Bitcoin Forum
August 03, 2026, 10:31:44 PM *
News: COLDCARD users only: critical vulnerability risks funds stored on COLDCARD devices; immediate action required
 
   Home   Help Search Login Register More  
Pages: « 1 [2] 3 4 5 6 7 8 9 10 11 12 13 14 15 »  All
  Print  
Author Topic: Large-scale Coldcard compromise (1360.23 BTC stolen so far)  (Read 4151 times)
LFC_Bitcoin
Diamond Hands
Legendary
*
Offline

Activity: 4340
Merit: 13078



View Profile
July 31, 2026, 06:26:20 AM
 #21

Just reading about it on X. I didn’t think anything like this was possible, I guess it shows the importance of multisig. Good practise to divide your stash amongst various hardware wallets.

█████████████████████████
██████████████▀▄▄▄▀██████
████████▀▀▄▄████▄▄▀███
██████████████
████▀▄▄████████████
██▀██▀▀▀▀██
███▄▀▀███████
█▀███████████▄█
█▄▀▄██▀███▄████▄██
███▄█████▄▄▄████
█████▄████▄▄▄▀▀▄▄██████
███████▄▀▀▀▀▄▄▄██████████
█████████████████████████
.
 Jackpot ter .....  COMMUNITY POWERED CRYPTO CASINO  
▄███████████████████████▄
█████████████████████████
█████████████████████████
██████▄░▄▄▀██████▀▄██████
███████▄░█▄░███▀▄████████
█████████▄▀█░▀▄██████████
██████████▄▀█▄▀██████████
██████████▀▄░█▄▀█████████
████████▀▄███░██░▀███████
██████▀▄██████░▀▀░▀██████
█████████████████████████
█████████████████████████
▀███████████████████████▀
▄███████████████████████▄
█████████████████████████
█████████████████████████
███████████████▀▀░░▐█████
███████████▀▀░░░░░░██████
███████▀▀░░░▄▄▀░░░░██████
████▀░░░░░▄█▀░░░░░▐██████
██████▄▄██▀░░░░░░░▐██████
███████████▄░░░░░░███████
██████████████▄░░▄███████
█████████████████████████
█████████████████████████
▀███████████████████████▀
▄███████████████████████▄
█████████████████████████
█████████████████████████
██████▀░░░▀▀▀▀▀░░░▀██████
█████▀░░░░░░░░░░░░░▀█████
████▀░░░░░░░░░░░░░░░▀████
████░░░░▄█▄░░░▄█▄░░░░████
███▌░░░░▀█▀░░░▀█▀░░░░▐███
███▌░░░░▄░░░░░░░▄░░░░▐███
█████▄▄░▄█▄▄▄▄▄█▄░▄▄█████
█████████████████████████
█████████████████████████
▀███████████████████████▀
 
  PLAY NOW  
[/quote]
Code: (Hero - Legendary Member)
[center][table][tr][td][url=h
Wind_FURY
Legendary
*
Offline

Activity: 3724
Merit: 2210



View Profile
July 31, 2026, 06:32:02 AM
Merited by pooya87 (5), vapourminer (4), LoyceV (4), Pmalek (3), JayJuanGee (1), hosemary (1), Zwei (1)
 #22

It seems that Coldcard users have not been fully proven to be affected by the Ill Bloom vulnerability, but because there are several users affected, Coldcard's name is dragged, however, anyone who uses Coldcard here, especially those who use it before 2026, must remain vigilant, for the sake of bitcoin security, it is better to move everything to a new wallet until the origin of this theft problem is known.

Coldcard confirmed the vulnerability: https://x.com/COLDCARDwallet/status/2082961993070247948


Here's a post in X about WHY it may have happened,

Quote

Regarding the Coldcard entropy bug – many folks are explaining what happened but I wanted to take a minute to explain why it may have happened.

It's a disastrous situation and our heart goes out to all the Bitcoiners affected.

Here's a timeline of events:

On July 28 2020: @FoundationHQ announced our first Passport hardware wallet and noted that we were building on Coldcard firmware which at the time was GPLv3 licensed (FOSS license).

On July 30 2020: NVK publicly said he regretted choosing GPL because Coldcard now had a “clone” and that they would change things in future updates. x.com/nvk/status/128…

On November 18 2020: Coldcard added its MIT + Commons Clause license, prohibiting commercial products substantially derived from the software. github.com/Coldcard/firmw…

On January 8, 2021: Coldcard firmware 3.2.1 formally announced, “License changed from GPL to MIT+CC on files for which the GPL doesn’t apply.” CC is the "Commons Clause" license addendum which is "source available" instead of FOSS.

On March 1, 2021: The “First pass w/ libNgU” commit removed the GPL @Trezor-derived crypto libraries and replaced them with libNgU. That same 120-file commit changed seed generation code. libNgU was licensed with a novel “Licensed for Bitcoin Only” license.

On March 17, 2021: Version 4.0.0 announced that all crypto and BIP39 code had been replaced and that the “last remaining GPL code” was removed. blog.coinkite.com/version-4.0.0-…
github.com/Coldcard/firmw…

Our best understanding right now is that the entropy bug was collateral damage from this major overhaul of the codebase.

To be clear, this overhaul was not solely about licensing. Coldcard also cited technical goals including adopting Bitcoin Core’s libsecp256k1, faster AES and SHA implementations, and reproducible builds.

But the timeline establishes two things:
(1) Foundation’s launch was the obvious impetus for Coldcard’s licensing change, and
(2) removing the remaining GPL code was an explicit goal of the subsequent v4 rewrite.

We don't know by how much the licensing pressure affected the scope or timeline of the rewrite. All we can determine is that the entropy bug was introduced inside the same 120-file commit that removed the old GPL code dependencies.

https://x.com/zherbert/status/2082993276324319713


Personally, for people who use ColdCard, remove all your assets, throw the wallet away, AND NEVER buy another hardware wallet from them again.

NotATether
Legendary
*
Offline

Activity: 2408
Merit: 10073


┻┻ ︵㇏(°□°㇏)


View Profile WWW
July 31, 2026, 06:37:40 AM
Merited by Pmalek (3), JayJuanGee (1)
 #23

Haa! NotATether. You mate some explanation to make about this comment, like what do you mean by saying people should not use their hardware wallet to generate seed phrases? This is the first time I would ever heard such, I've been using my seed phrases that was generated with an airgapped hardware wallet, how is this not safe?

This vulnerability is entirely the fault of a firmware update which introduced a vulnerability in the RNG.

That's why I said you cannot trust the hardware wallet to do it right.

It is better to use a downloaded copy of the Iancoleman website, or an offline Electrum, Sparrow, or any other open source wallet on a secure computer to create the seed, or even dice, than to trust a firmware whose code is hard to read and understand.

Just reading about it on X. I didn’t think anything like this was possible, I guess it shows the importance of multisig. Good practise to divide your stash amongst various hardware wallets.

If you have a few hardware wallets, multisig would be the better option imo.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
SilverCryptoBullet
Sr. Member
****
Offline

Activity: 1120
Merit: 286



View Profile
July 31, 2026, 06:39:00 AM
 #24

Just use an open source reputed wallet.
Coldcard wallet is open source
https://walletscrutiny.com/?platform=allPlatforms&page=0&query-string=coldcard

Very concerning. I’ve never touched a coldcard but I’ve seen them mentioned enough around these forums to where I’m certain this is going to be a big deal if it is in fact a vulnerability and not someone losing their stash due to their own mistake. I’ll have to do some reading up about this one.
It's very concerning, I see Coldcard wallet is recommended by Jameson Lopp on his blog too.
https://www.lopp.net/bitcoin-information/recommended-wallets.html
Quote
Key Storage Hardware:

    Comparison Matrix
    BitBox
    Coldcard
    Jade
    Krux
    Ledger
    Passport
    Seedsigner
    Specter DIY
    Trezor
Will it be time for him to remove Coldcard from his Recommended wallets list?











██
██
██████
R


▀▀██████▄▄
████████████████
▀█████▀▀▀█████
████████▌███▐████
▄█████▄▄▄█████
████████████████
▄▄██████▀▀
LLBIT
██████
██
██
██████
██
██
██
██
██
██
██
██
██
██
██
██████
██████████████
 
 TH#1 SOLANA CASINO 
██████████████
██████
██
██
██
██
██
██
██
██
██
██
██
██████
████████████▄
▀▀██████▀▀███
██▄▄▀▀▄▄████
████████████
██████████
███▀████████
▄▄█████████
████████████
████████████
████████████
████████████
█████████████
████████████▀
████████████▄
▀▀▀▀▀▀▀██████
████████████
███████████
██▄█████████
████▄███████
████████████
█░▀▀████████
▀▀██████████
█████▄█████
████▀▄▀████
▄▄▄▄▄▄▄██████
████████████▀
[
[
5,000+
GAMES
INSTANT
WITHDRAWALS
][
][
HUGE
   REWARDS   
VIP
PROGRAM
]
]
████
██
██
██
██
██
██
██
██
██
██
██
████
████████████████████████████████████████████████
 
PLAY NOW
 

████████████████████████████████████████████████
████
██
██
██
██
██
██
██
██
██
██
██
████
NotATether
Legendary
*
Offline

Activity: 2408
Merit: 10073


┻┻ ︵㇏(°□°㇏)


View Profile WWW
July 31, 2026, 06:40:39 AM
 #25

It's very concerning, I see Coldcard wallet is recommended by Jameson Lopp on his blog too.
https://www.lopp.net/bitcoin-information/recommended-wallets.html
Quote
~
Will it be time for him to remove Coldcard from his Recommended wallets list?

Ledger should also be removed because of that seed phrase recovery update they introduced some time ago.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
Meuserna
Sr. Member
****
Offline

Activity: 334
Merit: 551


View Profile WWW
July 31, 2026, 06:49:09 AM
 #26

It's very concerning, I see Coldcard wallet is recommended by Jameson Lopp on his blog too.
https://www.lopp.net/bitcoin-information/recommended-wallets.html
Quote
~
Will it be time for him to remove Coldcard from his Recommended wallets list?

Ledger should also be removed because of that seed phrase recovery update they introduced some time ago.

THIS.

Ledger's key extraction scheme will be hacked. I have no doubt about that. It'll probably at the firmware level. And I won't be surprised if it ends up being an even bigger catastrophe than this attack. It's not a question of "if." It's a question of "when."

The loss of those coins is preventable, but too many idiots prioritize brand loyalty and cool factor. They're victims in waiting and there's only so many times we can warn them. Ledger cannot be trusted.


It seems that Coldcard users have not been fully proven to be affected by the Ill Bloom vulnerability, but because there are several users affected, Coldcard's name is dragged, however, anyone who uses Coldcard here, especially those who use it before 2026, must remain vigilant, for the sake of bitcoin security, it is better to move everything to a new wallet until the origin of this theft problem is known.

Coldcard confirmed the vulnerability: https://x.com/COLDCARDwallet/status/2082961993070247948


Here's a post in X about WHY it may have happened,

Quote

Regarding the Coldcard entropy bug – many folks are explaining what happened but I wanted to take a minute to explain why it may have happened.

It's a disastrous situation and our heart goes out to all the Bitcoiners affected.

Here's a timeline of events:

On July 28 2020: @FoundationHQ announced our first Passport hardware wallet and noted that we were building on Coldcard firmware which at the time was GPLv3 licensed (FOSS license).

On July 30 2020: NVK publicly said he regretted choosing GPL because Coldcard now had a “clone” and that they would change things in future updates. x.com/nvk/status/128…

On November 18 2020: Coldcard added its MIT + Commons Clause license, prohibiting commercial products substantially derived from the software. github.com/Coldcard/firmw…

On January 8, 2021: Coldcard firmware 3.2.1 formally announced, “License changed from GPL to MIT+CC on files for which the GPL doesn’t apply.” CC is the "Commons Clause" license addendum which is "source available" instead of FOSS.

On March 1, 2021: The “First pass w/ libNgU” commit removed the GPL @Trezor-derived crypto libraries and replaced them with libNgU. That same 120-file commit changed seed generation code. libNgU was licensed with a novel “Licensed for Bitcoin Only” license.

On March 17, 2021: Version 4.0.0 announced that all crypto and BIP39 code had been replaced and that the “last remaining GPL code” was removed. blog.coinkite.com/version-4.0.0-…
github.com/Coldcard/firmw…

Our best understanding right now is that the entropy bug was collateral damage from this major overhaul of the codebase.

To be clear, this overhaul was not solely about licensing. Coldcard also cited technical goals including adopting Bitcoin Core’s libsecp256k1, faster AES and SHA implementations, and reproducible builds.

But the timeline establishes two things:
(1) Foundation’s launch was the obvious impetus for Coldcard’s licensing change, and
(2) removing the remaining GPL code was an explicit goal of the subsequent v4 rewrite.

We don't know by how much the licensing pressure affected the scope or timeline of the rewrite. All we can determine is that the entropy bug was introduced inside the same 120-file commit that removed the old GPL code dependencies.

https://x.com/zherbert/status/2082993276324319713


Personally, for people who use ColdCard, remove all your assets, throw the wallet away, AND NEVER buy another hardware wallet from them again.

Oh my god. That just makes it worse. So much worse.

I didn't lose any coins. I'm not a ColdCard user. But I just want to scream at the top of my lungs, NEVER TRUST YOUR BITCOIN TO CODE THAT IS NOT FULLY OPEN SOURCE. No exceptions. No excuses.

SilverCryptoBullet
Sr. Member
****
Offline

Activity: 1120
Merit: 286



View Profile
July 31, 2026, 06:52:52 AM
 #27

Ledger should also be removed because of that seed phrase recovery update they introduced some time ago.
I agree and I knew that but did not write it in the post because I think it is off-topic.

You are very right about Ledger wallet and its Recover product years ago. It's perhaps a little bit surprising for you if you know Jameson Lopp had a livestream with Andreas Antonopoulos about Ledger's Recover.

Their livestream three years ago:
Ledger Recover: What The Hell is Happening? With aantonop and lopp.
Andreas got a severe migraine and he has been no longer active recent months.

Forum discussed and warned about it:
Ledger Recovery - Send your (encrypted) recovery phrase to 3rd parties.











██
██
██████
R


▀▀██████▄▄
████████████████
▀█████▀▀▀█████
████████▌███▐████
▄█████▄▄▄█████
████████████████
▄▄██████▀▀
LLBIT
██████
██
██
██████
██
██
██
██
██
██
██
██
██
██
██
██████
██████████████
 
 TH#1 SOLANA CASINO 
██████████████
██████
██
██
██
██
██
██
██
██
██
██
██
██████
████████████▄
▀▀██████▀▀███
██▄▄▀▀▄▄████
████████████
██████████
███▀████████
▄▄█████████
████████████
████████████
████████████
████████████
█████████████
████████████▀
████████████▄
▀▀▀▀▀▀▀██████
████████████
███████████
██▄█████████
████▄███████
████████████
█░▀▀████████
▀▀██████████
█████▄█████
████▀▄▀████
▄▄▄▄▄▄▄██████
████████████▀
[
[
5,000+
GAMES
INSTANT
WITHDRAWALS
][
][
HUGE
   REWARDS   
VIP
PROGRAM
]
]
████
██
██
██
██
██
██
██
██
██
██
██
████
████████████████████████████████████████████████
 
PLAY NOW
 

████████████████████████████████████████████████
████
██
██
██
██
██
██
██
██
██
██
██
████
Pmalek
Legendary
*
Offline

Activity: 3570
Merit: 9412



View Profile
July 31, 2026, 07:14:07 AM
 #28

Coldcard is not open-source. The code is publicly available for verification, but it's not open-source. I guess the right term is "source-verifiable code."
With an open-source license, you are allowed to use the code, build upon it, and release your own products. Coldcard doesn't allow you to do that. In the beginning, it was open-source, but NVK changed it to prevent other companies from copying the Coldcard code to create similar (competitor) products. That was a bad decision.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
Stalker22
Legendary
*
Offline

Activity: 2310
Merit: 1612



View Profile
July 31, 2026, 07:47:48 AM
Merited by JayJuanGee (1)
 #29

I guess it shows the importance of multisig.
~

Also, a good, strong passphrase for your seed phrase.  Many people overlook this part, but it is actually a very strong security measure if used correctly.

█████████████████████████
███████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
███▀░░██████▀░▀████░░▀███
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
███▄░░██████░░████░░▄███
█████▄░░▀███░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
 ROOBET .██████. BET ON WORLD CUP  🗺 ⚽︎.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
|.
   BET NOW   
flatfly (OP)
Legendary
*
Offline

Activity: 1288
Merit: 1332

Joined: 2012


View Profile
July 31, 2026, 07:52:00 AM
 #30

Technical deep dive:

https://blog.coinkite.com/entropy-technical-backgrounder/

Did you know? Counterparty is still alive! It's the Bitcoin-native DEX with a fascinating history, running with zero downtime since 2014.
Meuserna
Sr. Member
****
Offline

Activity: 334
Merit: 551


View Profile WWW
July 31, 2026, 07:54:37 AM
Merited by JayJuanGee (1)
 #31

Coldcard is not open-source. The code is publicly available for verification, but it's not open-source. I guess the right term is "source-verifiable code."
With an open-source license, you are allowed to use the code, build upon it, and release your own products. Coldcard doesn't allow you to do that. In the beginning, it was open-source, but NVK changed it to prevent other companies from copying the Coldcard code to create similar (competitor) products. That was a bad decision.

That is exactly right. And here's the problem with "source verifiable" code vs open source code.

When ColdCard switched their code from being open source to “source verifiable” they blocked other developers from being able to legally use their code. This decreased the number of developers regularly reading their code.

Fewer devs reading the code meant fewer experts finding errors in the code, which meant fewer errors being found and fixed.

Hackers found an exploit in ColdCard's code and they exploited it to vicious effect. Over 500 wallets were drained.

Eff ColdCard and their “source verifiable” code. It isn't open source, and it's costing people their coins.

This isn't the last of these attacks, but these attacks are preventable.

Never trust your Bitcoin to code that is not fully open source. No exceptions. And if we're being completely honest, it's probably time to stop using wallets created using code-generated seed phrases unless you're also using human-generated input such as a passphrase or multisig.

ABCbits
Legendary
*
Offline

Activity: 3682
Merit: 10263



View Profile
July 31, 2026, 07:54:48 AM
 #32

It is better to use a downloaded copy of the Iancoleman website, or an offline Electrum, Sparrow, or any other open source wallet on a secure computer to create the seed, or even dice, than to trust a firmware whose code is hard to read and understand.

I would just use /dev/urandom as the seed/entropy source, if i know wallet somehow doesn't use it.

It's very concerning, I see Coldcard wallet is recommended by Jameson Lopp on his blog too.
https://www.lopp.net/bitcoin-information/recommended-wallets.html
Quote
~
Will it be time for him to remove Coldcard from his Recommended wallets list?

Ledger should also be removed because of that seed phrase recovery update they introduced some time ago.

Actually he should update the whole list (not only wallet page). It's clearly very outdated, when it still show Joinmarket that got its final update and Green wallet called Blockstream wallet these days.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits..REWARDING, BEYOND LIMITS...
█████████████████████████
█████████████████████████
███████████▀▀░░▀█▄░░▀████
████████▀░░░░░░░░▀█▄░████
███████░░░░▄▄░░▄░░░▀█████
██████░░░░░▀▀▄██▀░░░░████
█████░░░██░▄██▀▄▄░░░█████
████░░░░░▄██▀░░▀▀░░██████
█████▄░░▀█▀░██░░░░███████
████░▀█▄░░░░░░░░▄████████
████▄░░▀█▄░░▄▄███████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████▀░░▀░███████████
████████░░░▄░█░██████████
███████████▌▐██░█████████
███████████░███▌▐████████
██████████░█████░████████
██████▀░▄░▀███▀░▄░▀█████
█████░▄▀░░░░█░▄▀░░░░█████
█████░░░░░░░█░░░░░░░█████
██████▄░░░▄███▄░░░▄██████
█████████████████████████
█████████████████████████


























  PLAY NOW  
NotATether
Legendary
*
Offline

Activity: 2408
Merit: 10073


┻┻ ︵㇏(°□°㇏)


View Profile WWW
July 31, 2026, 08:13:53 AM
Merited by JayJuanGee (1), Cookdata (1)
 #33

Here's the full list of vulnerable devices and their firmware versions.



Note that there is a firmware patch for Mk4, Q, and Mk5. For Mk3 and Mk2, there is no patch, so they must transfer funds out to a more secure seed phrase.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
Texac
Hero Member
*****
Offline

Activity: 2520
Merit: 554


how do you define success?


View Profile WWW
July 31, 2026, 08:31:29 AM
 #34

That is, randomness is a single point of failure?

If the entropy of seed generation can be predicted, then no secure element, air-gap or PIN can save our  private key. Reading Coinkite's advisory post, it seemed like this, he indicated that the root of this problem was the randomness of the seed generation.

So we don't consider hardware wallet as absolute security? Or should security layers be more additive?

If I use a strong BIP39 passphrase can I still have this problem?

▄▄███████████████████▄▄
▄███████████████████████▄
███████████████████████
████████▀▀▀▀██▀█▄▀███████
███▀▀██▄▄██▄██▌▄▄▄▄▄██
████▄█████▐██▀▄█▀▀█████
█████▌██▀▀▄█▀██▄██▄███
██▄▄▄▄███████████▐███████
████████▐█████████▀▀█████
███████▄██████▀█▄▄▄▄▄████
███████████████████████

▀███████████████████████▀
▀▀███████████████████▀▀

 Kings Game  
 
 🎰   🎲   ⚽ 
████
██
██
██
██
██
██
██
██
██
██
██
████
████████████████████████████


RAKEBACK
..UP TO 30%..
████████████████████████████
████
██
██
██
██
██
██
██
██
██
██
██
████
████
██
██
██
██
██
██
██
██
██
██
██
████
████████████████████████████
 
..500%..
WELCOME BONUS
+ 250 FREE SPINS
████████████████████████████
████
██
██
██
██
██
██
██
██
██
██
██
████

   WIN NOW     
YellowSwap
Full Member
***
Offline

Activity: 630
Merit: 196



View Profile
July 31, 2026, 08:57:37 AM
 #35

That is, randomness is a single point of failure?

If the entropy of seed generation can be predicted, then no secure element, air-gap or PIN can save our  private key. Reading Coinkite's advisory post, it seemed like this, he indicated that the root of this problem was the randomness of the seed generation.

So we don't consider hardware wallet as absolute security? Or should security layers be more additive?

If I use a strong BIP39 passphrase can I still have this problem?

If you are using any MK Devices I suggest you move your Bitcoin out, at this point it's better to move them back into Electrum software wallet for the time being.

You will have to get a better hardware wallet later, I guess the problem is how the seed phrases are been generated, lord have mercy, I don't ever think that such thing will happen on hardware wallets.

This is where Dice only seed or multisig wallet will come to the rescue, but damn mine isn't generated this way, what the hell is happening? I heard that this coldcard is even a reputable company,

Livingleged
Full Member
***
Offline

Activity: 266
Merit: 154



View Profile
July 31, 2026, 09:21:31 AM
 #36

~snip
I must admit this is one of the most emotional bitcoin thefts story I’ve read here in the forum, I didn’t know when tear dropped off my chic. Sorry for your loss I hope the thief realises he didn’t just steal bitcoin but he just stole what was meant to safe a life.
From your post you only showed the wallet address you didn’t tell what wallet it was, and I think it’s better you provide every necessary information that could help you get back your fund.
I hope it turns out good and you recover everything to safe this child’s life.

Hypnotizer
Full Member
***
Offline

Activity: 336
Merit: 222



View Profile
July 31, 2026, 09:38:12 AM
 #37

Quote from: Livingleged
From your post you only showed the wallet address you didn’t tell what wallet it was

Did you realize this theft is associated to a specific hardware wallet? I don’t get what you mean by “he didn’t tell what wallet it is/was”.

Quote from: Livingleged
and I think it’s better you provide every necessary information that could help you get back your fund.
I hope it turns out good and you recover everything to safe this child’s life.

It’s a very sad and tragic situation, at this point I can’t help but feel sorry for this victim but I don’t think any “necessary information” Whatsoever he provided can help him get his funds. This is a Theft.

@Victim.. I pray you find peace and more abundance in ways you don’t expect to recover from this massive loss, 1.8 bitcoins theft is certainly not an easy thing to recover from but you should have hope. With life everything is still recoverable.


NotATether
Legendary
*
Offline

Activity: 2408
Merit: 10073


┻┻ ︵㇏(°□°㇏)


View Profile WWW
July 31, 2026, 09:43:28 AM
 #38

An advisory of the vulnerability and compilation of all the affected addresses and amounts will be created on BitMixList, for easy accessibility and reference purposes.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
Stalker22
Legendary
*
Offline

Activity: 2310
Merit: 1612



View Profile
July 31, 2026, 09:48:27 AM
Last edit: July 31, 2026, 09:59:48 AM by Stalker22
 #39

~
From your post you only showed the wallet address you didn’t tell what wallet it was, and I think it’s better you provide every necessary information that could help you get back your fund.

I also agree.  He just gave the address where the coins were moved, the one where all the stolen funds were consolidated - everyone can know it since it was from public in blockchain.  It feels like victims should disclose a small piece of something as proof that their sob story is at least partially true -  like a message signed from the compromised address or something.



Quote from: Livingleged
From your post you only showed the wallet address you didn’t tell what wallet it was

Did you realize this theft is associated to a specific hardware wallet? I don’t get what you mean by “he didn’t tell what wallet it is/was”.

You do realize Coldcard has released multiple hardware revisions and dozens of firmware updates over the years, right?

Livingleged is right. He did not mention a single detail about his wallet.  What specific hardware was he using?  What firmware version?  How was the seed generated, and did he use a passphrase?  All of these details are essential to accurately identify the threat and potentially protect future victims.

█████████████████████████
███████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
███▀░░██████▀░▀████░░▀███
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
███▄░░██████░░████░░▄███
█████▄░░▀███░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
 ROOBET .██████. BET ON WORLD CUP  🗺 ⚽︎.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
|.
   BET NOW   
YellowSwap
Full Member
***
Offline

Activity: 630
Merit: 196



View Profile
July 31, 2026, 09:57:14 AM
 #40


The address I'm writing about is bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.

You didn't steal from a wallet.

You stole from a family

Naah, I will never let this pass me, what a sad story to read, oh my God, I can never imagine saving my Bitcoin for years only to lost it this way? I would die even though I don't have kid yet, I hope the hacker who did this reconsider this address atleast.

He is right that some Bitcoin holders aren't rich, they are only trying to build a better future for their family,  it is on this same journey that I'm setting up for myself, this is making me cry already, I chose to not steal but rather work my way up, I don't know why people do this.

Someone's life is at stake here, what will be the fate of that boy who needs surgery in the nearest future? This is making me very angry right now, I'm not even sure that someone who did this will be on here, but I hope so.

It's also good that moderators made it available at the face front of the forum, I am sorry for your loss whoever you are, I wish I can help one way or the other.


ColdCardVictim I can't promise that you will get help here, if nothing comes up please try to contact @ZachXBT on twitter maybe he can help, this guy has helped recovered some lost and stolen Bitcoin back in the past, and for the sake of your son I think you need gofundme or something similar to raise funds, I can be a part contributor if this is possible.

If you are reading this, I will suggest you sign some message on that Bitcoin address just to prove that it truly belongs to you.

Here is how to sign message if you don't know.


May the Lord's help shine upon you and your Family.
Pls be strong.

Pages: « 1 [2] 3 4 5 6 7 8 9 10 11 12 13 14 15 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!