@nnft17

Unhosted #Bitcoin Wallet Operator. Not your node, not your rules.

📍
Joined March 2021
#Haltefrist muss bleiben. :doit:
Der Referentenentwurf zur Krypto-Besteuerung liegt vor. Aber er ist noch nicht im Kabinett. Das ist das Zeitfenster. Sobald die Unionsminister ihn im Kabinett mittragen, ist die CDU/CSU-Fraktion im Bundestag gebunden an etwas, das sie seit Mai ablehnt. Deshalb ein neuer Musterbrief, diesmal nur an die CDU-Wahlkreisabgeordneten. Drei Punkte: 1.Der Entwurf ist eine Steuererhöhung. CDU und CSU haben versprochen, die Steuern nicht zu erhöhen. 2.Er bringt 2027 null Euro und 2031 350 Millionen. Der Erfüllungsaufwand steht im Entwurf überall mit „folgt". 3.Daytrader zahlen künftig 25 statt bis zu 45 Prozent. Belastet werden die langfristigen Sparer. Am Sonntag hat die CDU in Mecklenburg-Vorpommern 4,9 Prozent geholt und ist erstmals in der Geschichte der Bundesrepublik an einer Fünf-Prozent-Hürde im Land gescheitert. Wer jetzt noch gegen das eigene Versprechen Steuern erhöht, hat aus dem Ergebnis nichts gelernt. Brief anpassen, abschicken, Antwort veröffentlichen. Zwei Minuten. #Haltefrist #Bitcoin Sehr geehrte/r Frau/Herr [Name], im Juli habe ich Ihnen zur Abschaffung der Haltefrist nach § 23 EStG geschrieben. Inzwischen liegt der Referentenentwurf des Bundesfinanzministeriums vor. Er verschiebt Bitcoin in § 20 EStG und besteuert Gewinne fristenunabhängig. Der Entwurf stammt aus dem BMF und hat das Kabinett noch nicht passiert. Jetzt kostet ein Nein die Union am wenigsten. Tragen die Unionsminister ihn erst im Kabinett mit, ist Ihre Fraktion an etwas gebunden, das sie inhaltlich seit Mai ablehnt. Das ist eine Steuererhöhung. CDU und CSU sind mit dem Versprechen angetreten, die Steuern nicht zu erhöhen. Ihre Fraktion hat mehrfach erklärt, die Haltefrist sei kein Privileg, sondern Teil der Systematik privater Veräußerungsgeschäfte, die ebenso für Gold, Kunst und Oldtimer gilt. Am 20. September hat die CDU in Mecklenburg-Vorpommern 4,9 Prozent erreicht und erstmals in der Geschichte der Bundesrepublik den Einzug in einen Landtag verpasst. Ich deute dieses Ergebnis nicht. Ich stelle nur fest: Wähler merken sich, ob Zusagen halten. Der Entwurf selbst nennt für 2027 null Euro Mehreinnahmen und für 2031 350 Millionen. Der Erfüllungsaufwand steht überall mit „folgt". Vieltrader zahlen künftig 25 statt bis zu 45 Prozent, belastet werden langfristige Sparer. Zwei Fragen: 1.Setzen Sie sich dafür ein, dass dieser Entwurf das Kabinett in dieser Form nicht passiert? 2.Werden Sie im Bundestag gegen die Abschaffung der Haltefrist stimmen? Über eine Antwort bis zum [Datum] würde ich mich freuen. Ich werde sie öffentlich machen. Mit freundlichen Grüßen [Name, Anschrift, Wahlkreis]
1
59
There is currently a phishing email going around that's pretending to come from us. Please do not follow the instructions in the email! We are currently investigating.
⚠️ ACHTUNG: BITBOX-PHISHING Aktuell kursiert eine Phishing-Mail, die vorgibt, von BitBox zu stammen und vor einem angeblich fehlerhaften Random Number Generator (RNG) warnt. Diese E-Mail ist FAKE. ❌ Keine Links anklicken. ❌ Keine Dateien herunterladen. ❌ Vor allem: Niemals eure Seed Phrase auf einer Webseite eingeben. Bitte weitersagen.
73
184
40
502
73,778
No good
Liquid got got? Liquid Pegout tx 4000/4200 BTC 8db751a650ae2f12006b7e8c69a75e4df360e8afd6b9e05ae0b9fa6458a7b140 Hacker message: "we are whitehats. contact us on chain" c103de95817b43f2df635ec6f35ff126ca26a7c6d20570c4b01866b2b3e69a19
41
Heute hat das Bundeskabinett das Jahressteuergesetz auf den Weg gebracht. Die Abschaffung der #Haltefrist für #Bitcoin und Kryptowerte ist nicht drin. Das ist keine Entwarnung, aber das Zeitfenster für Lars Klingbeil schließt sich so langsam. Jetzt den örtlichen MdBs schreiben und die Petition unterschreiben! nitter.cf/f_schaeffler/status/20…
Musterbrief an Wahlkreisabgeordnete von CDU/CSU und SPD zur möglichen Abschaffung der Haltefrist bei Bitcoin: Betreff: Geplante Abschaffung der Haltefrist nach § 23 EStG – Bitte um Ihre Position Sehr geehrte/r Frau/Herr [Name], ich wende mich an Sie als Bürger/in Ihres Wahlkreises [Wahlkreis/Ort]. Anlass ist der mögliche Regierungsentwurf, mit dem die einjährige Haltefrist für private Veräußerungsgeschäfte nach § 23 EStG für Kryptowerte abgeschafft werden soll. Ich bitte Sie, diesem Vorhaben nicht zuzustimmen, und möchte Ihnen kurz begründen, warum. 1. Es geht um Vertrauensschutz. Bereits am 20. Juni 2013 hat die Bundesregierung auf eine parlamentarische Anfrage hin klargestellt, dass Bitcoin als privates Wirtschaftsgut behandelt wird und Veräußerungen unter § 23 EStG fallen – mit einjähriger Haltefrist, wie beim Verkauf von Edelmetallen. Das Bundesfinanzministerium hat diese Einordnung 2022 in einem umfassenden Schreiben bestätigt. Millionen Bürger haben auf dieser Grundlage über mehr als ein Jahrzehnt ihre Vermögensplanung ausgerichtet. Wer diese Systematik nun kippt, beschädigt das Vertrauen in die Verlässlichkeit unseres Steuerrechts – weit über das Thema Kryptowerte hinaus. 2. Es gibt ein verfassungsrechtliches Problem. Der allgemeine Gleichheitssatz (Art. 3 Abs. 1 GG) verbietet die Ungleichbehandlung wesentlich gleicher Sachverhalte. Bitcoin ist steuersystematisch wie Gold ein privates Wirtschaftsgut – keine Kapitalanlage im Sinne des § 20 EStG, denn es gibt keinen Emittenten, keinen Zins und keine Forderung. Das Bundesverfassungsgericht hat in seiner Entscheidung zur Pendlerpauschale (2008) klargestellt: Wer eine steuerrechtliche Grundentscheidung trifft, muss sie folgerichtig durchhalten. Ausnahmen bedürfen eines besonderen sachlichen Grundes – der rein fiskalische Zweck der Einnahmenerhöhung genügt ausdrücklich nicht. Eine gezielte Herauslösung von Kryptowerten aus der Systematik des § 23 EStG, während Gold, Kunst und Oldtimer dort verbleiben, wäre genau eine solche nicht folgerichtige Ausnahme. 3. Die praktischen Folgen träfen den Standort. Geschätzt 7 bis 10 Millionen Menschen in Deutschland halten Bitcoin und andere Kryptowerte – quer durch alle Alters- und Einkommensgruppen, viele davon in Ihrem Wahlkreis. Die Abschaffung der Haltefrist würde nicht die großen Vermögen treffen, die längst über Kapitalgesellschaften oder im Ausland strukturiert sind, sondern private Sparer, die langfristig und rechtstreu vorgesorgt haben. Zugleich würde Deutschland einen Standortvorteil aufgeben, den andere Länder gezielt aufbauen. Meine Bitte an Sie: Setzen Sie sich in Ihrer Fraktion dafür ein, dass die Haltefrist des § 23 EStG für Kryptowerte erhalten bleibt. Ich würde mich über eine kurze Rückmeldung freuen, wie Sie zu diesem Vorhaben stehen und wie Sie im weiteren Gesetzgebungsverfahren abzustimmen beabsichtigen. Mit freundlichen Grüßen [Vor- und Nachname] [Straße, Hausnummer] [PLZ, Ort – im Wahlkreis] [ggf. E-Mail/Telefon]
24
141
9
924
91,511
We asked an unreleased research version of Claude to take a stab at the Riemann hypothesis. It didn’t solve it, but it did make strides on a related problem: it increased the lower bound for the fraction of zeros of the Riemann zeta function that satisfy the hypothesis from 41.6% to 67.2%. anthropic.com/research/riema…
1
50
Never forget 😂🤦
A BIP110 influencer story in three parts:
2
47
The wildest thing about all this is that hardly anyone called out Coldcard’s sea of red flags, which are so obvious in hindsight: no FOSS license, no published independent audits, messy code, chaotic commit histories, and past criticism from security researchers over how the company handled vulnerability disclosures. Somehow, most of the community was blinded by the halo effect. This was a security bug in the social layer.
66
83
12
606
62,750
The last 48 hours showed Bitcoin at its best. No central authority or company . Just people around the world voluntarily organizing into what may be the largest open source IT support effort ever.
13
31
4
237
7,272
WARNING: Users are reporting that the new COLDCARD firmware upgrade is bricking some devices. Before upgrading the firmware, be sure to safely move all funds off the wallet.
Now we’re getting RNG related bug screens. This is a result of yesterday’s firmware release. DO NOT UPDATE FIRMWARE. This thing is bricked now.
78
99
54
503
180,972
The most common question I am getting right now in the fall out of the news of COLD CARD MK3, MK4, MK5 and Q having compromised entropy, is: "Rob, what would you do right now if you were in my shoes? Where would you send your bitcoin to be safe?" I will share with you my list of what I would do, but first, there is AN URGENT SECURITY ADVISORY IN THE BITCOIN ECOSYSTEM. Below is my personal assessment of the situation. If you or someone you know: Uses an MK3, MK4, MK5, or Q in a single signature OR A multi signature wallet where the cold card devices can move the funds on their own (Example, 2 cold cards and a Ledger). Please continue reading. You may be in danger. If this does not apply to you, keep on reading if you like, but you are not impacted by this issue. If you are still here, there are three identified mitigations that protect you at the moment. They are all different forms in which you may have brought your own entropy. A: DICE - This is done by either rolling dice from the start, or adding dice rolls to the generated seed phrase. At least 50 dice rolls would be my threshold at 128 bits of entropy. OR B: PASSPHRASE - You used a passphrase of sufficient entropy (128 bits). 128 Bits of entropy pass phrase examples include RANDOM combinations of the following: - 12 BIP 39 seed words. - 10 common words in the english language - 25 mixed lower case letters and numbers - 20 if you use ASCII characters Note on pass phrases: This does not include the same word 12 times, 10 words in a sentence, etc. This combinations of characters/numbers OR words should never have been seen or spoken before in the total sum of all human knowledge and experiences. It needs to be RANDOM for it to be entropy. OR C: EXTERNAL ENTROPY - Your seed phrase was derived entirely outside of the cold card ecosystem. (It was imported into the cold card, not generated on it) Now, if you are still reading, and you do not have any of these mitigations in place, you need to move your funds. The urgency of circumstances are as follows: TIER 1: AS SOON AS POSSIBLE Scenario A: If you are in a signature wallet with an effected device, and did not use any of the mitigations listed above. You need to move funds right now. Find someone to help you, any moment your funds can be stolen. Scenario B: If you have an N of N (eg 2 of 2, 3 of 3, etc) multisig of just cold card devices that did not have mitigations listed above (dice and/or passphrase). Attackers will be grinding all of the combinations of compromised keys. They know all your seed phrases. You are compromised. It is just a matter of time for them to assemble the puzzle pieces together and steal your funds. If this scenario is you, I will have more below on how to mitigate risk when broadcasting your transaction. TIER 2: URGENTLY If you are in a single signature wallet with an effected device, and you used either less than 50 dice rolls OR a pass phrase less secure than what I shared above. The entire security of your bitcoin is reliant on how much of Dice AND Passphrases you applied to your wallet. Attackers know your seed phrase. Your entropy from dice or pass phrase is the only thing protecting you. Did you add a pass phrase of 'bitcoin'? You are basically in tier 1. Did you use 6 words? You are not at tier 1, but you aren't safe. You need to make plans to move funds quickly. TIER 3 SOON, BUT IMPORTANT CONTEXT: You have a multi signature wallet where the compromised devices have sufficient ability to move the funds. An example is a 2 of 3 multisig where you have 2 cold cards and another signer. The issue with Tier 3 is that an attacker may have already figured out your insecure seed phrases. This means when you broadcast your bitcoin transaction, an attacker in theory can then steal your funds. NOTE: IF YOU ARE IN THIS SITUATION, AND YOU HAVE REUSED ADDRESSES, ALL REUSED ADDRESSES PUT YOU RIGHT BACK AT THE TIER 1 MOVE RIGHT AWAY YOUR FUNDS ARE AT RISK AT THIS VERY MOMENT You should look into finding a way to use the @MARAFoundation_ slipstream service, which uses a private mempool. This means that by the time an attacker could see your attempted recovery, it is already in a block and not possible for them to steal funds. TIER 4: KEY ROTATION. This is where you have an insecure cold card(s) in your multisig quorum, and you know that the other keys in your quorum are not impacted by this bug. If there is a MK3,MK4,MK5 or Q in the quorum, BUT they either: 1. Rolled sufficient dice (50 min) 2. Have a strong pass phrase (as defined above). 3. Used entropy not sourced from the device, they are not impacted by this bug in the Cold Card (see notes earlier on mitigations). You are in a position where a minority of your keys are compromised. Funds are safe, but you are at reduced security. Make plans when you are able to remove the compromised device from your wallet. Now. With that security advisory out of the way, back to the question, what would I do in this situation? Below is just my opinion, but you should not rely on only my opinion, you will have to make your own choices based on what you feel is best for you. I want to be clear, if you are not on this list. It is not that I think your product/business is bad, insecure or at risk, I am directly answering the question of what I would do. This is my personal judgement given my decade of experience in bitcoin. First, a disclaimer: My bitcoin is at my company @AnchorWatch. I have full skin in the game in that if I'm offering a custody solution, there will never be another place I store large amounts of bitcoin long term for myself or my family, and it will be this way as long as I am here. I was the first bitcoin that went on our Trident Vault platform. If the day ever comes, I will be the last bitcoin to leave the platform. The years of what we built at AnchorWatch were for exactly moments like this. Avoiding catastrophic risk of ruin scenarios. We offer 2 products: 1. Our Flagship Product where you as the customer can hold 1 or 3 keys, and we act as a cosigner. We leverage bitcoin native smart contracts which allow for your bitcoin to have different ways it can be spent across time. 2. Multi Institution Custody, where we let you distribute your keys across 3 institutions of ourselves, @bitgo and @CoinCorner. 2 of the 3 institutions must sign off on the transaction, and you have to present a Yubikey signature before withdrawing to mitigate deepfake and compromised accounts. For both products as, since we are a cosigner, we are able to enforce rules like whitelisted addresses, and velocity controls (how much bitcoin can you send how often). You can even disable the send button on the platform if you so choose! We also offer 1:1 insurance backed by Lloyd's of London. If you want to learn more about what we do, hit up @_joerodgers or @BeccaAmilee to learn more, or check out our website. Now with that out of the way, places where I'd leave my bitcoin (besides @AnchorWatch) in no particular order: Custodian: I'd trust my life savings at @River under a duress situation. This is one of those times. @Leishman and the entire team at River are elite operators. It is my favorite bitcoin services business in the market today outside of my own. They own their own custody infrastructure, and at times like this, you want those who have extreme ownership and control over how their customer's money is being managed. @River does monthly proof of reserves, and you can turn on the force field feature which will freeze withdrawals of bitcoin. They have a world class custody team as well, and are making improvements regularly with a larger upgrade that has been planned for a long time, happening later this year. Collaborative Custody: 1. The @Bitkey is an incredible product with an elite team of engineers supported by the @BlockEng organization. They have exceptional bitcoin developers across @spiral_xyz and @CashApp teams who deeply understand Bitcoin. @jack has been a long time believer in bitcoin who has built an organization that has no peer in the resources they have not just understanding bitcoin, but building on bitcoin. You can pick it up a Bitkey at best buy today! I do want to add a disclaimer that all keys are managed within the Bitkey ecosystem. The Bitkey team has gone to great lengths to keep things secure, but in light of recent events, I want to call that out. At the moment, the Bitkey is my only exception to a purist ideal of multi vendor multisig (more below). 2. @CasaHODL - @Nneuman and @lopp have been on top of this incidence response, and have built a very clean user experience to let people be safe. You can either use a 2 of 3 or 3 of 5 multisig with a great mobile app. Casa is the best UX for soverign collaborative multisig that exists in the market today. 3. @uncahined - Unchained pioneered the collaborative custody model and the multi institution custody model. They have been working around the clock trying to support customers and have even been able to use slip stream going the extra mile on short notice to keep customers bitcoin safe. Self Custody: I have spent close to $5k on LLM tokens over the past 24 hours scanning over a hundred bitcoin related repositories. As of now, I have seen no vulnerability that has me concerned about any hardware device outside of the Cold Cards. Even so, you can't be sure. So I would follow the @mflaxman "Bitcoin 10x security guide". Its how I held my bitcoin before I founded @AnchorWatch, and even though the guide is 6 years old, the principles are timeless. I would remove his suggestion of using the cold card and replace it with any other hardware wallet. I would replace the cold card with a @Ledger at this time if it were my decision. You can pick up a Ledger up at Best Buy in the US. Michael pioneered multi vendor multisig as a concept, and if you want a fully sovereign solution, as of today there is no better mental model on how to think through this, he has advanced tabs to further increase the security. For his cold card guide he fairly calls out the added benefit of rolling dice, which would have saved you today. I think the future is combining the tech we use at @AnchorWatch to move beyond the single signature/ multi signature paradigm of custody, with the principles of @mflaxman's 10x security guide and the support of collaborative custody. More on that later, but I would check out @lianabitcoin from @Wizardsardine as well, they offer a fully open source wallet that enables these more advanced smart contracts and are security researchers in the bitcoin ecosystem. With that, I'm going to get back to work. I will post a followup reply if I have additional information or any corrections or clarifications to make.
156
329
53
1,460
410,977
nnft retweeted
Beware of scams! Never enter your seed (12 or 24 words) phrase into any website. Never take a seed given to you by someone else and enter it into your wallet. Never call a number given to you in an email or text. Never pick up the phone from unknown numbers. Triple check authenticity of any wallet app downloaded from an App Store. Scammers are going to capitalize on the Coldcard panic. Warn your friends who may not be technical!
1
9
1
24
2,755
Thanks to a generous credit of tokens from @PPQdotAI , Kimi K3 and an ape with a laptop (me) have conducted the following analysis of a bunch of projects / companies wallet softwares. @Coinkite , @OPENDIME , @SeedSigner , @Bitkey , @bluewalletio , @PhoenixWallet , @SparrowWallet , @Trezor , @Blockstream , @Ledger , @BitBoxSwiss , @SpecterDIY , @ElectrumWallet , @SamouraiWallet 🟡 Yellow ≠ broken. None of the nine Yellow products has a confirmed fund-loss-by-default flaw. Yellow means at least one of: (a) something security-critical sits outside independent verification. i.e., closed firmware or secure-element code (Opendime, Ledger, open source please!), vendor-run recovery infrastructure (Phoenix/ACINQ, Jade's oracle, Bitkey's WSM); (b) a real but bounded weakness, such as a zero-work-factor KDF (BlueWallet), weak legacy KDFs on a hot wallet (Electrum), no-SE DIY hardware with thin maintenance (SpecterDIY), a just-patched vulnerability awaiting its report (Bitkey); or (c) a dead/unmaintained product whose crypto reviewed clean (free Samourai!). In every case the entropy/key-generation path itself was reviewed and found sound unless the cell says otherwise.
92
186
58
777
131,840
An acquaintance of mine intentionally left a small amount of bitcoin in a ColdCard MK4 RNG created seed phrase (that was originally a "duress" wallet) to see when it might get swept. Last night it got swept to bc1qzm5pauxyv7t7vqstzpumqcn066wfjsmev34mf3. So at this point any RNG generated seedphrase on any ColdCard product is under active attack. Move quickly if you're exposed.
84
241
57
1,602
350,422
PUBLIC SERVICE ANNOUNCEMENT FOR @lianabitcoin USERS: (more info coming soon in our complete article, it's taking time to go through every possible case) If your setup is vulnerable (as in: Coldcard keys are sufficient to spend, no other key is needed to spend) ⚠️ Before transferring your funds, assess the risks. ⚠️ - If you transacted or refreshed in the past and use SEGWIT and ONLY Coldcards in your setup, transfer funds ASAP. Being too late will have your funds stolen, this is a race against the clock. - In ANY other case (Either: you never transacted nor refreshed from your wallet, OR you use taproot, OR you don't only use Coldcards) the safest option is to wait for a Slipstream tool we will provide soon. Or course if you wallet is not affected (for example your compromised Coldcard is only one key in a 2-of-3), you can transact normally.
10
25
1
86
15,002
We as bitcoiners need to do better, we failed. We failed your friends, we failed the mission. It looks embarrassing, bc it is. „Don’t trust, verify“ became a slogan, then disappeared. It needs to come back! FOSS is the way, but someone needs to read it, empowered via LLMs.
1
2
50
nnft retweeted
Technical advisory for users who created affected coldcard-only or coldcard-majority multisigs, who may be affected by the ongoing attack. Please do your own research on this. If you have a multisig of all Coldcards running Mk3 firmware 4.0.1 or later, or where the threshold amount of signer are compromised (e.g. two of the three in a 2 of 3), you need to be very careful about what comes next. If every cosigner came from an affected device (i.e. all Coldcard Mk3 4.0.1), a single past spend is enough to undo you. That means you should consider immediately moving your funds to a safer setup, because you're in a race against the clock with the attacker. If at least one of your seeds came from a healthy device, you are in much better shape, because the attacker can only use your prior spends and can only touch addresses that have been revealed in those spends. If you have never spent at all, or if you spent but the entirety of your funds moved and the change landed in a fresh address, stay calm and act in a measured fashion. The attacker cannot compute the addresses your funds are sitting at now without the healthy public key. Don't panic. If you move your funds now and publish the transaction the normal way, it sits in the public mempool first, where it hands over the public keys the attacker is missing. They can then copy it, pay a higher fee, and have theirs mined instead of yours. If you panic, you feed into their attack. So do it in the right order. Build and test the new wallet first. Then consider sweeping everything in a single transaction, so there is one moment of exposure rather than several. Ideally, do this using a direct submission service that keeps the transaction out of the public mempool, such as slipstream.mara.com. Nobody has seen the attack run against a multisig yet. But given that this attacker drained 500 wallets in three blocks, it's clear that they have prepared and practiced ahead of time. This could be the next wave.
6
23
2
85
23,695
If you have coins on a #coldcard, single sig, move them now to a different hardware wallet, different seed, ideally multi sig. This is not a drill.
1
159
nnft retweeted
I miss Andreas Antonopoulos – I hope he's doing great and I wish him the best. A true legend.
142
187
30
3,362
111,985
Glaubwürdigkeit ist in der Politik das höchste Gut. #Haltefrist @cducsubt
Klingbeil verkündet gerade: „Wir haben in der Koalition verabredet, dass wir die Besteuerung von Kryptos voranbringen.” Das heißt: Die CDU ist umgefallen. Noch im Mai schrieb die Unionsfraktion schwarz auf weiß, es bestehe „kein Anlass, an der bewährten Regelung etwas zu ändern”. Die Haltefrist sei Ausdruck eines „systematischen Gleichklangs” im Steuerrecht. Und: Eine Abschaffung sei „auch im Koalitionsvertrag nicht vereinbart”. Was stimmt nun, liebe @cducsubt? Wer 2013 im Vertrauen auf die Auskunft der Bundesregierung investiert hat (Drs. 17/14530), wer sich im Mai auf die Zusage der CDU verlassen hat – der lernt gerade: Auf dieses Wort kann man nicht bauen. Friedrich Merz wollte die Partei der Verlässlichkeit führen. Das hier ist das Gegenteil. #Bitcoin #Haltefrist
1
109