the generated 24 words will *never* collide with someone else's" [no matter how counter-intuitive this feels to our ape brains]. Thus, I would focus on whether you feel the need to obscure a "real" vs. "fake" address, how worried you are about SW/HW wallet access, how confident you are in remembering this 25th word in n years (and there's no protection to someone physically getting your backup if you include your 25th word), etc. My current leaning is I like the Seedsigner approach. It's somewhat annoying to re-input the 24 words each time, but there's no passphrase to remember and I don't even have a device to worry about, just a physical backup to know the location of. For long term cold storage, this seems appealing. Just my current thinking, which could change as I'm definitely in the "research as I rethink everything" phase!
My heart goes out to all those affected by this. They did NOTHING wrong, everything they were supposed to and still.... got vaporized. One thing missing here is this: Many of these youtube "influencers" have been pushing to invest in BTC and ONLY BTC, self-custody/cold wallets and get off exchanges. If you questioned that, you were shut down with the "not your keys, not your coins" argument. Going to need a new slogan after this. I am new to BTC and still believe in BTC, but never would I put all my eggs in one basket. Chose multiple ETF's using different custodians, then setup a cold wallet and funded it with a tiny, tiny amount. In addition to that I use a 4th exchange to keep a very small sum on. My reasoning: Blackrock, etc. employs cyber-security experts far more knowledgeable than I. The tiny expense ratio is money well spent IMO, unless you're some cyber-whiz. And no, it's not insured by FDIC/SPIC. But at least there's a chance Fidelity or whoever would make people whole, if they dropped the ball. That and the Fed can always print more $ to give to custodians/big banks (remember the great recession?) to reimburse people. Still, you can and should have low-cost index funds, gold, REIT's etc. Good rule to live by: No more than 10% in any one investment! And self-custody? It's there/built, if the world ends and I need it.
I have no idea what that means... but I would get your damn coins off that cold card asap. IMO
IMO update firmware with lots of other changes in the same PR, after some months and many more updates - move towards closed source, destroy brand value, hope no one finds it and years later warn users to update their seeds with new firmware. But yeah too little too late. I don’t think they can do anything when so many years have passed
Pretty much all it us good for IMO.
IMO Right now, the best thing you can do is use a hardware wallet with a complicated hidden wallet passphrase/extra seed word. Even a 4 character alphanumeric passphrase would be like 1.6Mx more difficult to crack than no passphrase and each additional character increases the difficulty exponentially.
Park it on an exchange OR do the homework to figure out how to self-custody properly (really not hard if you actually look into it). For most people the answer is the former (IMO of course).
It's still a feature. That was a typo on my part. You can review the guarantee here. [https://www.fidelity.com/security/customer-protection-guarantee](https://www.fidelity.com/security/customer-protection-guarantee) The lock down on the account and banning account and money transfers is the best security feature IMO. They also have multi factor authentication and biometrics. Nothing is completely fool proof. I suppose you can think of the most extreme scenarios but seems as secure as anything in the market, [https://www.fidelity.com/security/overview](https://www.fidelity.com/security/overview)
So you've done roughly a x4? From 234 usd to about 1k now? That's not enough to worry about transfering to a cold wallet IMO so you could either wait, buy more and transfer to a cold wallet or just sell if you think prices will tank soon.
Yes. We’re going to see many cycles that are different going forward. It’s still an incredibly young asset. Expecting the first 15 years of bitcoin’s life to repeat forever is not a reasonable bet IMO.
Thinking about it, passphrases are pretty stupid IMO. If an attacker coaxed the 24-word seedphrase out of you you (e.g. at gunpoint), and they find an amount of funds there, they could suspect or at least consider the possibility of the existence of a passphrase, which is often chosen to be a cryptographically weak word. They could brute-force it in a matter of hours. The passphrase would at best buy you enouth time to transfer your funds from the passphrase protected wallet to a new one, but then the attacker would be able to see those funds had been moved shortly after the attack, which could prompt a follow-up attack now they are certain you own a large amount of crypto. It probably is better to spread the funds between two wallets, a decoy one (the one you present when attacked) that holds a small amount of crypto protected by a regular 24-word seedphrase (no passphrase), and a "main stash" one you never tell anyone about, with a passphrase to protect it from low entropy vulnerabilities like the Coldcard flaw.
How is Bitcoin NOT mainstream? We have ETF’s, companies leveraging debt to buy BTC, there’s crypto ATMs basically everywhere, basically everyone knows what Bitcoin is. IMO it’s completely mainstream. Whether it’s being used is a separate conversation tho
IMO it wasn't that stupid back then. It was a bet on a boom of digital ownership, and the majority of people just wanted to make a fortune from it.
IMO much better that than dealing with seedphrases, passphrases, firmware, sending and receiving, transferring, becoming a bank, dusting, exposing, leaking, hacks, dice, etc.. If your plan is just investing and hodling then an ETF is more simplified and logical.
If it's that easy to make a psyop against BTC by actually stealing people's money, it's a psyop that's desperately needed if one actually hopes for large scale adoption. Unless one hopes for events such as this to happen to a MUCH larger number of people. IMO dsasters such as this just show that the technology and its use is still in its infancy. Criminals steal money whenever they can from whoever they can. No further conspiracies needed.
Once the value of your holdings starts to exceed 6 figures in inflation adjusted terms, paper jist becomes too fragile as a sole method, IMO. You have to punch that shit in to steel.
#2 IMO, AI is relevant but not in the way that you think. I have a feeling the CTO introduced the bug in the code by vibe-coding. Pushing code that he hasn't verified or checked, caused the bug
This is so true. IMO entrepreneurs are going to have to figure out insurance products that protect average people. Hey whomever figures this out will be the next billionaire like a digital vault or something. From a gen xer It is ironic how the computer nerds at my high school couldn't get laid and now the cool kids mow their yards Lol
But you have to hack something you initially don't know if it's there or not..... Very safe IMO
It's not obvious to me as a software engineer/IT specialist. There are major data breaches and CVEs published daily/weekly, long before AI were added to the process. Yes, AI is increasing the pace, but this could have been identified 6 months ago by the attacker and them quietly scanned/indexed wallets they could drain until they were confident to pull the trigger. Most vulnerabilities are in the wild for years before identified, so the timing isn't really suspect IMO.
They have to be scrambling right now. Lucky that it happened to a small provider before the big ones get hit. They should be in Project Glasswing, IMO.
Because it is very difficult to test on the real hardware, they added a pseudo random number generator, that could be used in emulated tests. Unfortunately that weak pseudo random number generator made it into the production firmware and was by mistake used instead of the hardware true random number generator. IMO no signing device firmware code should even have a pseudo random number generator. Not even for testing purposes.
No, it does not IMO. Hanlon Razor applies. As someone who works in IT and who worked in cybersecurity for years, mistakes like that happen constantly. It's not often that bad but from time to time it is. If it was an inside job it was a bad one - evidence of the vulnerability (or backdoor, if we accept "inside job") was public for years, since it was inserted to the code, and wasn't even that obfuscated. Just no one thought to audit that part of the code.
Of course i agree, but to a typical consumer a cold wallet is supposed to be the golden standard of safekeeping your coins. IMO most consumers should just stick to exchanges. Sucks cuz it sort of defeats the purpose, but for just an investor it makes no sense to keep your keys unless you plan to do a lot of research to protect em
It's a super risky investment. Mutual funds 75% and real estate 25% would be best for most people IMO. I could maybe see 1 to 5 percent in crypto if you could spare it but the number of people going allin with it blows my mind.
It definitely is, so long as one understands that IBIT isn’t bitcoin, and, critically, should the day come where a large number of people want to cash out their IBIT and use the proceeds to buy actual bitcoin, they might not be able to. If bitcoin ever becomes what its biggest supporters hope it does, one likely won’t, at that point in time, be able to buy bitcoin with fiat, either because fiat won’t be accepted for it, or, because the bitcoin price is rising so rapidly one will lose a lot of value in the several days it takes our banking system to allow one to move one’s own money from one institution to another. IMO, self-custody is one of those things where the day it becomes seen by most as a critical thing to have is the day the system will no longer allow people to have it. Contrary to popular belief, Coinbase or any other exchange doesn’t HAVE to let you withdraw the actual crypto that you possess their IOUs for.
My take, which everyone is welcome to disagree with, and I am certainly willing to be proven wrong, is that Bitcoin has/will fail to be adopted as a currency, and will just be traded as a commodity. I don't think it's a failure if it stays this way. Creating a digital commodity that ranks in the top world assets in less than 20 years is a huge accomplishment. BTC has great value for moving large amounts of money quickly and cheaply, but the need for outside tech for BTC to function as an every day currency, which time and time again has proven to be a weak point in crypto's security, just makes in impractical as an actual currency IMO.
Not exactly. Simply updating the firmware wouldn’t have changed anything about the compromised seeds already generated. Users would have had to sweep their wallets, generate a completely new seed, and migrate all of their coins to the new seed. So that would have been publicly acknowledging a fundamental flaw in their own security when NVK had always arrogantly claimed they were the most secure hardware wallet available. IMO it’s within the realm of possibility that they knew about this but did not want to suffer the public embarrassment of admitting it and asking all of their users for all of those years to migrate their funds to new recovery seeds. Of course it’s also possible they did not know about it, just saying it’s at least possible they did. They might have hoped that the vulnerability would never be exposed.
ALL billionaires are shady. Just the fact that they are billionaires speaks for itself. 100 million dollars yield 1 million a month on safe investments, what do they need more money for? Who is really helping society and people in need? IMO it's pathetic to stand by the side of any billionaire. Bottom line is, no matter how they got there, they don't actually give the tiniest F\*@& for society or people.
I never heard of a dice roll till this coldcard fiasco A lot of people suggested cold storage. Not your keys, not your bitcoin I then bought a trezor and followed the instructions. Stamped it onto mental and split it into 2 different locations You can call me lazy or whatever for not looking into everything along with dice rolls and the other very complicated crap. If we want this Bitcoin stuff to be serious, then we can’t have all these complex crap that scares away the layman IMO.
That's not quite right. It wasn't linked against the wrong library, they didn't use the library correctly. He absolutely intended to switch to libNgU, but they didn't take the time to understand the settings, and thus botched the implementation. Relevant quotes from their [technical post](https://blog.coinkite.com/entropy-technical-backgrounder/): > In 2021, we moved COLDCARD’s elliptic-curve operations to Bitcoin Core’s libsecp256k1, using the same implementation trusted by Bitcoin Core instead of maintaining a separate EC stack. **That required adding libNgU, an embedded MicroPython library that exposes libsecp256k1 and other Bitcoin primitives.** > The cryptographic choice was sound. **The integration was not.** During that migration, **wallet seed generation moved from ckcc.rng_bytes() to ngu.random.bytes(). That path resolved rng_get() to MicroPython’s software fallback instead of COLDCARD’s hardware RNG implementation.** > That file either builds PRNG code, or uses the STM32 hardware TRNG. Looking quickly at it, you’d think we got the TRNG version of get_rng() but in fact, **I explicitly set MICROPY_HW_ENABLE_RNG to zero, thinking we didn’t need either version, but that’s not what it does.** IMO your post reads like they shipped with `debug=True` or something. The library can generate numbers from secure chips (TRNG), but how they used it did not bring that into play, using the general PRNG from the overall chip instead. It's a minor correction, but for the amount of slightly incorrect things circulating, I think it's good to get it accurate. It's still an absolute F-up, and even more so that I suspect this was rushed due to [motivations to get out from the GPL](https://x.com/zherbert/status/2082993276324319713) to block competition. It's framed like they needed to use libsecp256k1... but I'm curious if that was actually necessary given this post. It suggests all they really wanted to do was use a more restrictive license to block others using their code. Also given pre-4.0 versions were not susceptible... begs the question yet again. If it was already functioning fine, *why* did they need to do all these changes on a tight timeline?
IMO the key takeaway from this fiasco is that multisig is superior. Bitkey has the most user friendly, big name backed, multisig setup. So bitkey is the next logical top recommendation.
IMO Trezor has been solid throughout the years
>my understanding is that if you are using multi-sig with "2 of 3" or "3 of 5", every time you need to have the multiple devices on hand You don't. That's one of the things I really like. You can have one device at home, create a transaction and sign it. Then take that PSBP (partially signed bitcoin transaction), which is just a file, to the location of the second device, and sign it again. Now it's a valid transaction and you can broadcast it. You can obviously also send the PSBT to someone else, who can then sign it if they have access to one of the keys, and send it back. Anyway, I really like that you don't have all the keys at the same place. A lot more secure IMO.
Since you had a passphrase you are good for the moment but because your original 24 could be compromised and that passphrase is the only thing keeping you safe, I’d suggest you hand roll a new set of seed words to get your new wallet and don’t depend on any RNG to provide you your 24 words. Just IMO
Great writeup and questions. Just a note that I think this is misleading: >The ring oscillators inside the Secure Element chip extract raw physical chaos from thermal fluctuations. The chip filters and concentrates this physical noise into a string of 256 ones and zeros (binary bits). This reads like hardware was the limitation and potentially implies that the Coldcard *doesn't* have a TRNG and/or use ring oscillators... but it does. [Datasheet](https://www.mouser.com/datasheet/3/282/1/ATECC608C-CryptoAuthentication-Summary-Data-Sheet-DS40002513.pdf) for the Coldcard MK3 chip, the ATECC608 [emphasis mine]: >**The ATECC608C True Random Number Generator (TRNG)** was developed in accordance with the NIST SP800-90A/B/C specifications. The DRBG and NRBG elements of the design were evaluated using a NIST certified laboratory to the procedures they have specified. [...] NIST validated and attests that the "ECC608 NRBG Entropy Source" module **complies to the SP800-90B standard with a ring oscillator-based architecture for a physical non-deterministic random bit generator module** that can be reused in product revisions of the ATECC608. Quotes from [the Coinkite writeup](https://blog.coinkite.com/entropy-technical-backgrounder/) on all of this, which illustrate the true root cause: > The cryptographic choice was sound. **The integration was not.** During that migration, wallet seed generation moved from ckcc.rng_bytes() to ngu.random.bytes(). **That path resolved rng_get() to MicroPython’s software fallback instead of COLDCARD’s hardware RNG implementation.** > The bulk of randomness on the COLDCARD was **coming from a PRNG that I didn’t know was actually in the source code base** (it is from a submodule, Micropython). At the same time the carefully crafted TRNG code I wrote was being used, but just by chance, and only for less important things. > That file either builds PRNG code, or uses the STM32 hardware TRNG. Looking quickly at it, you’d think we got the TRNG version of get_rng() but in fact, **I explicitly set MICROPY_HW_ENABLE_RNG to zero, thinking we didn’t need either version, but that’s not what it does.** Because that code provided a PRNG with the same function signature as the desired code, the build completed without identifying the wrong implementation. Collective translation: "I had a fully capable hardware tool, but did not know exactly what I was doing and thus it wasn't used." I think [this X post](https://x.com/zherbert/status/2082993276324319713) is super interesting, and IMO it reads that Coinkite rushed to swap crypto libs to prevent competition (change from GPL to other licenses) and absolutely fumbled. It seems like they chose to prioritize blocking others in the hardware wallet space vs. the proclaimed mission of utmost security. Aside: I don't have a Ledger, but looks like airgapping is not feasible from [this rundown comparison](https://www.spark.money/tools/bitcoin-hardware-wallet-comparison)? So you trade random seed generation for some amount of leak risk (and overall, would say the latter is far more likely, or at least where most users are likely to trip up somehow). This is not to defend Coldcard, nor to detract from Ledger. The point to make is to be *super, duper, duper* specific on the *exact* cause of the issue as all of this circulates. You make *excellent* overall points, I just disagree with writing up the RNG details as if this is about better vs. worse secure chips. It's not, and there are other considerations as well (entropy vs. leak risk, as one example).
IMO it would hit sub 1500 in Q4 before making any new ATH. Eitherway it's a decent price for the long run and no one knows the future. In terms of alt ETH is probably one of the only few alts that is more safe and stable compared to most.
> I’m going back to index fund, I want to be sure my money is still there in 50 years. This is quite the bold statement IMO.
AI isn’t needed for that part, IMO. That part is fairly easy once you’ve identified the flaw in the firmware. Reviewing all the firmware versions for all potential flaws, now that part is tedious and a job for AI.
Yes, *recently*: >The MicroPython fallback was introduced upstream in May 2018. It did not enter COLDCARD wallet seed generation until the libNgU migration in March 2021. The affected Mk3 firmware range is 4.0.1 through 4.1.9. Version 4.2.0 corrects new seed generation. So the issue entered the scene 2021: > ...we have to assume that someone used AI to review previous versions of our firmware and stumbled upon this issue. A few weeks ago, we used one of the best available AI models to review our code for security issues, and it did not find this bug or anything serious. The used the "best AI" *3 weeks ago* to look, but this issue is 5yrs old? A couple other troublesome comments: > The bulk of randomness on the COLDCARD was coming from a PRNG that I didn’t know was actually in the source code base (it is from a submodule, Micropython). At the same time the carefully crafted TRNG code I wrote was being used, but just by chance, and only for less important things. > Looking quickly at it, you’d think we got the TRNG version of get_rng() but in fact, I explicitly set MICROPY_HW_ENABLE_RNG to zero, thinking we didn’t need either version, but that’s not what it does. So yes, AI is great to review, but IMO this is... really, really sad/bad to read. For a device collectively hodling $millions-billions, they just winged a new crypto library implementation and "oopsie," we didn't really understand the code base and technical details of the upstream code. Also, [this X post](https://x.com/zherbert/status/2082993276324319713) is even more troubling, as it sounds like the entire motivation was to get out from under the GPL so others couldn't use their code. Thus, one has to wonder about the tension/diligence given (a) stay to your mission of providing the most secure wallet ever vs. (b) stop my pesky competitors from using my open source code. My leaning is this was rushed and motivated by blocking competition vs. "whew, take a deep f-cking breath, let's get a lot of independent eyes on this change as we get ready to replace our RNG library" (you know, one of the most core pieces of software in the entire stack).
Trezor has mishandled customer info leading to phishing attacks. I would recommend BitBox, Jade and Passport. They are the best options IMO
Not just this year. RWA gonna be a huge part of crypto from now on IMO because we are just starting to see major tokenizations happen. So much more is yet to come
IMO, this needs to be added to the main post, please. While I can't blame you for trusting the random number generator, particularly for how much they hype the Coldcard specifically for the dedicated secure chip, epoxy potting, tamper light, etc... *this* is the key takeaway: entropy matters (*not* "reproducing cryptographic methods offline is sketch", which is how your final line reads). And you won't hear it enough to make it any better, but I'm sorry this happened to you. I can't even imagine.
Aaaaal that hype is on the betting books now. Meme coins are a fairly specific target market and right now any new meme coin is a play on model nostalgia as much as it's a play on meme hype. IMO of course but, that's what I see.
I would have if I’d just stayed tf in btc from $58k to $126k. I watched it more than double, yet had to keep trying out the newest fart/shit/dog/cat coin until I ended up with less than I started with. So, I made money. I just lost slightly more than I made by the time it peaked. Best thing to do IMO, is get in the top three, btc, eth, solana, and DCA down and up, maybe a little more the if it goes lower, but stay tf in. Don’t F with any meme coins. You will always hear about someone who turned $500 into $300k, but the chance of it being you or anyone you know is up there with winning the lottery.
42% of miners signaling, this one is going to go through without much noise IMO
42% of miners signaling, this one is going to go through without much noise IMO
IMO it's not a good idea to talk to anybody about BTC especially if you do self-custody...
The thing that Apple bets on to ban competing stores / ways to install apps on Iphones is security. That only they are capable of providing it and that other ways would harm users. If that is the case then you are making the point that installing apps from your store is safe which IMO would make you liable because you are constantly making the point that your store is secure.
IMO Isn't it more likely to start losing seed phrases if you have lots of them?
IMO capital will flow to space, quantum, drones, biotech, whatever. There’s just much better targets out there.
Maybe that's a good habit. DCA is always a good habit IMO
IMO the infinite amount of money avail, makes all things that cant be printed as fast go up faster when priced against it. the stronger and more finite and valuable the thing matters, but bottom line, everything else is just noise.
There will always be a few of these, at least as long as infrastructure models for trad-fi still exist. Savvy investors will, perhaps more with crypto than with traditional equities, continue to index themselves. Unlike trying to match index PA you can group them and earn interim yields as well. https://ibb.co/v4qtJ4cd Depending on what you want to build around it. I accept some limitations to run a tax model on the side that converts yields atomically to ETH and stores them in a communal buyback contract. In this way the tokenized index gets the PA sharing action of an indexed instrument, with an additional risk/reward layer (can't ignore it) that earns yield without speculating on re-composition. Depending on your arrangements (I put some locks right now) the ability to manage to news and rapid changes in defi markets is also a plus. IMO crypto, and specifically smart chains, offer so much more usability over a traditional index ETF that it's worth the extra management even with relatively small bags. I think that in the current markets, crypto index ETFs are ok for a tradfi investor who has sufficient money to pay management fees while they sit on idle capital. More active investors will move as the space evolves and offers better opportunities.
This ETF is excellent IMO - WALT https://markets.ft.com/data/etfs/tearsheet/summary?s=WALT:SWX:USD
It sure has an interesting set of properties but I am not sure if it there is a scalable business case that could not be replicated and the lack of financial incentives is a bit worrisome, IMO.
Bitcoin isn’t an investment. IMO. S&p500 over btc. Unless you gonn slam many bitcoin investment which is risky.
Beef tallow absolutely has a distinct flavor. It does have a beef flavor but it tastes like beef tallow (rendered beef fat) it’s not going to taste like the meat. It’s going to taste like the fat. Which is very good IMO. But id reckon they use a more clarified and mass produced version with less intense flavor as to not put people off, who may not like it.
It's currently at 6 cents. If it does everything it intends to do, I think it's easily a multi-trillion dollar asset. Hedera with $1 trillion market cap is $20. But even if it only goes to $1, or $5, or $10... It's at 6 cents now. That's a 16x, 83x, or 166x on your investment. ETH is at ~$2000.... People are calling for a $10,000 ETH (I think that's wrong but we'll see). That would be a 5x on your investment. 🤷 HBAR has a far better asymmetric upside, IMO. NFA DYOR.
I’ll be that guy who actually admits regardless of charles lack of public suaveness and my incoming downvotes, I’m still all about cardano, because it’s actually scientifically approached and works. Still leagues ahead imo. Staking has rewarded very well over the years, currently not as much as bank at current price, but the core is there. Can’t beat their foundation anywhere IMO. \* Regardinf robinhood staking - yea that’s just laziness, put it into a cool stake pool doing honorable things / historically 2x+ higher than RH offering.
I've already mentioned why non-bitmain miners signaled early -- neutralize ASICBoost exchanges/wallets -- they supported segwit b/c fees were really high at that time and it was a bad customer experience. they were also on-board with Lightning scaling devs -- Less weight here. Core has changed significantly over the last 10 years. I dont think this is comparable Merchants, users and nodes -- this is not true IMO, it comes down to finding out if a minority soft fork led by node runners can successfully activate a soft fork. Its pointless to keep debating about this. I'm very interested to see how this plays out. Awesome to be alive during this time. :)
The need to protect cryptocurrency from quantum attack almays to me felt like a distant problem. The timeline is shrinking fast though IMO. If you look at the Google Quantum AI researchers that published a [whitepaper](https://arxiv.org/abs/2603.28846) with updated resource estimates for breaking secp256k1, the elliptic curve used by Btc, Eth (amongst all the other shit coins). It very much suggests that, with a future cryptographically relevant quantum computer using a superconducting architecture, attacks could require fewer than half a million qubits and execute in minutes rapidly, nearly a 20-fold reduction apparently!! If Google is taking it seriously so should most of us crypto degens. Theyve now set a 2029 timeline for its own migration to PQ Cryptog, they've been chatting about this shit recently in progressing to quantum hardware, error correction, and resource estimates. For all shitcoins and their chains, the risk is up there coz public-chain data is permanent. Addresses, sigs, and exposed pub keys may still be attacked years from now if quantum computers arrive. For us degens and the chain creators, I feel there needs to be preparation. Some projects are talking about this shit already like Nervos CKB. Crypto Agility is the key to chains surviving.
Daily weekly whatever works best for you. When the markets are down big, then increase the size (IMO) and let off in bull markets and eventually stop and get ready to DCA out
IMO Tuesday afternoon before the market closes is the best time to put your regular weekly purchase in. It is a rare moment of lesser volatility week to week. Other than that? Just buy every week.
Now it's harder to buy more, and it won't be pumping that hard in the future IMO. So the easy money stage might be over.. It's becoming more mature asset now
IMO the landscape is still rudimentary. Things may look a lot different in 10+ years. The only people I know who spend bitcoin spend it on the dark web right now.
Don't put amounts of money in crypto you are gonna be worried about or gonna need in your life in the next couple years. Crypto has been going down this year and may continue to do so for a while. Your holdings may lose quite some value as that happens. But if you believe, like many do, that crypto will see new bull runs in the future with new all time highs then that's what we are betting on. IMO SOL is a good pick with high potential to perform well if a new bull run kicks off. If you want to make this bet, i suggest you stop worrying too much about price drops and put in automatic buy orders to buy more if the price drops further. This will lower your average buying costs and increase your potential upside if the tide turns. I am personally doing the same, i already bought some SOL and have open buy orders lined up at lower levels.
I think you are underestimating how little volatility you need to do 5x leverage excluding costs of doing so. 10% move which is something quite often would be 50% drawdown on your position if against you. Leveraged strats are profitable in sub 1% of plays, just because under 1% of players are sophisticated enough to actually have an edge over the market. There is absolutely no way on earth leverage yields you a net positive without an edge over a long period of time; Short term it's just luck and there are plenty of famous crypto traders rotting bankrupted after they got lucky. IMO there is no way in the modern world you can do anything by hand apart from buy and hold, there's way too many correlated bits moving with the correlation dynamically evolving. You need a model and it has to be damn good if you wanna borrow money to make money. Or have some micro advantage on a specific market cause of something specific happening, emissions, etc, but these are limited in time.
This is a fair point. As someone who has been in crypto since Dec 2016, I do not think it is 100% fair for people to say its lack of user security. There is real exploits and real hacks that cause wallets and funds to be drained. Yes, there absolutely is some responsibility of the user for having weak security that allows an exploit to drain but there is also advanced crypto users like myself who had a wallet drained recently due to a video program I put on my computer that allowed a hacker to gain access to my pc with some of my wallets on it. The real problem is the lack of education, the greed of individuals, and crypto falling so far from reasons I entered and reasons crypto was created. Crypto IMO and why I came was to leave the fiat ponzi financial system. Self sovereignty, self custody, peer to peer transacting with no middle men. If you are storing crypto in self custody you should have a cold storage wallet that is where u keep a majority of your holdings and funds (maybe even 2 and split ur large holdings and savings between them). Should also have multiple wallets that you use for different types of trading and when connecting to dapps. If you are connecting to a dapps for the 1st time you should always use a test wallet with little funds on it just in case it is malicious. I believe crypto is the best thing for people, yet need to understand and get educated properly. The problem is getting that education as there is many different opinions on best practices and there is no large onboarding education platform. I learned everything I know through experience and learning from mistakes. Don’t let hearing people having their wallet drained scare u away from the 1 thing that can return wealth and power to the little guy. Best to start with reputable exchanges (I also don’t like exchanges or keeping my holding on exchanges), it’s how I learned. Get a feel and understanding for how blockchain works. What’s a swap, how to bridge, how to transfer to different wallets. Don’t take big risk, keep large holdings in cold storage, use multiple wallets with funds spread across so if 1 does get compromised u dont lose everything, dont have all wallets loaded on the device u use the most to surf the web where u can potentially get exploited.
This is a huge downfall of crypto IMO. As time goes on I do think this mechanism will improve substantially, but right now you are just shit out of luck. Keep looking for the physically written info
What you said sounds nice and dandy on paper. But it's more about the ways it can and would be abused IMO. Especially the bullshit reasoning behind chat controll laws. Who knows maybe it won't be abused withing 5 years. Maybe even 10 years. But I'm willing to bet that it will be abused within the year it's implemented. There have already been arrests in the US and UK over polical memes on social etc. Letting a AI government system scan every messaging app and gallery on my phone and PC sounds like a nightmare to me. And I also remember there being a case where Google flagged pictures taken by parents of their children as CP before. Although this might not be the right place to discuss this since it's a crypto sub. It's mighty suspicious that within 2 years all government bodies all of the sudden wanted full digital controll and oversight, on everything. At about the same time META and Microsoft started lobbying these laws too. And that whole child protection angle, is being pushed by a lobbying foundation shell set up and funded by META.
Im a believer in Power Law but the upper bound and middle bound are somewhat worthless IMO. But the floor is hugely important
It's been a combination of investor psychology, self-fulfilling prophecies, and coincidence IMO. If people believe in the 4 year cycle, why would they buy now and not in October? Why would they sell in Q4 three years later? As long as people broadly believe it, it's going to happen until a bigger buyer breaks the trend. On the coincidence front, if you look at the highs and lows over the last couple cycles, there were really clear signs outside of any kind of bullshit theories. Rates rising, equities dropping like a rock, FTX, war, blah blah blah. It has diverged a bit over the past 9 months and I think that's because so many got burned by leverage and derivatives. Essentially, the reason things don't get totally priced in is because of the tension between people who believe in the 4 year cycle, people who don't, and people who aren't even thinking about it. It will break eventually, and there will be a ton of angry people who get caught on the rough side of a bad trade, either waiting for a time to buy that gets bid up early, or selling too early and watching it continue going, or trying to hold and sell at the right time and watching it drop hard earlier than expected. There's no legitimate reason for a 4 year cycle. The halving is irrelevant at this point, more or less. So now it's just about how long it takes for people to stop believing in it. All it will take is one time being completely blindsided, and it will happen eventually.
Great question ! Although 2-3 x returns IMO are inevitable I also believe DOGE could 5x in that time. Bitcoin is hard to see at 300k in 4 years . DOGE has already proven it’s done it at current price levels , Bitcoin has not at 60k
If you're looking for the orange with the most possible juice, and have belief in bitcoin, haters will hate, but im holding ASST and MSTR for an amplified bet on bitcoin. That's my 2 cents. ASST is the cleaner bet IMO. no debt. 1 preferred stock giving amplification to the common. And a large possibility of huge growth since it is a much smaller treasury than MSTR. It will also be easier for it to 5-10x in bitcoin holdings over time compared to MSTR. Ultimately up to you if you truly dont care about owner and want pure amplified performance I would recommend ASST. /r/striveASST
Sure, but a person with that mentality would have likely sold at $100, $500, $1,000 etc. I'm not here to argue the intrinsic value of it. No one has ever convinced anyone to change their mind IMO. I simply play the volatility to make money.
ZachXBT is making millions on X but he is just one guy. Still, it's a role that is always needed in the space IMO. If you can do it quick and still be detail oriented there are good bounties to claim. Seems like a more profitable path to take instead of finiding a job and getting paid like 2k a month for work that is worth much more
This is a thing on a lot of wallet monitoring applications. This is a pretty simple feature. IMO this should be one of many features with customizability; addresses, tokens, amounts, contract deployment, etc.
I suspect AI will end up being "good enough" that the majority of people won't care. The cat and mouse game of AI detection will always be a thing, and there will be niche communities that adhere to it, but people (especially those who grow up with AI) won't put enough economic pressure on platforms to filter it out and we end up with 99.99% of content on the internet being AI generated. My biggest concern is that AI will have inherent biases that shape content, and we already have large swaths of the population outsourcing their thinking to AI. It's a recipe for a particularly lame type of dystopia IMO.
Used them all (except coldcard) Trezor is the best IMO And i say this as someone who used paper, and then Armory and Electrum to store coins