How Cake Wallet’s Broken Seed Generator Got My Bitcoin Stolen

This happened in May 2021. For years, I believed something had gone wrong during a Bitcoin-to-Monero exchange. Only now, after investigating Cake Wallet’s historical source code, analysing the blockchain transaction and checking independent vulnerability research, have I finally discovered what really happened.

On 24 May 2021, 0.02 BTC was stolen from my Cake Wallet immediately after it arrived. Cake later promised compensation, but never paid.

The evidence is clear. Cake generated my 12-word Bitcoin seed using a catastrophically insecure random-number generator. Someone reconstructed my private key, monitored my wallet and swept the deposit.

Continue reading “How Cake Wallet’s Broken Seed Generator Got My Bitcoin Stolen”

HTTPS is easy and completely free!

After watching a talk about encryption from Yan Zhu online (JSConf Budapest 2016 – Encrypt the Web For $0) I decided to try Let’s Encrypt again to enable HTTPS on a website. I used Let’s encrypt before in November 2015. At that time the Let’s Encrypt project was in private beta and required a lot of manual configuration to get things configured. But right now the tools to configure Let’s encrypt seem really really mature.

Continue reading “HTTPS is easy and completely free!”