Skip to content
Archive

Post

Back to deliverables

T TrinityInsIO
Trinity Insights
@TrinityInsIO

At the root, an entropy generation flaw in Coldcard devices, introduced in March 2021. Coinkite itself puts effective entropy at about 40 bits on the most exposed models. It should have been 128. The attacker never touched a single device. Everything was recomputed offline.

· 10 Views

replies reposts likes
1 replies collected
Trinity Insights @TrinityInsIO ·

The dizzying part: this code has been public for five years. Forked, audited, reviewed. Nobody saw it. Coinkite's CEO suggests the flaw may have been surfaced by AI-assisted code review. That is his hypothesis, not an established fact. If he is right, every old public repository just changed status.

1

7 replies whose parent comment X withheld

Trinity Insights @TrinityInsIO ·

The explanation is about scale, not measurement. Every day, between 3,600 and 12,700 BTC older than one year change hands. A theft of a thousand BTC fits inside that variation without bending it. 86 million dollars: less than a fifth of an ordinary day. x.com/TrinityInsIO/status/2084…

1
Trinity Insights @TrinityInsIO ·

31 July, however, breaks pattern: 60,875 aged BTC moved, eight times the median. 1 August: 64,044. Yet the attacker took only 284 BTC on the 31st. 0.5% of the day's movement. What you see there is not the theft. It is holders getting out.

1
Trinity Insights @TrinityInsIO ·

Fees tell the same story. 5.79 BTC in total fees on the 31st, against 2.3 to 3.7 the days before. Transaction count normal, rate per kilobyte normal. Same volume, twice the spend: transactions packed with inputs. Whole wallets leaving in one go.

1
Trinity Insights @TrinityInsIO ·

What we cannot say, too. 60,875 BTC is high, but 34 days did better over two years. And measured against each vintage's own variability, the move does not clear statistical noise. The timing is striking. It is not proof.

1
Trinity Insights @TrinityInsIO ·

One last fact, little discussed: as of 1 August, the 1,367 stolen BTC had not moved. Zero sold. The attacker consolidates across eight wallets and waits. So no sell pressure. No point looking for the theft's imprint in price, it is not there either.

1
Trinity Insights @TrinityInsIO ·

What comes next plays out over weeks: a defensive migration is slow. Order a device, relearn, move. When those old coins move, standard indicators will read long term holder distribution. Cycle top, some will say. A forced migration is not a sale. We will be tracking it, vintage by vintage.

1
Trinity Insights @TrinityInsIO ·

31 July seen from our platform. Coin Days Destroyed: every coin moved counts in proportion to its age. The spike dwarfs the rest of the quarter. Trinity Insights is waitlist-only for now: trinityinsights.io/?utm_source… x.com/TrinityInsIO/status/2084…

These were collected in full; the comment they answer was not returned by X.