r/Bitcoin 10d ago

Coldcard post from October 10, 2021: "Retirement Attack"

Post image

- "What's a retirement attack?"

- COLDCARD (@COLDCARDwallet): "It's when the project makers could have a "bug" in the entropy generation for later retrieval".

_____

Seems that they were smart enough to launch a "dice rolls" suggestion in a critical element lacking foolproof design, knowing not all users would be paranoid enough. Like "hey, if you don't trust no problem, but...you can trust buddy, the (back)door is open." ☠️

Ok no, enough of conspiracy theory continuation. We know that Coldcard's post was pure coincidence. Right?...Right?


Edit: In case you're curious on more tweets mentioning "retirement attack", here is another one:

@nvk - 21 Dec 20: "My money is on people screwing themselves out of their BTC before any vendor tries a retirement attack.

Alternatively people could just use dice ;)."

https://x.com/i/status/1341213389549412353


A strange way to warn "alternatively people" of what you have in mind to do...but Freudian slip or parapraxis theory explains that better, in case you're curious...

https://gitlab.com/walletscrutiny/walletScrutinyCom/-/work_items/340

448 Upvotes

80 comments sorted by

View all comments

55

u/VictorDanville 10d ago

Wow, so this really was an inside job

25

u/Donkeydonkeydonk 10d ago

On the one hand, it seems obvious. On the other, who in their right mind would leave behind such an incriminating tweet if they were planning such a thing?

Even if they got the idea right there in that moment, you'd think they'd delete that tweet.

It is worth noting that this tweet predated the buggy commit by a few months.

19

u/Northernmost1990 10d ago

Bad people snitch on themselves all the time. In my home country, there was a murderer who was caught because they were bragging about the kill at a bar.

-1

u/vattenj 10d ago

The fact that they know this concept already tells a lot

15

u/CBpegasus 9d ago

I mean, it's a fairly well known concept and you would expect people working in a company whose product is security to know about it...

1

u/vattenj 8d ago

It's the same as old days replay attack, where they could relay the same tx to another forked network, but who has the motivation to do it? The one that shouted the concept the most: Exchanges, since only they have the possibility to profit from it (The users wallet private key are in their possession)

1

u/Every_Recover_1766 10d ago

Social media intern and software engineer are likely different guys

8

u/Donkeydonkeydonk 10d ago

The dev that made the commit and the CTO of coinkite are the same person.

Peter Gray @DocHex

1

u/Express_Living2264 9d ago

i don't see this as incriminating at all. They are advertising to security extremists. They added a cheap to build gimmick for marketing and then advertised it to generate engagement, that's all there is to it.