LFC_Bitcoin
Diamond Hands
Legendary

Activity: 4340
Merit: 13071
|
 |
July 31, 2026, 06:26:20 AM |
|
Just reading about it on X. I didn’t think anything like this was possible, I guess it shows the importance of multisig. Good practise to divide your stash amongst various hardware wallets.
|
[/quote] [center][table][tr][td][url=h
|
|
|
Wind_FURY
Legendary

Activity: 3724
Merit: 2208
|
It seems that Coldcard users have not been fully proven to be affected by the Ill Bloom vulnerability, but because there are several users affected, Coldcard's name is dragged, however, anyone who uses Coldcard here, especially those who use it before 2026, must remain vigilant, for the sake of bitcoin security, it is better to move everything to a new wallet until the origin of this theft problem is known.
Coldcard confirmed the vulnerability: https://x.com/COLDCARDwallet/status/2082961993070247948Here's a post in X about WHY it may have happened, Regarding the Coldcard entropy bug – many folks are explaining what happened but I wanted to take a minute to explain why it may have happened. It's a disastrous situation and our heart goes out to all the Bitcoiners affected. Here's a timeline of events: On July 28 2020: @FoundationHQ announced our first Passport hardware wallet and noted that we were building on Coldcard firmware which at the time was GPLv3 licensed (FOSS license). On July 30 2020: NVK publicly said he regretted choosing GPL because Coldcard now had a “clone” and that they would change things in future updates. x.com/nvk/status/128… On November 18 2020: Coldcard added its MIT + Commons Clause license, prohibiting commercial products substantially derived from the software. github.com/Coldcard/firmw… On January 8, 2021: Coldcard firmware 3.2.1 formally announced, “License changed from GPL to MIT+CC on files for which the GPL doesn’t apply.” CC is the "Commons Clause" license addendum which is "source available" instead of FOSS. On March 1, 2021: The “First pass w/ libNgU” commit removed the GPL @Trezor-derived crypto libraries and replaced them with libNgU. That same 120-file commit changed seed generation code. libNgU was licensed with a novel “Licensed for Bitcoin Only” license. On March 17, 2021: Version 4.0.0 announced that all crypto and BIP39 code had been replaced and that the “last remaining GPL code” was removed. blog.coinkite.com/version-4.0.0-… github.com/Coldcard/firmw… Our best understanding right now is that the entropy bug was collateral damage from this major overhaul of the codebase. To be clear, this overhaul was not solely about licensing. Coldcard also cited technical goals including adopting Bitcoin Core’s libsecp256k1, faster AES and SHA implementations, and reproducible builds. But the timeline establishes two things: (1) Foundation’s launch was the obvious impetus for Coldcard’s licensing change, and (2) removing the remaining GPL code was an explicit goal of the subsequent v4 rewrite. We don't know by how much the licensing pressure affected the scope or timeline of the rewrite. All we can determine is that the entropy bug was introduced inside the same 120-file commit that removed the old GPL code dependencies. https://x.com/zherbert/status/2082993276324319713Personally, for people who use ColdCard, remove all your assets, throw the wallet away, AND NEVER buy another hardware wallet from them again.
|
|
|
|
NotATether
Legendary

Activity: 2408
Merit: 10012
┻┻ ︵㇏(°□°㇏)
|
 |
July 31, 2026, 06:37:40 AM |
|
Haa! NotATether. You mate some explanation to make about this comment, like what do you mean by saying people should not use their hardware wallet to generate seed phrases? This is the first time I would ever heard such, I've been using my seed phrases that was generated with an airgapped hardware wallet, how is this not safe?
This vulnerability is entirely the fault of a firmware update which introduced a vulnerability in the RNG. That's why I said you cannot trust the hardware wallet to do it right. It is better to use a downloaded copy of the Iancoleman website, or an offline Electrum, Sparrow, or any other open source wallet on a secure computer to create the seed, or even dice, than to trust a firmware whose code is hard to read and understand. Just reading about it on X. I didn’t think anything like this was possible, I guess it shows the importance of multisig. Good practise to divide your stash amongst various hardware wallets.
If you have a few hardware wallets, multisig would be the better option imo.
|
|
|
|
|
SilverCryptoBullet
|
 |
July 31, 2026, 06:39:00 AM |
|
Just use an open source reputed wallet.
Coldcard wallet is open source https://walletscrutiny.com/?platform=allPlatforms&page=0&query-string=coldcardVery concerning. I’ve never touched a coldcard but I’ve seen them mentioned enough around these forums to where I’m certain this is going to be a big deal if it is in fact a vulnerability and not someone losing their stash due to their own mistake. I’ll have to do some reading up about this one.
It's very concerning, I see Coldcard wallet is recommended by Jameson Lopp on his blog too. https://www.lopp.net/bitcoin-information/recommended-wallets.htmlKey Storage Hardware:
Comparison Matrix BitBox Coldcard Jade Krux Ledger Passport Seedsigner Specter DIY Trezor
Will it be time for him to remove Coldcard from his Recommended wallets list?
|
|
██ ██ ██████ | R |
▀▀▀▀▀▀▀██████▄▄ ████████████████ ▀▀▀▀█████▀▀▀█████ ████████▌███▐████ ▄▄▄▄█████▄▄▄█████ ████████████████ ▄▄▄▄▄▄▄██████▀▀ | LLBIT | ██████ ██ ██ | ██████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██████ | ██████████████ THE #1 SOLANA CASINO
██████████████ | ██████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██████ | ████████████▄ ▀▀██████▀▀███ ██▄▄▀▀▄▄█████ █████████████ █████████████ ███▀█████████ ▀▄▄██████████ █████████████ █████████████ █████████████ █████████████ █████████████ ████████████▀ | ████████████▄ ▀▀▀▀▀▀▀██████ █████████████ ▄████████████ ██▄██████████ ████▄████████ █████████████ █░▀▀█████████ ▀▀███████████ █████▄███████ ████▀▄▀██████ ▄▄▄▄▄▄▄██████ ████████████▀ | [ [ | 5,000+ GAMES INSTANT WITHDRAWALS | ][ ][ | HUGE REWARDS VIP PROGRAM | ] ] | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | ████████████████████████████████████████████████ PLAY NOW ████████████████████████████████████████████████ | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ |
|
|
|
NotATether
Legendary

Activity: 2408
Merit: 10012
┻┻ ︵㇏(°□°㇏)
|
 |
July 31, 2026, 06:40:39 AM |
|
Ledger should also be removed because of that seed phrase recovery update they introduced some time ago.
|
|
|
|
|
Meuserna
|
 |
July 31, 2026, 06:49:09 AM |
|
Ledger should also be removed because of that seed phrase recovery update they introduced some time ago. THIS. Ledger's key extraction scheme will be hacked. I have no doubt about that. It'll probably at the firmware level. And I won't be surprised if it ends up being an even bigger catastrophe than this attack. It's not a question of "if." It's a question of "when." The loss of those coins is preventable, but too many idiots prioritize brand loyalty and cool factor. They're victims in waiting and there's only so many times we can warn them. Ledger cannot be trusted. It seems that Coldcard users have not been fully proven to be affected by the Ill Bloom vulnerability, but because there are several users affected, Coldcard's name is dragged, however, anyone who uses Coldcard here, especially those who use it before 2026, must remain vigilant, for the sake of bitcoin security, it is better to move everything to a new wallet until the origin of this theft problem is known.
Coldcard confirmed the vulnerability: https://x.com/COLDCARDwallet/status/2082961993070247948Here's a post in X about WHY it may have happened, Regarding the Coldcard entropy bug – many folks are explaining what happened but I wanted to take a minute to explain why it may have happened. It's a disastrous situation and our heart goes out to all the Bitcoiners affected. Here's a timeline of events: On July 28 2020: @FoundationHQ announced our first Passport hardware wallet and noted that we were building on Coldcard firmware which at the time was GPLv3 licensed (FOSS license). On July 30 2020: NVK publicly said he regretted choosing GPL because Coldcard now had a “clone” and that they would change things in future updates. x.com/nvk/status/128… On November 18 2020: Coldcard added its MIT + Commons Clause license, prohibiting commercial products substantially derived from the software. github.com/Coldcard/firmw… On January 8, 2021: Coldcard firmware 3.2.1 formally announced, “License changed from GPL to MIT+CC on files for which the GPL doesn’t apply.” CC is the "Commons Clause" license addendum which is "source available" instead of FOSS. On March 1, 2021: The “First pass w/ libNgU” commit removed the GPL @Trezor-derived crypto libraries and replaced them with libNgU. That same 120-file commit changed seed generation code. libNgU was licensed with a novel “Licensed for Bitcoin Only” license. On March 17, 2021: Version 4.0.0 announced that all crypto and BIP39 code had been replaced and that the “last remaining GPL code” was removed. blog.coinkite.com/version-4.0.0-… github.com/Coldcard/firmw… Our best understanding right now is that the entropy bug was collateral damage from this major overhaul of the codebase.To be clear, this overhaul was not solely about licensing. Coldcard also cited technical goals including adopting Bitcoin Core’s libsecp256k1, faster AES and SHA implementations, and reproducible builds. But the timeline establishes two things: (1) Foundation’s launch was the obvious impetus for Coldcard’s licensing change, and (2) removing the remaining GPL code was an explicit goal of the subsequent v4 rewrite. We don't know by how much the licensing pressure affected the scope or timeline of the rewrite. All we can determine is that the entropy bug was introduced inside the same 120-file commit that removed the old GPL code dependencies. https://x.com/zherbert/status/2082993276324319713Personally, for people who use ColdCard, remove all your assets, throw the wallet away, AND NEVER buy another hardware wallet from them again. Oh my god. That just makes it worse. So much worse. I didn't lose any coins. I'm not a ColdCard user. But I just want to scream at the top of my lungs, NEVER TRUST YOUR BITCOIN TO CODE THAT IS NOT FULLY OPEN SOURCE. No exceptions. No excuses.
|
|
|
|
|
SilverCryptoBullet
|
 |
July 31, 2026, 06:52:52 AM |
|
Ledger should also be removed because of that seed phrase recovery update they introduced some time ago.
I agree and I knew that but did not write it in the post because I think it is off-topic. You are very right about Ledger wallet and its Recover product years ago. It's perhaps a little bit surprising for you if you know Jameson Lopp had a livestream with Andreas Antonopoulos about Ledger's Recover. Their livestream three years ago: Ledger Recover: What The Hell is Happening? With aantonop and lopp.Andreas got a severe migraine and he has been no longer active recent months. Forum discussed and warned about it: Ledger Recovery - Send your (encrypted) recovery phrase to 3rd parties.
|
|
██ ██ ██████ | R |
▀▀▀▀▀▀▀██████▄▄ ████████████████ ▀▀▀▀█████▀▀▀█████ ████████▌███▐████ ▄▄▄▄█████▄▄▄█████ ████████████████ ▄▄▄▄▄▄▄██████▀▀ | LLBIT | ██████ ██ ██ | ██████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██████ | ██████████████ THE #1 SOLANA CASINO
██████████████ | ██████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██████ | ████████████▄ ▀▀██████▀▀███ ██▄▄▀▀▄▄█████ █████████████ █████████████ ███▀█████████ ▀▄▄██████████ █████████████ █████████████ █████████████ █████████████ █████████████ ████████████▀ | ████████████▄ ▀▀▀▀▀▀▀██████ █████████████ ▄████████████ ██▄██████████ ████▄████████ █████████████ █░▀▀█████████ ▀▀███████████ █████▄███████ ████▀▄▀██████ ▄▄▄▄▄▄▄██████ ████████████▀ | [ [ | 5,000+ GAMES INSTANT WITHDRAWALS | ][ ][ | HUGE REWARDS VIP PROGRAM | ] ] | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | ████████████████████████████████████████████████ PLAY NOW ████████████████████████████████████████████████ | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ |
|
|
|
Pmalek
Legendary

Activity: 3570
Merit: 9408
|
 |
July 31, 2026, 07:14:07 AM |
|
Coldcard is not open-source. The code is publicly available for verification, but it's not open-source. I guess the right term is "source-verifiable code." With an open-source license, you are allowed to use the code, build upon it, and release your own products. Coldcard doesn't allow you to do that. In the beginning, it was open-source, but NVK changed it to prevent other companies from copying the Coldcard code to create similar (competitor) products. That was a bad decision.
|
| EARNBET | | | ⚽ 🏀 🏈 🏓 🎯 🥊 |
| ⚾ 🎾 ⛳ 🏐 🏏 🏎️ | | |
███████▄▄███████████ ████▄██████████████████ ██▄▀▀███████████████▀▀███ █▄████████████████████████ ▄▄████████▀▀▀▀▀████████▄▄██ ███████████████████████████ █████████▌████▀████████████ ███████████████████████████ ▀▀███████▄▄▄▄▄█████████▀▀██ █▀█████████████████████▀██ ██▀▄▄███████████████▄▄███ ████▀██████████████████ ███████▀▀███████████ | ....HIGHEST.... VIP REWARDS ✔ G U A R A N T E E D
| | | 🜲 | KING OF THE CASTLE $200K in prizes | | | ..PLAY NOW.. |
|
|
|
Stalker22
Legendary

Activity: 2310
Merit: 1605
|
 |
July 31, 2026, 07:47:48 AM |
|
I guess it shows the importance of multisig. ~
Also, a good, strong passphrase for your seed phrase. Many people overlook this part, but it is actually a very strong security measure if used correctly.
|
|
|
|
flatfly (OP)
Legendary

Activity: 1288
Merit: 1275
Joined: 2012
|
 |
July 31, 2026, 07:52:00 AM |
|
|
Did you know? Counterparty is still alive! It's the Bitcoin-native DEX with a fascinating history, running with zero downtime since 2014.
|
|
|
|
Meuserna
|
 |
July 31, 2026, 07:54:37 AM |
|
Coldcard is not open-source. The code is publicly available for verification, but it's not open-source. I guess the right term is "source-verifiable code." With an open-source license, you are allowed to use the code, build upon it, and release your own products. Coldcard doesn't allow you to do that. In the beginning, it was open-source, but NVK changed it to prevent other companies from copying the Coldcard code to create similar (competitor) products. That was a bad decision. That is exactly right. And here's the problem with "source verifiable" code vs open source code. When ColdCard switched their code from being open source to “source verifiable” they blocked other developers from being able to legally use their code. This decreased the number of developers regularly reading their code. Fewer devs reading the code meant fewer experts finding errors in the code, which meant fewer errors being found and fixed. Hackers found an exploit in ColdCard's code and they exploited it to vicious effect. Over 500 wallets were drained. Eff ColdCard and their “source verifiable” code. It isn't open source, and it's costing people their coins. This isn't the last of these attacks, but these attacks are preventable. Never trust your Bitcoin to code that is not fully open source. No exceptions. And if we're being completely honest, it's probably time to stop using wallets created using code-generated seed phrases unless you're also using human-generated input such as a passphrase or multisig.
|
|
|
|
ABCbits
Legendary

Activity: 3682
Merit: 10259
|
 |
July 31, 2026, 07:54:48 AM |
|
It is better to use a downloaded copy of the Iancoleman website, or an offline Electrum, Sparrow, or any other open source wallet on a secure computer to create the seed, or even dice, than to trust a firmware whose code is hard to read and understand.
I would just use /dev/urandom as the seed/entropy source, if i know wallet somehow doesn't use it. Ledger should also be removed because of that seed phrase recovery update they introduced some time ago. Actually he should update the whole list (not only wallet page). It's clearly very outdated, when it still show Joinmarket that got its final update and Green wallet called Blockstream wallet these days.
|
|
|
|
NotATether
Legendary

Activity: 2408
Merit: 10012
┻┻ ︵㇏(°□°㇏)
|
 |
July 31, 2026, 08:13:53 AM |
|
Here's the full list of vulnerable devices and their firmware versions.  Note that there is a firmware patch for Mk4, Q, and Mk5. For Mk3 and Mk2, there is no patch, so they must transfer funds out to a more secure seed phrase.
|
|
|
|
|
Texac
|
 |
July 31, 2026, 08:31:29 AM |
|
That is, randomness is a single point of failure?
If the entropy of seed generation can be predicted, then no secure element, air-gap or PIN can save our private key. Reading Coinkite's advisory post, it seemed like this, he indicated that the root of this problem was the randomness of the seed generation.
So we don't consider hardware wallet as absolute security? Or should security layers be more additive?
If I use a strong BIP39 passphrase can I still have this problem?
|
| Kings Game | 🎰 🎲 ⚽ | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | ████████████████████████████
████████████████████████████ | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | ████████████████████████████
| ..500%.. | WELCOME BONUS + 250 FREE SPINS |
████████████████████████████ | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | WIN NOW |
|
|
|
|
YellowSwap
|
 |
July 31, 2026, 08:57:37 AM |
|
That is, randomness is a single point of failure?
If the entropy of seed generation can be predicted, then no secure element, air-gap or PIN can save our private key. Reading Coinkite's advisory post, it seemed like this, he indicated that the root of this problem was the randomness of the seed generation.
So we don't consider hardware wallet as absolute security? Or should security layers be more additive?
If I use a strong BIP39 passphrase can I still have this problem?
If you are using any MK Devices I suggest you move your Bitcoin out, at this point it's better to move them back into Electrum software wallet for the time being. You will have to get a better hardware wallet later, I guess the problem is how the seed phrases are been generated, lord have mercy, I don't ever think that such thing will happen on hardware wallets. This is where Dice only seed or multisig wallet will come to the rescue, but damn mine isn't generated this way, what the hell is happening? I heard that this coldcard is even a reputable company,
|
|
|
|
ColdcardVictim
Newbie

Activity: 5
Merit: 119
|
 |
July 31, 2026, 09:00:59 AM |
|
I hope you see this message. The Attacker
I know the chances of that happening are almost zero, but I still feel like I need to write these words. Maybe you'll scroll past them. Maybe someone else will read them instead. Either way, I want there to be a reminder that behind every Bitcoin address is a real person with a real life.
The address I'm writing about is bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.
You probably don't remember my wallet. To you, it was likely just one of hundreds. Another transaction. Another balance. Another success. But to me, it was something completely different. It was almost 1.8 BTC that I had spent years putting aside, little by little. I didn't become rich overnight, and I certainly didn't have money to waste. Every purchase came from work, patience, and saying "I'll wait" whenever I wanted to spend money on something for myself.
People often assume that anyone who owns Bitcoin must be wealthy. The truth is very different. Some of us simply believed that if we saved long enough, Bitcoin could help us give our families a better future. That's what I believed. Every time I bought a little more, I imagined that one day it would help when my family needed it most.
My son was born with a congenital heart condition. Next year he'll turn 18, and we're preparing for the surgery that we've known would eventually come. For years, those savings represented more than numbers on a screen. They represented peace of mind. They represented hope. They represented the feeling that no matter how difficult life became, I would be able to tell my son, "Don't worry, we'll find a way."
When the coins disappeared, it wasn't just the balance that changed. It felt like years of planning disappeared with them. I remember staring at my wallet for what felt like forever, refreshing it over and over because I couldn't accept what I was seeing. I kept hoping there had been a mistake. There wasn't.
I've asked myself the same questions over and over. Why my wallet? Why my family? Why did something I trusted to protect my savings end up becoming the reason I lost them? I still don't have answers.
I don't know anything about you. I don't know your age, your country, your story, or what brought you to this point. Maybe you'll spend those coins without thinking about where they came from. Maybe you'll tell yourself that in Bitcoin there are winners and losers. Maybe that's enough for you.
But I hope, even for just a moment, you think about the people behind the addresses you emptied.
Not every wallet belongs to a millionaire.
Not every wallet belongs to someone chasing luxury.
Some belong to parents trying to build a future for their children. Some belong to people saving for retirement. Some belong to families trying to survive difficult times. Mine belonged to a father trying to prepare for his son's future.
If there is even a small part of you that still believes in doing the right thing, I ask you to think about returning what you took. Not because you owe me an explanation, and not because anyone can force you to do it, but simply because you have the opportunity to undo some of the pain you've caused.
If you choose not to, then I hope these words stay with you anyway. I hope that someday, when you think back to these coins, you remember that they weren't just Bitcoin. They were years of hope, sacrifice, and love from a father who only wanted to be ready when his son needed him most.
I don't know what the future looks like now. I don't know how we'll rebuild, or how long it will take. I only know that I won't stop trying for my son, because he deserves every chance I can give him.
If you ever read this, I hope you remember one thing.
You didn't steal from a wallet.
You stole from a family
|
|
|
|
|
|
Livingleged
|
 |
July 31, 2026, 09:21:31 AM |
|
~snip
I must admit this is one of the most emotional bitcoin thefts story I’ve read here in the forum, I didn’t know when tear dropped off my chic. Sorry for your loss I hope the thief realises he didn’t just steal bitcoin but he just stole what was meant to safe a life. From your post you only showed the wallet address you didn’t tell what wallet it was, and I think it’s better you provide every necessary information that could help you get back your fund. I hope it turns out good and you recover everything to safe this child’s life.
|
|
|
|
|
Hypnotizer
|
 |
July 31, 2026, 09:38:12 AM |
|
From your post you only showed the wallet address you didn’t tell what wallet it was
Did you realize this theft is associated to a specific hardware wallet? I don’t get what you mean by “he didn’t tell what wallet it is/was”. and I think it’s better you provide every necessary information that could help you get back your fund. I hope it turns out good and you recover everything to safe this child’s life.
It’s a very sad and tragic situation, at this point I can’t help but feel sorry for this victim but I don’t think any “necessary information” Whatsoever he provided can help him get his funds. This is a Theft. @Victim.. I pray you find peace and more abundance in ways you don’t expect to recover from this massive loss, 1.8 bitcoins theft is certainly not an easy thing to recover from but you should have hope. With life everything is still recoverable.
|
|
|
|
NotATether
Legendary

Activity: 2408
Merit: 10012
┻┻ ︵㇏(°□°㇏)
|
 |
July 31, 2026, 09:43:28 AM |
|
An advisory of the vulnerability and compilation of all the affected addresses and amounts will be created on BitMixList, for easy accessibility and reference purposes.
|
|
|
|
Stalker22
Legendary

Activity: 2310
Merit: 1605
|
 |
July 31, 2026, 09:48:27 AM Last edit: July 31, 2026, 09:59:48 AM by Stalker22 |
|
~ From your post you only showed the wallet address you didn’t tell what wallet it was, and I think it’s better you provide every necessary information that could help you get back your fund.
I also agree. He just gave the address where the coins were moved, the one where all the stolen funds were consolidated - everyone can know it since it was from public in blockchain. It feels like victims should disclose a small piece of something as proof that their sob story is at least partially true - like a message signed from the compromised address or something.
From your post you only showed the wallet address you didn’t tell what wallet it was
Did you realize this theft is associated to a specific hardware wallet? I don’t get what you mean by “he didn’t tell what wallet it is/was”. You do realize Coldcard has released multiple hardware revisions and dozens of firmware updates over the years, right? Livingleged is right. He did not mention a single detail about his wallet. What specific hardware was he using? What firmware version? How was the seed generated, and did he use a passphrase? All of these details are essential to accurately identify the threat and potentially protect future victims.
|
|
|
|
|