Synchronice
Legendary

Activity: 1666
Merit: 1175
|
 |
Today at 12:26:22 PM |
|
This incident demonstrates that the BTC-community needs to reconsider its attitude toward hardware wallets as a completely safe and secure way to store cryptocurrencies. Nothing is perfect. And take this into account when organizing your "crypto storage". This isn't a huge hit to hardware wallets, but rather a dispelled illusion that this devices are invulnerable. This was bound to happen one day. We all relaxed, placing the burden of ensuring secure storage entirely on hardware wallet manufacturers. With financial assets, as we see, the cost of error is very high. Putting aside the emotions and "shock", what conclusions can we draw? Risk diversification. Those who didn't store all their funds on a single coldcard device were able to preserve some of their savings. Therefore, you should abandon the illusion of " one of the best if not the best" and store your assets separated across devices from different manufacturers (I hope you don't make the mistake of trusting Ledger?  ). This isn't a huge hit to hardware wallets because people easily forget and forgive. Just look at what Ledger did with its Ledger Recover service, they basically did worse than what happened to Coldcard but how did the situation change around Ledger? No negativity, people completely forgot their promise about Secure Chip. Basically, what you say right now about diversification, my conclusion is that hardware wallet should be treated as a hot wallet and we shouldn't put more coins there than we can afford to lose. Honestly, I feel a little sad and ashamed. I suggested Coldcard (along with Passport) to many people as one of the most secure Bitcoin hardware wallet and now this happened.
|
|
|
|
BlackHatCoiner
Legendary

Activity: 2100
Merit: 9981
Cross Chain Crypto Swap
|
 |
Today at 12:34:18 PM |
|
Going forward, those not ready for the challenges of doing self custody should probably just buy into ETFs. It saddens me to say that, but I believe it to be the truth. And I was wondering, how are they going to make the people forfeit their custody? Well, duh. Cyber attacks on cold storage to destroy the reputation that they are cold. A lot of people were worried that quantum computers will break bitcoin, and they couldn't imagine the AI giant would find the vulnerabilities before quantum computers arrive. People should be a lot more worried about the security of their setup, even if they didn't use Coldcard. What AI found in Coldcard can be extrapolated to everything.
|
|
|
|
m2017
Legendary

Activity: 2562
Merit: 1695
keep walking, Johnnie
|
Have you seen this news yet? https://blockonomi.com/coldcard-bitcoin-theft-hits-88-6m-as-third-attack-wave-emerges/The third wave of theft from Coldcard devices has occurred. Now, a hacker (or group of hackers) has gained access to wallets with smaller balances (approximately 0.1 BTC) and withdrew (by combining wallets into one transaction) approximately ~$13 million \ near 208 BTC (a considerable sum from wallets with small balances) to different wallets (change of tactics?). I'm surprised that after the first wave of thefts, Coldcard wallets owners didn't move their cryptoassets to other HW devices or wallets generated with the new seed phrase (after Coldcard firmware update). That's why they're now in trouble. They either weren't aware of what was happening (the first wave and the vulnerability) or ignored the possibility of a repeat theft. The hacker turned out to be quite cunning and completely cleared out BTC-wallets, gradually, in several stages (like a hungry fox that found itself in a henhouse).
|
| . .Duelbits..REWARDING, BEYOND LIMITS... | █████████████████████████ █████████████████████████ ███████████▀▀░░▀█▄░░▀████ ████████▀░░░░░░░░▀█▄░████ ███████░░░░▄▄░░▄░░░▀█████ ██████░░░░░▀▀▄██▀░░░░████ █████░░░██░▄██▀▄▄░░░█████ ████░░░░░▄██▀░░▀▀░░██████ █████▄░░▀█▀░██░░░░███████ ████░▀█▄░░░░░░░░▄████████ ████▄░░▀█▄░░▄▄███████████ █████████████████████████ █████████████████████████ | █████████████████████████ █████████████████████████ █████████▀░░▀░███████████ ████████░░░▄░█░██████████ ███████████▌▐██░█████████ ███████████░███▌▐████████ ██████████░█████░████████ ██████▀░▄░▀███▀░▄░▀██████ █████░▄▀░░░░█░▄▀░░░░█████ █████░░░░░░░█░░░░░░░█████ ██████▄░░░▄███▄░░░▄██████ █████████████████████████ █████████████████████████ | █ █ █ █ █ █ █ █ █ █ █ █ █ | |
| | █ █ █ █ █ █ █ █ █ █ █ █ █ | PLAY NOW |
|
|
|
BlackHatCoiner
Legendary

Activity: 2100
Merit: 9981
Cross Chain Crypto Swap
|
That's why they're now in trouble. They either weren't aware of what was happening (the first wave and the vulnerability) or ignored the possibility of a repeat theft. Or they were aware, but could not get access to their wallets. The purpose of a cold storage is to not be accessible at any point and time. It's August, people are in vacations. It's entirely possible that they saw the news and were in a foreign country, far away from their homes, or wherever they keep their seed phrases.
|
|
|
|
Wind_FURY
Legendary

Activity: 3724
Merit: 2208
|
 |
Today at 01:22:37 PM |
|
The ColdCard situation showed the community that Bitcoin still has a very long journey before it actually reaches mass adoption. But TODAY, we lost some users. We can't blame those people. You would probably have the same viewpoint if you lost your entire life-savings held in Bitcoin.  8 years of stacking, gone. I think it's time to move on. I believed in Bitcoin. Holding it gave me peace of mind because my country has faced several FATF sanctions. I was glad to find a kind of money that cannot be censored or debased because I just want to protect myself from the money printing and my country's weak and inflated currency comapred to the dollar. I’m 39, and I was hoping to have a good financial cushion before 50. But today, my 2 BTC were drained. Losing my Bitcoin has changed my mindset. It’s no longer about finishing the race first. At this point, I just want to finish it. But losing my BTC feels like I’m back at the starting line. I lost years of hard work and time. I thought I was secure because Cold Card was always praised as one of the best and most secure wallets. It’s open source, so anyone can verify. I’m done with Bitcoin. I’m not even sure if I still believe in it. I don’t know what the future holds for it anymore. I could have stayed with traditional investments and lived a normal life. Maybe I should have just moved everything into a Bitcoin ETF when they launched. But I don't know. It's too late to do it. To everyone who has lost their BTC, I wish you the best and good health. I hope you find the strength to start again. https://www.reddit.com/r/Bitcoin/comments/1vclm91/8_years_of_stacking_gone_i_think_its_time_to_move/
|
|
|
|
|
Bytecoiner419
|
 |
Today at 01:33:07 PM |
|
The ColdCard situation showed the community that Bitcoin still has a very long journey before it actually reaches mass adoption. But TODAY, we lost some users. We can't blame those people. You would probably have the same viewpoint if you lost your entire life-savings held in Bitcoin.  8 years of stacking, gone. I think it's time to move on. I believed in Bitcoin. Holding it gave me peace of mind because my country has faced several FATF sanctions. I was glad to find a kind of money that cannot be censored or debased because I just want to protect myself from the money printing and my country's weak and inflated currency comapred to the dollar. I’m 39, and I was hoping to have a good financial cushion before 50. But today, my 2 BTC were drained. Losing my Bitcoin has changed my mindset. It’s no longer about finishing the race first. At this point, I just want to finish it. But losing my BTC feels like I’m back at the starting line. I lost years of hard work and time. I thought I was secure because Cold Card was always praised as one of the best and most secure wallets. It’s open source, so anyone can verify. I’m done with Bitcoin. I’m not even sure if I still believe in it. I don’t know what the future holds for it anymore. I could have stayed with traditional investments and lived a normal life. Maybe I should have just moved everything into a Bitcoin ETF when they launched. But I don't know. It's too late to do it. To everyone who has lost their BTC, I wish you the best and good health. I hope you find the strength to start again. https://www.reddit.com/r/Bitcoin/comments/1vclm91/8_years_of_stacking_gone_i_think_its_time_to_move/This gets to me man. I feel for this person.
|
|
|
|
|
Catenaccio
|
 |
Today at 01:43:23 PM |
|
Apparently this draining has been happening for years to a few unsuspecung users, meaning that someone was aware of the randomness flaw since a few years ago. In 2022, a brand new Coldcard user was drained after transferring funds to it. https://www.reddit.com/r/Bitcoin/s/NJXFF7hI0aThis definitely makes it a scandal now, given that the victim was blocked for reporting this, and this could possibly see Coinkite employees getting put on trial for this. With that lost case in 2022, and this video about the same issue two years ago. https://www.youtube.com/watch?v=oj_W3xOlt6UColdcard team completely ignored that terrible security issues of their hardware wallet, it's very hard to understand why they ignored that risk. I see they can be blind and terrible with coding, did not realize it but if there are people from developers in community to users reporting such security issues, it would be time for them to sit down, analyze it and realize their mistakes and fix them years ago. These things make me have my own conspiracy theory like "Does Coldcard team stay behind this massive wallet drain?" Like yogg.My Cold Keys Just Got Swiped! All Cold Kuntz!!Methods can be different but did they all plan these things?
|
|
|
|
|
|
| R |
▀▀▀▀▀▀▀██████▄▄ ████████████████ ▀▀▀▀█████▀▀▀█████ ████████▌███▐████ ▄▄▄▄█████▄▄▄█████ ████████████████ ▄▄▄▄▄▄▄██████▀▀ | LLBIT | | | 4,000+ GAMES███████████████████ ██████████▀▄▀▀▀████ ████████▀▄▀██░░░███ ██████▀▄███▄▀█▄▄▄██ ███▀▀▀▀▀▀█▀▀▀▀▀▀███ ██░░░░░░░░█░░░░░░██ ██▄░░░░░░░█░░░░░▄██ ███▄░░░░▄█▄▄▄▄▄████ ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀ | █████████ ▀████████ ░░▀██████ ░░░░▀████ ░░░░░░███ ▄░░░░░███ ▀█▄▄▄████ ░░▀▀█████ ▀▀▀▀▀▀▀▀▀ | █████████ ░░░▀▀████ ██▄▄▀░███ █░░█▄░░██ ░████▀▀██ █░░█▀░░██ ██▀▀▄░███ ░░░▄▄████ ▀▀▀▀▀▀▀▀▀ |
| | | | | | | | | ▄▄████▄▄ ▀█▀▄▀▀▄▀█▀ ▄▄░░▄█░██░█▄░░▄▄ ▄▄█░▄▀█░▀█▄▄█▀░█▀▄░█▄▄ ▀▄█░███▄█▄▄█▄███░█▄▀ ▀▀█░░░▄▄▄▄░░░█▀▀ █░░██████░░█ █░░░░▀▀░░░░█ █▀▄▀▄▀▄▀▄▀▄█ ▄░█████▀▀█████░▄ ▄███████░██░███████▄ ▀▀██████▄▄██████▀▀ ▀▀████████▀▀ | . ▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄ ░▀▄░▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄░▄▀ ███▀▄▀█████████████████▀▄▀ █████▀▄░▄▄▄▄▄███░▄▄▄▄▄▄▀ ███████▀▄▀██████░█▄▄▄▄▄▄▄▄ █████████▀▄▄░███▄▄▄▄▄▄░▄▀ ████████████░███████▀▄▀ ████████████░██▀▄▄▄▄▀ ████████████░▀▄▀ ████████████▄▀ ███████████▀ | ▄▄███████▄▄ ▄████▀▀▀▀▀▀▀████▄ ▄███▀▄▄███████▄▄▀███▄ ▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄ ▄██▀▄███░░░▀████░███▄▀██▄ ███░████░░░░░▀██░████░███ ███░████░█▄░░░░▀░████░███ ███░████░███▄░░░░████░███ ▀██▄▀███░█████▄░░███▀▄██▀ ▀██▄▀█▄▄▄██████▄██▀▄██▀ ▀███▄▀▀███████▀▀▄███▀ ▀████▄▄▄▄▄▄▄████▀ ▀▀███████▀▀ | | OFFICIAL PARTNERSHIP SOUTHAMPTON FC FAZE CLAN SSC NAPOLI |
|
|
|
cAPSLOCK
Legendary
Online
Activity: 4452
Merit: 8045
|
 |
Today at 01:51:12 PM |
|
It may be worth noting if you have a coldcard and you have updated the firmware to the latest patched version, there have been reports that the device is being bricked by errors in the new firmware. I have seen one that I own, turn itself off in the middle of various menu navigation twice. I'm leaving it off for now. https://x.com/i/status/2083633778572787862Whee. 
|
|
|
|
|
Karl_3000
Full Member
 

Activity: 364
Merit: 187
Bitcoin can not fail you
|
 |
Today at 02:06:32 PM |
|
It may be worth noting if you have a coldcard and you have updated the firmware to the latest patched version, there have been reports that the device is being bricked by errors in the new firmware. I have seen one that I own, turn itself off in the middle of various menu navigation twice. I'm leaving it off for now. https://x.com/i/status/2083633778572787862Whee. Anyone that has the wallet but not affected should transfer all his coin from that wallet to another wallet entirely and the person should not use the wallet again. Those that were affected can keep the wallet in case the hacker is later known and arrested. It can make their legal coin recovery faster. But for new coins they should also stop using the wallet. There are open sorice wallets that can be used.
|
|
|
|
BobbysTransactions
Jr. Member

Activity: 46
Merit: 21
|
 |
Today at 02:07:32 PM |
|
https://wizardsardine.com/blog/coldcard-rng-vulnerability/The safeguard that was supposed to be working The libngu developers had anticipated this scenario. They had added a compile-time check, meant to refuse to build the firmware if the hardware TRNG was unavailable:
# ifndef MICROPY_HW_ENABLE_RNG # error "get a HW TRNG plz" # endif
Unfortunately, #ifndef tests whether the macro exists, not whether it is true. And it does exist, with the value 0. So the check passed without a word, on every single build, for more than 5 years. One character stood between that safeguard and its purpose: #if instead of #ifndef.
Can a developer explain to me how you could get those if ("ifndef" in lieu of "if") statements wrong? Is in not unreasonable to suspect an inside job, given what we know?
|
|
|
|
|
NotATether
Legendary

Activity: 2408
Merit: 10045
┻┻ ︵㇏(°□°㇏)
|
 |
Today at 02:22:25 PM |
|
Can a developer explain to me how you could get those if ("ifndef" in lieu of "if") statements wrong?
Is in not unreasonable to suspect an inside job, given what we know?
Basically in C you can #define a macro and set it a value there like a number or something (1 and 0 are common) or leave it blank (null). So then #if tests whether the macro is defined and has a value that is not null and meets some condition e.g. #if FOO_BAR == 0, while #ifndef tests if the macro is not defined at all, meaning null macros fail this test. (So both #define FOO_BAR and #define FOO_BAR 0 followed by #ifndef FOO_BAR fail the condition) The coldcard developer used #ifndef MICROPY_HW_ENABLE_RNG, meaning the value of the macro was ignored and only it's non-existence (i.e. #define or by passing -D to the command line args of the compiler) was tested.
|
|
|
|
philipma1957
Legendary
Online
Activity: 4928
Merit: 12309
'The right to privacy matters'
|
 |
Today at 02:23:10 PM |
|
Won't be easy for the thieves to spend the stolen coins. Will take a lot of mixing.
Spending the coins may not be their goal. Hurting BTC may be the goal. Just think If ledger and their recovery system is going to be cracked in a few weeks by the same guy.
|
|
|
|
|
suzanne5223
|
 |
Today at 02:29:01 PM |
|
Apparently this draining has been happening for years to a few unsuspecung users, meaning that someone was aware of the randomness flaw since a few years ago. In 2022, a brand new Coldcard user was drained after transferring funds to it. https://www.reddit.com/r/Bitcoin/s/NJXFF7hI0a [snip] This definitely makes it a scandal now, given that the victim was blocked for reporting this, and this could possibly see Coinkite employees getting put on trial for this. After so many years, the issue was reported to the Coldcard team did not address it and left it unresolved? That's an act of irresponsibility. Since this is the case, then people who are using the wallet addresses using the entropy of Libbitcoin bx seed, Trust Wallet, and Lubian.com, which was said to have led to the exposure of over 220,000 BTC wallets, should also move their coins, or else the same thing as Coldcard will repeat itself.
|
| Kings Game | 🎰 🎲 ⚽ | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | ████████████████████████████
████████████████████████████ | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | ████████████████████████████
| ..500%.. | WELCOME BONUS + 250 FREE SPINS |
████████████████████████████ | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | WIN NOW |
|
|
|
BobbysTransactions
Jr. Member

Activity: 46
Merit: 21
|
The coldcard developer used #ifndef MICROPY_HW_ENABLE_RNG, meaning the value of the macro was ignored and only it's non-existence (i.e. #define or by passing -D to the command line args of the compiler) was tested.
Yes, but is this a credible error? Why would the developer think "let me use #ifndef rather than #if"?
|
|
|
|
|
BobbysTransactions
Jr. Member

Activity: 46
Merit: 21
|
 |
Today at 03:03:06 PM |
|
The COLDCARD source code has always been open and publicly available, so we have to assume that someone used AI to review previous versions of our firmware and stumbled upon this issue. A few weeks ago, we used one of the best available AI models to review our code for security issues, and it did not find this bug or anything serious.
Both attackers and defenders have the same AI tools, but today it did not help us, and only helped the bad guys.
Sorry, but we shouldn't assume anything. A rogue employee has to be a considered posibility until proven otherwise.
|
|
|
|
|
NotATether
Legendary

Activity: 2408
Merit: 10045
┻┻ ︵㇏(°□°㇏)
|
 |
Today at 03:49:50 PM |
|
Yes, but is this a credible error? Why would the developer think "let me use #ifndef rather than #if"?
I'm not sure, 95% of macro conditions are #ifndef (mainly for defining header files like #ifndef _STDLIB_H), but #if is also sometimes used for more complex situations.
|
|
|
|
YOSHIE
Legendary

Activity: 2912
Merit: 1909
Leading Crypto Sports Betting & Casino Platform
|
 |
Today at 03:57:53 PM |
|
After so many years, the issue was reported to the Coldcard team did not address it and left it unresolved? That's an act of irresponsibility.
As far as I know, in the case of the Coldcard breach which drained users of millions of dollars/thousands of lost Bitcoins, due to the theft incident that occurred, as far as I know, Coinkite has already released a warning to the victims, although at this time there is no clear solution for compensation or recovering stolen Bitcoins, what I know is that the company cannot be held responsible for this disaster, they say Bitcoin assets are completely in the hands of self-custody users. They know that this decision is indeed difficult and many of the victims are emotional and upset, but what else can I say, for that reason, none of the parties or Coinkite employees can make a decision or take responsibility in this case, They are aware that this decision could make it doubtful for users to use their Bitcoin Wallet in the future, because of the theft incident against Coldcard, they not only suffered losses, but their reputation was also at stake, it was indeed a bitter decision that Coldcard had to swallow.
|
| ..Stake.com.. | | | ▄████████████████████████████████████▄ ██ ▄▄▄▄▄▄▄▄▄▄ ▄▄▄▄▄▄▄▄▄▄ ██ ▄████▄ ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██ ██████ ██ ██████████ ██ ██ ██████████ ██ ▀██▀ ██ ██ ██ ██████ ██ ██ ██ ██ ██ ██ ██████ ██ █████ ███ ██████ ██ ████▄ ██ ██ █████ ███ ████ ████ █████ ███ ████████ ██ ████ ████ ██████████ ████ ████ ████▀ ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██ ██ ▀▀▀▀▀▀▀▀▀▀ ██ ▀█████████▀ ▄████████████▄ ▀█████████▀ ▄▄▄▄▄▄▄▄▄▄▄▄███ ██ ██ ███▄▄▄▄▄▄▄▄▄▄▄▄ ██████████████████████████████████████████ | | | | | | ▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄ █ ▄▀▄ █▀▀█▀▄▄ █ █▀█ █ ▐ ▐▌ █ ▄██▄ █ ▌ █ █ ▄██████▄ █ ▌ ▐▌ █ ██████████ █ ▐ █ █ ▐██████████▌ █ ▐ ▐▌ █ ▀▀██████▀▀ █ ▌ █ █ ▄▄▄██▄▄▄ █ ▌▐▌ █ █▐ █ █ █▐▐▌ █ █▐█ ▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█ | | | | | | ▄▄█████████▄▄ ▄██▀▀▀▀█████▀▀▀▀██▄ ▄█▀ ▐█▌ ▀█▄ ██ ▐█▌ ██ ████▄ ▄█████▄ ▄████ ████████▄███████████▄████████ ███▀ █████████████ ▀███ ██ ███████████ ██ ▀█▄ █████████ ▄█▀ ▀█▄ ▄██▀▀▀▀▀▀▀██▄ ▄▄▄█▀ ▀███████ ███████▀ ▀█████▄ ▄█████▀ ▀▀▀███▄▄▄███▀▀▀ | | | ..PLAY NOW.. |
|
|
|
|
decodx
|
 |
Today at 05:06:26 PM |
|
<...>Just look at what Ledger did with its Ledger Recover service, they basically did worse than what happened to Coldcard but how did the situation change around Ledger? No negativity, people completely forgot their promise about Secure Chip
I'm not saying Ledger didn't do some pretty shitty things, but how can you say what they did was worse than this? https://coldcard-watch.vercel.app/
|
|
|
|
|
|
YellowSwap
|
I see no reason to create a new topic about this but it looks like ColdCard is just one crappy hardware wallet company over all. They can't even fixed a firmware right for their devices. The picture below is what users are currently getting after updated to the latest firmware.  I think this is one of those reasons why you don't want to install latest firmware instantly as they are available. Always give it time because you can never tell what will happen, atleast let some other people lead the way first.  Sorry to say but ColdCard just sucks big time.
|
|
|
|
Zaguru12
Legendary

Activity: 1498
Merit: 1251
Instant Crypto Withdrawals
|
 |
Today at 05:28:23 PM |
|
The third wave of theft from Coldcard devices has occurred. Now, a hacker (or group of hackers) has gained access to wallets with smaller balances (approximately 0.1BTC) and withdrew (by combining wallets into one transaction) approximately ~$13 million \ near 208 BTC (a considerable sum from wallets with small balances) to different wallets (change of tactics?).
This exactly as predicted earlier on by Fillippone when he actually guessed that the earlier bench mark of 0.15 BTC was taken to get the highest accounts first and a new wave of attack will come for addresses with lower amounts. The most scary question now is, is this new wave of attack even done by the first hackers who probably since this flaw was announced and the vulnerabilities already exposed, wouldn’t new attackers already looking into this too and could be the ones behind this. This now leads to how many of the closed source wallets were having this vulnerabilities and were unknown, now the hackers will step up their efforts to crack the ones with vulnerabilities down and AI is definitely going to make it easy for them. That's why they're now in trouble. They either weren't aware of what was happening (the first wave and the vulnerability) or ignored the possibility of a repeat theft. Or they were aware, but could not get access to their wallets. The purpose of a cold storage is to not be accessible at any point and time. It's August, people are in vacations. It's entirely possible that they saw the news and were in a foreign country, far away from their homes, or wherever they keep their seed phrases. Or better still what if the seed phrases were thought to be lost permanently already, we usually use to discuss this when discussion of permanently lost bitcoin are happening and lost of seed phrases are actually been talked about. Now vulnerabilities like this actually gives this bitcoins the ability to be brought back into the market again
|
|
|
|
|