Betrayal

It never comes from the enemy.

🧡

There is this one quote about betrayal that’s been stuck at the back of my mind for a while now: “that’s the thing about betrayal. It never comes from the enemy.”

That’s why it hurts so much. If you don’t trust someone, if he (or she) is your enemy, betrayal doesn’t happen. Trust has to come first, and after that betrayal can happen.

The world runs on trust, and to a large degree it has to. You have to trust the people you interact with, you have to trust that the water is drinkable, that the food you eat isn’t poisoned, that the chair you’re going to sit down in is not made of paper, and so on. Going through the world relies on a million different trust assumptions, whether you’re conscious of them or not.

Magicians use these trust assumptions to fool you. When you see someone who is wearing glasses, for example, you trust that there are actual glasses in the frame. It’s a fine assumption to make. A magician will use this assumption to play a trick on you, and suddenly you realize that your assumption was wrong all along. You’ve been fooled. You feel surprised, and if it’s innocent enough, delighted. But you might feel stupid too, and if the magician is not a magician but a scammer, you feel stupid and angry.

Anger. That’s probably the main emotion that a lot of bitcoiners have felt in the last two weeks. Confusion and anger. And disbelief.

“Don’t trust, verify.” That’s how the slogan goes. And that’s part of the issue: it became a slogan, not a practice. (Oh my god, I’m sounding like ChatGPT now, fuck me. Maybe hodlbod was right after all.)

But here’s the issue: it’s an impossible problem. How paranoid should you be? What should you trust, and what might be compromised? The reality is that everything and everyone might be compromised. Your spouse might be an agent, your compiler might have an undetectable backdoor, someone might listen to your every conversation by measuring the vibrations of your window with a laser. There is no end to it. Your skepticism has to bottom out somewhere. If it doesn’t, your life will be indistinguishable from the life of the psychotic.

How paranoid should you be? If you get rekt, you haven’t been paranoid enough. But still, if you’ve been fine until now, it’s no guarantee that you’ve been paranoid enough, since you might get rekt at any moment.

On the other side: how trusting should you be? If you are generally trusting, you will get hurt. Betrayal, exploitation, and other ills along these lines will befall you. However, if we’re not trusting anyone or anything at all ever, we’re back at paranoid schizophrenia, which isn’t a good way to live life either.


People often ask me what wallet they should use, or similar questions of that sort. I never give a direct answer, because it always depends. What is your situation? What are you worried about? How much do you know about the thing you’re getting yourself into? Are we talking chump change, or generational wealth? Where do you live? Are you a person of interest? Are you worried about kidnapping, extortion, theft? How often do you need to access it? Are you in my position, where you need to part with your sats to eat food? Or are you just dabbling and looking for exposure?

There is no blanket answer, just like there isn’t a blanket answer for what car to get, or what house to live in, or what country to move to, or what kitchen knife to get (or what kind of gun, for that matter). It all depends.

That said, if you finally make a choice and get the thing, there are certain trust assumptions that the thing will work as advertised. You trust the manufacturer to do their job. To run certain tests, have a certain level of quality assurance, and so on.

I think that’s what a large (small?) part of the Bitcoin community is wrestling with right now. Certain trust assumptions turned out to be wrong, on multiple levels. There is a feeling of betrayal. And it hurts so much because betrayal never comes from the outside, never from the enemy. Always from within. Always from people you thought could be trusted.

It might have been a stupid mistake, but it’s a mistake that should’ve been caught, that should’ve been fixed, that should’ve never ended up in production.

It should’ve never ended up in production because entropy generation is the most critical part of any hardware wallet. Users trust that this part works, no matter how often you encourage them to roll the dice. Low entropy should be treated as a catastrophic failure mode because it is impossible to patch after the fact.

Impossible. That’s the right word to use. People were put into impossible situations because of that failure. People thought that they could sleep soundly, having all their funds in airgapped cold storage. You did everything right, so waking up one day to see that your wallet is suddenly empty is literally something that should be impossible. And yet it happened. The impossible happened.

“Don’t trust, verify.” Someone should’ve verified that the hardware RNG is used. Yes, hindsight is 20/20, but for such a critical piece of equipment… I’m flabbergasted that it wasn’t tested properly.


Where do we go from here?

I can’t help but think about the gun community, and all the lessons that had to be learned along the way. “Handle every gun as if it were loaded.” (Even though you know that it isn’t, even if you just unloaded it yourself.) “Treat every RNG as if it were compromised.” Maybe that’s the lesson. (But then, why build and use RNGs in the first place?)

And I can’t help but notice that following age-old wisdom would’ve helped to avoid catastrophic loss too: “Never put all your eggs in one basket,” and so on. “Measure twice, cut once.”


It’s been two weeks now. The adrenaline is slowly but surely leaving my body. The damage is done. (Psychological damage; I am aware that the financial damage is ongoing.)

I keep wondering what we’ll learn from this. I don’t think that the lesson should be “don’t trust anyone or anything ever again,” although I think it will be something close to that.

There’s a rule in the backup world that’s called “3-2-1.” It means that you keep three copies of your data on two different types of storage, with one copy stored off-site. There is a lot of experience (a lot of wisdom) embedded in this rule. Lots of lessons learned the hard way. It’s a good rule, because it is not overly paranoid. It is paranoid enough. It’s “3-2-1” not “7-6-5-4-3-2-1”.

I guess we’ll land on something similar. Secure enough. Paranoid enough. Trusting some things, like our own two eyes, looking at the dice we rolled or the coins we flipped. The paper we just wrote on, or the steel we just stamped. What can fail us, and what shouldn’t? What is trustworthy? Who or what can betray us?

That’s the question, isn’t it. Who can betray us. Who or what can rug-pull us? It’s everyone and everything, including ourselves.

Trade-offs. All the way down.


🧡

Found this valuable? Don't have sats to spare? Consider sharing it, translating it, or remixing it.
Confused? Learn more about the V4V concept.