The smarter you are the bigger the blind spot, I see it all the time with ppl rolling their own security because they are “qualified”. This means you are a small mistake away from getting pwn. While everyone else using market solutions enjoy the economies of scale and the market beating they take.

Reply to this note

Please Login to reply.

Discussion

You're probably right, he had blinders on for this and couldn't see past his own intellect. Either way, it's super, super sad.

has luke verified this story himself?

Theres no other way for a hacker to steal bitcoin unless it was on a computer somewhere. The only other thing I can think of is some entropy weakness but that seems not as likely

I’m still shocked he wouldn’t be completely batshit paranoid like most of us are to leave that kind of exposure.

I find it telling that all the responses are very short

He is very light on details (its already stolen) = max panic impact

He @ the wrong IC3

He has not shared this info on any other platform he uses (Mastodon, Nostr)

He claims he was sick in bed, so didn't notice YESTERDAY???

He always made out he hardly had any and was pretty poor from it all. 200 bitcoin ?!? 😂

That’s the full coinjoin.

Only one of those inputs are his.

Ah ok

How do you do a coinjoin like this, with only two participants?

We're early enough with Bitcoin that almost everyone will "roll their own" solution at some point. Even the tradeoffs between single sig with shamir vs multisig have no clear winner so it's still very easy to make mistakes.

For most single sig plus passphrase will do, and they can use SeedXOR for backup

singlesig + pw is the ideal for cold storage due to simplicity. I now have a nunchuk + tapsigner setup for my day to day onchain wallet. I think this is the best setup.

That is the way. LN pocket change, BTC spending wallet, and deep cold. A few setups derisk mistakes.

It really comes down to the determination of the thief.

I would suggest it is silly to store a $3m asset in your home office, no matter what methods you use to secure it.

At some threshold you are putting more valuable things at risk (your family), than the Bitcoin.

this has been my setup for 6+ years

Seeing ppl peddling complicated shit to civilians is infuriating.

Complicated shit is just going to get people rekt.

Love the airgapping too

Keys should never touch a thing that touches the internet.

100 %

But mah yubikey

You have to generate your private and public keys (thinking about PGP) before you export to the yubi key

You can also generate them right inside the yubikey.

Easy as that!!!

note18dxh7nx03nm36ck53ng02r7frpv807yc6re6pkzvj08p0hy8guqqrf283q

Is there some alternative for generating PGP keys? (apart for a computer that will never touch internet again)

PGP keys are not a big deal, you can revoke them.

Thinking about encrypting files with you PGP keys

Can someone please explain to me the mistake he made? And what are PGP wallets. I don't understand. Thanks in advance.

Stored private keys on a computer

Online computer*

which he used for other internet activities also

I wouldn't do it on an airgapped general purpose computer either.

Why not? Curious how you’d put it

because my kid or partner would probably turn on the wifi or something. Why risk it?

Exactly

That is just dumb. That's not blinders. 😂

this is perplexing tho.

does he not know what cold storage is?

https://twitter.com/lukedashjr/status/1609661811455819776?s=46&t=h0OK6DjyBsFg-vNNWDDILw

Oh wow

I guess, but keeping everything in a hot wallet and/or secured by the same pgp key? I just don't understand a blind spot that big, but also I suppose my intellect isn't that big. Super sad regardless.

Rolling your own is almost always a bad idea.

Unless you’re fiatjaf I suppose 😂