QR codes were supposedly a security risk until NVK incorpora...

Momo

npub1heqkxm37d5h7n8sx2gqdez5sxnu39qrylhxnnd66dxpu4e2ufyysdkkx28

hex

26b687efe2c68c11a668fa20bd6790a6a865ad7f020db925fc49c9c06c0b7066

nevent

nevent1qqszdd58al3vdrq35e505g9av7g2d2r944lsyrdeyh7ynjwqds9hqesprpmhxue69uhhyetvv9ujuem4d36kwatvw5hx6mm9qgstustrdclx6tlfncr9yqxu32grf7gjspj0mnfekadxnq72u4wyjzgwctjgc

Kind-1 (TextNote)

2026-07-31T15:11:57Z

QR codes were supposedly a security risk until NVK incorporated them into his own Coldcard Q.

USB cables were supposedly a security risk too and he never missed a chance to mock Ledger over them. (This "issue" he kept raising had a very simple solution, but if you only listened to him unchallenged, you'd never have heard about it.)

He poked fun at nostr:nprofile1qyvhwumn8ghj7urjv4kkjatd9ec8y6tdv9kzumn9wshsz9nhwden5te0wfjkccte9ec8y6tdv9kzumn9wsqzpy3fg4melylapvm4nug40c7elgs08lfycju09084yr9v7ey67amd8gg8xl Jade for using the marketing term "virtual secure elements", yet having two secure elements did nothing when his product failed to generate enough entropy.

He mocked nostr:nprofile1qyx8wumn8ghj7cnjvghxjmcpz4mhxue69uhk2er9dchxummnw3ezumrpdejqqg8je9kf0ajpnffclpx087njugv5vp0psjqfdeh9zuxvukmk0xw5qqpfw6hy for using a general-purpose Raspberry Pi and made a huge deal about being able to extract the seed if you were close enough to the device using radio extraction techniques. Yet he made such a blunder that you didn't even have to be anywhere near his devices to compromise them.

I'm mad! I'm still waiting to hear from a friend who had a single-sig on MK4. I hope his funds are safe or at least he transferred any serious amount to his Cold Card.

原始 JSON

{
  "kind": 1,
  "id": "26b687efe2c68c11a668fa20bd6790a6a865ad7f020db925fc49c9c06c0b7066",
  "pubkey": "be41636e3e6d2fe99e065200dc8a9034f9128064fdcd39b75a6983cae55c4909",
  "created_at": 1785510717,
  "tags": [
    [
      "p",
      "922945779f93fd0b3759f1157e3d9fa20f3fd24c4b8f2bcf520cacf649af776d",
      "wss://premium.primal.net/",
      "mention"
    ],
    [
      "p",
      "f2c96c97f6419a538f84cf3fa72e2194605e1848096e6e5170cce5b76799d400",
      "wss://brb.io",
      "mention"
    ],
    [
      "r",
      "wss://nwc.primal.net/ndkioamgdtksfdtzy6zzu83esd7qui"
    ],
    [
      "r",
      "wss://relay.mosvault.online/"
    ],
    [
      "r",
      "wss://nos.lol/"
    ],
    [
      "r",
      "wss://eden.nostr.land/"
    ],
    [
      "r",
      "wss://nostr.bitcoiner.social/"
    ],
    [
      "r",
      "wss://nostr.wine/"
    ],
    [
      "client",
      "Primal Web"
    ]
  ],
  "content": "QR codes were supposedly a security risk until NVK incorporated them into his own Coldcard Q.\n\nUSB cables were supposedly a security risk too and he never missed a chance to mock Ledger over them. (This \"issue\" he kept raising had a very simple solution, but if you only listened to him unchallenged, you'd never have heard about it.)\n\nHe poked fun at nostr:nprofile1qyvhwumn8ghj7urjv4kkjatd9ec8y6tdv9kzumn9wshsz9nhwden5te0wfjkccte9ec8y6tdv9kzumn9wsqzpy3fg4melylapvm4nug40c7elgs08lfycju09084yr9v7ey67amd8gg8xl Jade for using the marketing term \"virtual secure elements\", yet having two secure elements did nothing when his product failed to generate enough entropy.\n\nHe mocked nostr:nprofile1qyx8wumn8ghj7cnjvghxjmcpz4mhxue69uhk2er9dchxummnw3ezumrpdejqqg8je9kf0ajpnffclpx087njugv5vp0psjqfdeh9zuxvukmk0xw5qqpfw6hy for using a general-purpose Raspberry Pi and made a huge deal about being able to extract the seed if you were close enough to the device using radio extraction techniques. Yet he made such a blunder that you didn't even have to be anywhere near his devices to compromise them.\n\nI'm mad! I'm still waiting to hear from a friend who had a single-sig on MK4. I hope his funds are safe or at least he transferred any serious amount to his Cold Card.",
  "sig": "142c8a0d5681dfe8c290edba3400ade1e7e55044df77f6c8c7f3a2df7bcf29bcac07ccef062df3dae96649ee4bf3963e2d05a7d010f8354960cd26cf91e90dba"
}