⚡️🚨 ALERT - Security researchers discover critical vulnerability (CVE-2025-27840) in ESP32 chip, used in several renowned bitcoin hardware wallets.

This vulnerability allows attackers to forge ECDSA signatures and make unauthorized transactions, according to Crypto Deep Tech.

Reply to this note

Please Login to reply.

Discussion

Remember when I told you to generate your private keys with the Bip39 word list?

If you don't understand what I just said, ask away because this is the most important aspect of Bitcoin (for you).

nostr:nevent1qqst3s9j5s6f038lv6lcgjynw04lpxwdwy5mds8cvx0v2mm83lrpmvspz4mhxue69uhhyetvv9ujuerpd46hxtnfduhsygzd0ppq29uzurflavp569g2ms4khtjwuw6f0pne80l6g69k7kukkvpsgqqqqqqsngta07

Man plug your posts into an LLM or something before posting and use it as a basic research assistant / bullshit detector. You can do better.

You’re being very hard on me. But do I really have no room for error here? I’m not a cybersecurity expert—I simply came across multiple sources confirming the vulnerability and, as usual, decided to share it with you. My intentions were good.

I know they are.

It’s ultimately up to you what you want to set your room for error- open protocol and it’s your npub.

Keep in mind everything here is reputation based, and getting caught once fear mongering (incorrectly) against Bitcoiners products among this crowd probably outweighs100 good posts.

It’s your brand, do whatever you want with it. This is my two sats. Hope it helps and I do appreciate you putting content on here (and responding).

Good luck out there.

Thank you for your advice, it's through mistakes that we learn. I'll keep this in mind for the future 🫡

Coldcard ftw yet again

Don't panic this has been already solved. There was nothing to solve actually. One company was seeking attention with publicity which in the end came out as bad publicity :)

If you want to read more about that...

https://developer.espressif.com/blog/2025/03/esp32-bluetooth-clearing-the-air/

https://nvd.nist.gov/vuln/detail/CVE-2025-27840

Thank you. Ps: I thought I had a beast on my phone 🤣

⚡️ I apologize publicly, I made a mistake here. I must not only cross-check sources but also verify their veracity in depth. It's through mistakes that we learn, I'll remember that in the future. Thank you for your understanding.

nostr:nevent1qqst3s9j5s6f038lv6lcgjynw04lpxwdwy5mds8cvx0v2mm83lrpmvspzemhxw309ucnjv3wxymrst338qhrww3hxumnwqueddd

Insane... It can be solve by an upgrade in the code? nostr:npub1jg552aulj07skd6e7y2hu0vl5g8nl5jvfw8jhn6jpjk0vjd0waksvl6n8n