Bitcoin Forum
August 01, 2026, 01:07:11 AM *
News: COLDCARD users only: critical vulnerability risks funds stored on COLDCARD devices; immediate action required
 
   Home   Help Search Login Register More  
Pages: « 1 2 [3] 4 5 6 »  All
  Print  
Author Topic: Large-scale Coldcard compromise (1082.65 BTC stolen so far)  (Read 1445 times)
YellowSwap
Full Member
***
Offline

Activity: 630
Merit: 187



View Profile
July 31, 2026, 09:57:14 AM
 #41


The address I'm writing about is bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.

You didn't steal from a wallet.

You stole from a family

Naah, I will never let this pass me, what a sad story to read, oh my God, I can never imagine saving my Bitcoin for years only to lost it this way? I would die even though I don't have kid yet, I hope the hacker who did this reconsider this address atleast.

He is right that some Bitcoin holders aren't rich, they are only trying to build a better future for their family,  it is on this same journey that I'm setting up for myself, this is making me cry already, I chose to not steal but rather work my way up, I don't know why people do this.

Someone's life is at stake here, what will be the fate of that boy who needs surgery in the nearest future? This is making me very angry right now, I'm not even sure that someone who did this will be on here, but I hope so.

It's also good that moderators made it available at the face front of the forum, I am sorry for your loss whoever you are, I wish I can help one way or the other.


ColdCardVictim I can't promise that you will get help here, if nothing comes up please try to contact @ZachXBT on twitter maybe he can help, this guy has helped recovered some lost and stolen Bitcoin back in the past, and for the sake of your son I think you need gofundme or something similar to raise funds, I can be a part contributor if this is possible.

If you are reading this, I will suggest you sign some message on that Bitcoin address just to prove that it truly belongs to you.

Here is how to sign message if you don't know.


May the Lord's help shine upon you and your Family.
Pls be strong.

Italian Panic
Hero Member
*****
Offline

Activity: 1092
Merit: 735


NO DEPO CODE VEGAR7, NO KYC Casino


View Profile WWW
July 31, 2026, 10:06:25 AM
Last edit: July 31, 2026, 01:48:34 PM by Italian Panic
Merited by LoyceV (4), hosemary (1), OcTradism (1)
 #42

A video from two years ago has resurfaced in which this bloke warned about the ColdCard system and its vulnerabilities.

https://www.youtube.com/watch?v=oj_W3xOlt6U

Yesterday’s attack targeted the ColdCard Mk3 (40 bit), but this video also highlights issues with the Mk4 (72 bit).


██████
██
██

████████████████
███████████████
█████████████
█████████████▄▄████▄▄████▄▄███████▌██▄▄████▄██
████████████▄██▀▀▀▀██▄██▄███▀███████▄██▀▀▀▀███
██████████▐██▄▄▄▄▄▄██▌▐██▀███████▌▐███████▐██
████████████▐██▀▀▀▀▀▀▀▀▐██▄███████▌▐██▄████▐██
█████████████▀██▄▄▄▄█████▀███▄▄▄██▀██▀██▄▄▄▄███
██████████████▀▀▀▀▀▀██████▀▀▀▀▀▀▄▌███▀▀▀▀▀▀▀
████████████████████████████▄███▄██
███████████████████████████▀█████▀










██
██
██████
▄▄███████▄▄
▄███████████████▄
▄███████████████████▄
▄█████████████████████▄
▄███████████████████████
████████████████████████
█████████████████████████
████████████████████████
▀███████████████████████▀
█████████████████████▀
▀███████████████████▀
▀███████████████▀
▀▀███████▀▀
 
  150 FS NO DEPOSIT BONUS ..... Subscribe to Our Telegram ( > ) .....   PLAY NOW   
OcTradism
Legendary
*
Offline

Activity: 2548
Merit: 1029



View Profile
July 31, 2026, 10:32:27 AM
 #43

A video from two years ago has resurfaced in which this bloke warned about the ColdCard system and its vulnerabilities.

https://www.youtube.com/watch?app=desktop&v=oj_W3xOlt6U&ra=m

Yesterday’s attack targeted the ColdCard Mk3 (40 bit), but this video also highlights issues with the Mk4 (72 bit).
The security advice is choosing wallets with 128 bits of entropy or 256 bits of entropy. Honestly, if you did not post it, I did not know that Coldcard has such terrible security vulnerability because of that firmware update according to the two reports on OP.

I don't understand it technically deeply about this hack, how attackers do that technically but it's surprising me as there were warnings at least from the video you shared, and it's two years ago.

I remember I read about importance of entrophy in the wallet seed phrase.
https://github.com/bitcoinbook/bitcoinbook/blob/develop/ch05_wallets.adoc
Quote
For an attacker who needs to guess a user’s entire recovery code, the length of the code (128 bits at a minimum) provides more than sufficient security.

https://learnmeabitcoin.com/beginners/security/
Quote
Should you use a 12 or 24 word seed? #
A 12 word seed is perfectly fine.

You can use a 24-word seed if you wish (or if it's your only option), but you're not compromising on security in any practical way by using a 12-word seed.
The two different seed phrase sizes contain the following bits of entropy:

12 words = 128 bits
24 words = 256 bits

ColdcardVictim
Newbie
*
Offline

Activity: 5
Merit: 119


View Profile
July 31, 2026, 11:19:26 AM
 #44

What makes this even harder for me is that I tried to speak about what happened before, and my previous topic was deleted. Whether there was a legitimate reason or not, it left me feeling like I had no voice.

Maybe it's just a coincidence. Maybe I'm reading too much into it. But when you've just lost years of savings, it's difficult not to question everything.

This forum is one of the largest Bitcoin communities in the world. If the person responsible for taking my coins is active anywhere, there's a chance they've visited this forum or will someday. That's why I wanted my message to exist here.

I'm not accusing anyone on this forum. I have no evidence to do that. I just wanted there to be a chance that the person who now controls those coins might eventually read the words of the family they affected.
Lost 1.8 BTC due to ColdCard https://bitcointalk.org/index.php?topic=5589972.0
LoyceV
Legendary
*
Offline

Activity: 4116
Merit: 22390


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
July 31, 2026, 12:02:28 PM
Merited by Zwei (1)
 #45

This inconsistency makes the coldcard firmware not use its own HWRNG support code but instead call the micropython random function.
At a n00b on firmware, it's shocking to read a firmware update can change such basic functionality. I guess it makes sense, without firmware no working hardware wallet, but still....

I've never owned a Coldcard, but have used hardware wallets. One of the things I dislike about them is the "black box" feeling it gives me: I have no idea what it's doing in there, and I basically have to trust the manufacturer (and some reviewers). And "trusting" is what I don't like when it comes to Bitcoin.

What makes this even harder for me is that I tried to speak about what happened before, and my previous topic was deleted. Whether there was a legitimate reason or not, it left me feeling like I had no voice.
Your first topic was probably deleted because you posted it on the Development & Technical Discussion board, where it doesn't belong.

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
satscraper
Legendary
*
Offline

Activity: 1540
Merit: 2867



View Profile
July 31, 2026, 12:07:13 PM
 #46

They confirmed that this compromise was possible due to low-entropy values generated by the MK3 model, an issue that "is present on every Mk3 firmware version since 4.0.1". In response to this they urgently released new firmware, namely v5.6.0 for MK4 and MK5 as well as v1.5.0Q for Q model. These are all mandatory updates.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
twiki
Member
**
Offline

Activity: 195
Merit: 56


View Profile
July 31, 2026, 12:07:54 PM
 #47

Is polymerbit also a Cold type of ring? Should I be afraid?
BlackBoss_
Hero Member
*****
Offline

Activity: 1442
Merit: 693


Rollbit is for you. Take $RLB token!


View Profile
July 31, 2026, 12:16:16 PM
Merited by ColdcardVictim (10)
 #48

This forum is one of the largest Bitcoin communities in the world. If the person responsible for taking my coins is active anywhere, there's a chance they've visited this forum or will someday. That's why I wanted my message to exist here.

I'm not accusing anyone on this forum. I have no evidence to do that. I just wanted there to be a chance that the person who now controls those coins might eventually read the words of the family they affected.
Lost 1.8 BTC due to ColdCard https://bitcointalk.org/index.php?topic=5589972.0
It is your hope that I can understand, if I had fallen into such situation like you did, I would have made my terrible action already but please stay strong and fight because you have your family behind to take care of them and surely they are really ready to take care of you, share the pain and loss you have now.

About the attacker(s), I don't know, maybe they visited the forum or will do it in the future, but honestly even I wish the best for you, I don't believe that such people will be ready to do the right things like returning bitcoins they hacked to victims including you. If they were good people, they would not do that already.

Will hackers behind this again come from North Korea like Lazzarus, let's wait for investigation and results later.

Quote
If you have a draft of that thread, you can make a new one in another board.
Hardware wallets

If you did not save it on your computer, you can find it in your draft page https://bitcointalk.org/index.php?action=drafts

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT|
4,000+ GAMES
███████████████████
██████████▀▄▀▀▀████
████████▀▄▀██░░░███
██████▀▄███▄▀█▄▄▄██
███▀▀▀▀▀▀█▀▀▀▀▀▀███
██░░░░░░░░█░░░░░░██
██▄░░░░░░░█░░░░░▄██
███▄░░░░▄█▄▄▄▄▄████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
█████████
▀████████
░░▀██████
░░░░▀████
░░░░░░███
▄░░░░░███
▀█▄▄▄████
░░▀▀█████
▀▀▀▀▀▀▀▀▀
█████████
░░░▀▀████
██▄▄▀░███
█░░█▄░░██
░████▀▀██
█░░█▀░░██
██▀▀▄░███
░░░▄▄████
▀▀▀▀▀▀▀▀▀
||.
|
▄▄████▄▄
▀█▀
▄▀▀▄▀█▀
▄░░▄█░██░█▄░░▄
█░▄█░▀█▄▄█▀░█▄░█
▀▄░███▄▄▄▄███░▄▀
▀▀█░░░▄▄▄▄░░░█▀▀
░░██████░░█
█░░░░▀▀░░░░█
▀▄▀▄▀▄▀▄▀▄
▄░█████▀▀█████░▄
▄███████░██░███████▄
▀▀██████▄▄██████▀▀
▀▀████████▀▀
.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
░▀▄░▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄░▄▀
███▀▄▀█████████████████▀▄▀
█████▀▄░▄▄▄▄▄███░▄▄▄▄▄▄▀
███████▀▄▀██████░█▄▄▄▄▄▄▄▄
█████████▀▄▄░███▄▄▄▄▄▄░▄▀
███████████░███████▀▄▀
███████████░██▀▄▄▄▄▀
███████████░▀▄▀
████████████▄▀
███████████
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▀▄███░░░▀████░███▄▀██▄
███░████░░░░░▀██░████░███
███░████░█▄░░░░▀░████░███
███░████░███▄░░░░████░███
▀██▄▀███░█████▄░░███▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
OFFICIAL PARTNERSHIP
SOUTHAMPTON FC
FAZE CLAN
SSC NAPOLI
KiaKia
Hero Member
*****
Offline

Activity: 1470
Merit: 624


Rainbet


View Profile WWW
July 31, 2026, 12:42:23 PM
Merited by Antidote47k (4)
 #49

If you are using Trezor or Keystone you should be fine, I contacted the team to talk about the breach, I even accused keystone team on x why they remained silent lol.

I can still remember very clearly when I set up my Keystone 3 for the first time, I meant this similar option in the op picture below.



I went with the Keystone SEs entropy, it is still secured enough because it uses two SEs to generates it's entropy and combine them to boost the randomness.

Still, Dice rolls like 99 times is more superior.

Unlike some bitcoin hardware wallets out there, my regards go out to everyone who is affected, that's a lot of Bitcoin, something around 40 million, man I just hope that Coldcard can make something happen.

fillippone
Legendary
*
Online Online

Activity: 2968
Merit: 21157


Duelbits.com - Rewarding, beyond limits.


View Profile WWW
July 31, 2026, 12:47:29 PM
Merited by OmegaStarScream (5), vapourminer (4), Pmalek (3), PrivacyG (2), philipma1957 (1), alexrossi (1), Zwei (1), Ambatman (1), Filicius (1)
 #50

What I find interesting here is not so much the vulnerability itself, but what this tells us about Bitcoin security in the age of AI.

Bitcoin itself is probably one of the most reviewed pieces of open-source software in the world. But the Bitcoin ecosystem is much bigger than Bitcoin Core. Wallets, hardware devices, firmware, libraries, exchanges, signing tools… there is a huge amount of code around Bitcoin, and obviously not all of it has received the same level of scrutiny.

And I think AI changes the game quite a bit here.

Until recently, going through a large and unfamiliar codebase looking for some obscure weakness required a lot of time and some pretty specialised skills. It still does, of course, but AI can make that process much faster. You can analyse more code, follow dependencies, spot strange patterns and test ideas at a scale that simply wasn’t realistic before.

What worries me most is old code.

We tend to think that if something has been around for 5 or 10 years without being hacked, it must be reasonably safe. But that’s not necessarily true. Maybe the vulnerability was always there and it simply wasn’t worth the enormous amount of work required to find it.

AI changes that calculation.

Of course, defenders have access to exactly the same tools, and hopefully this means we will see much more AI-assisted auditing of wallets, firmware and other Bitcoin infrastructure.

But attackers only need to find one forgotten piece of code protecting enough money to make the effort worthwhile.

So I don’t think the real question is whether AI can somehow “break Bitcoin”. That’s probably the wrong way to look at it.

The more interesting question is how much vulnerable code is still sitting somewhere in the Bitcoin ecosystem, considered safe mainly because nobody has managed to find the bug yet.

My guess is that over the next few years we’re going to find out. In a brutal way, probably.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits PREDICT..
█████████████████████████
█████████████████████████
███████████▀▀░░░░▀▀██████
██████████░░▄████▄░░████
█████████░░████████░░████
█████████░░████████░░████
█████████▄▀██████▀▄████
████████▀▀░░░▀▀▀▀░░▄█████
██████▀░░░░██▄▄▄▄████████
████▀░░░░▄███████████████
█████▄▄█████████████████
█████████████████████████
█████████████████████████
.
.WHERE EVERYTHING IS A MARKET..
█████
██
██







██
██
██████
Will Bitcoin hit $200,000
before January 1st 2027?

    No @1.15         Yes @6.00    
█████
██
██







██
██
██████

  CHECK MORE > 
ColdcardVictim
Newbie
*
Offline

Activity: 5
Merit: 119


View Profile
July 31, 2026, 12:54:38 PM
Merited by sunsilk (1)
 #51

This forum is one of the largest Bitcoin communities in the world. If the person responsible for taking my coins is active anywhere, there's a chance they've visited this forum or will someday. That's why I wanted my message to exist here.

I'm not accusing anyone on this forum. I have no evidence to do that. I just wanted there to be a chance that the person who now controls those coins might eventually read the words of the family they affected.
Lost 1.8 BTC due to ColdCard https://bitcointalk.org/index.php?topic=5589972.0
It is your hope that I can understand, if I had fallen into such situation like you did, I would have made my terrible action already but please stay strong and fight because you have your family behind to take care of them and surely they are really ready to take care of you, share the pain and loss you have now.

About the attacker(s), I don't know, maybe they visited the forum or will do it in the future, but honestly even I wish the best for you, I don't believe that such people will be ready to do the right things like returning bitcoins they hacked to victims including you. If they were good people, they would not do that already.

Will hackers behind this again come from North Korea like Lazzarus, let's wait for investigation and results later.

Quote
If you have a draft of that thread, you can make a new one in another board.
Hardware wallets

If you did not save it on your computer, you can find it in your draft page https://bitcointalk.org/index.php?action=drafts


Thank you very much for your kind words. They genuinely mean a lot to me.

You're probably right. Someone willing to steal life savings is unlikely to suddenly have a change of heart. Still, I felt that if there was even the smallest chance my message could reach them, it was worth trying. I think I would have regretted staying silent more than writing the post.

My family is the reason I'm still fighting. There are days when this feels overwhelming, but giving up isn't an option. I have to keep moving forward for my son.

I also appreciate you mentioning the drafts page and suggesting I repost it in the Hardware Wallets board. I'll definitely check if I still have a copy there. Thank you for taking the time to read my story and for offering both your encouragement and practical advice. I truly appreciate it.
suzanne5223
Hero Member
*****
Offline

Activity: 3388
Merit: 747


Want top-notch marketing for your brand, Hire me


View Profile WWW
July 31, 2026, 12:57:28 PM
Last edit: July 31, 2026, 01:24:28 PM by suzanne5223
 #52

It's very concerning, I see Coldcard wallet is recommended by Jameson Lopp on his blog too.
https://www.lopp.net/bitcoin-information/recommended-wallets.html
Quote
~
Will it be time for him to remove Coldcard from his Recommended wallets list?

Ledger should also be removed because of that seed phrase recovery update they introduced some time ago.
Yes, this is why we should never rely on a list provided by reputable people at times, since the list is not updated in real timetime, because the wallet was provided years ago, before Ledger abused people's trust and Coldcard changed their firmware.
i believe it's better to not complicate things and just go for air-gapped Electrum to save ourselves from future trouble, since there's also information flying around about the scam Sparrow wallet on the Apple Store.
https://x.com/VandelayBTC/status/2082920858234843368?s=20

▄▄███████████████████▄▄
▄███████████████████████▄
███████████████████████
████████▀▀▀▀██▀█▄▀███████
███▀▀██▄▄██▄██▌▄▄▄▄▄██
████▄█████▐██▀▄█▀▀█████
█████▌██▀▀▄█▀██▄██▄███
██▄▄▄▄███████████▐███████
████████▐█████████▀▀█████
███████▄██████▀█▄▄▄▄▄████
███████████████████████

▀███████████████████████▀
▀▀███████████████████▀▀

 Kings Game  
 
 🎰   🎲   ⚽ 
████
██
██
██
██
██
██
██
██
██
██
██
████
████████████████████████████


RAKEBACK
..UP TO 30%..
████████████████████████████
████
██
██
██
██
██
██
██
██
██
██
██
████
████
██
██
██
██
██
██
██
██
██
██
██
████
████████████████████████████
 
..500%..
WELCOME BONUS
+ 250 FREE SPINS
████████████████████████████
████
██
██
██
██
██
██
██
██
██
██
██
████

   WIN NOW     
Italian Panic
Hero Member
*****
Offline

Activity: 1092
Merit: 735


NO DEPO CODE VEGAR7, NO KYC Casino


View Profile WWW
July 31, 2026, 01:03:00 PM
 #53

Is polymerbit also a Cold type of ring? Should I be afraid?

Polymerbit was made by italian and uses keys generated offline and printed on a sort of polymer banknote with a holographic layer. I don’t see any issues if you trust the people who created them, if you trusted them before, you can continue to do so.

It’s very likely that whoever carried out this attack used advanced AI agent to scrape the Coldcard firmware, found the bug, and trained another agent to carry out the attack. So now we should expect all wallets to be combed through by agents created by malicious hackers to find other bugs.

In the coming weeks, there will be a flood of requests for updates to existing wallets, patches, upgrades, phone calls, emails… pay close attention.

██████
██
██

████████████████
███████████████
█████████████
█████████████▄▄████▄▄████▄▄███████▌██▄▄████▄██
████████████▄██▀▀▀▀██▄██▄███▀███████▄██▀▀▀▀███
██████████▐██▄▄▄▄▄▄██▌▐██▀███████▌▐███████▐██
████████████▐██▀▀▀▀▀▀▀▀▐██▄███████▌▐██▄████▐██
█████████████▀██▄▄▄▄█████▀███▄▄▄██▀██▀██▄▄▄▄███
██████████████▀▀▀▀▀▀██████▀▀▀▀▀▀▄▌███▀▀▀▀▀▀▀
████████████████████████████▄███▄██
███████████████████████████▀█████▀










██
██
██████
▄▄███████▄▄
▄███████████████▄
▄███████████████████▄
▄█████████████████████▄
▄███████████████████████
████████████████████████
█████████████████████████
████████████████████████
▀███████████████████████▀
█████████████████████▀
▀███████████████████▀
▀███████████████▀
▀▀███████▀▀
 
  150 FS NO DEPOSIT BONUS ..... Subscribe to Our Telegram ( > ) .....   PLAY NOW   
LoyceV
Legendary
*
Offline

Activity: 4116
Merit: 22390


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
July 31, 2026, 01:25:27 PM
 #54

From Reddit:
Quote
All the affected addresses contained more that 0.15 BTC at the time of the transactions.
~
Theft address has consolidated most of the funds in bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.
I checked this address, and the 0.15 BTC threshold seems to be correct. I expect the number of addresses holding lower amounts to be much larger than the currently swept addresses, and I expect a brute-force weak key attacker to already know the keys to those addresses. So that brings the question: why leave anything under $9500 untouched? I've never seen that before in any hack!

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
EstherBtc
Jr. Member
*
Offline

Activity: 49
Merit: 7


View Profile
July 31, 2026, 01:29:35 PM
 #55


https://x.com/COLDCARDwallet/status/2083155034762621425

Coldcard posted this on their official page on X.com. comments surrounding this tweet suggests they should send this to the emails of those who have bought from them others are saying they should refund the victims and shut down.

My heart goes to all those who are victims of this. Please stay strong.

Lucius
Legendary
*
Offline

Activity: 4046
Merit: 7665



View Profile WWW
July 31, 2026, 01:29:59 PM
 #56

~snip~
1. I assume wallets that use a passphrase are safe from these attacks because seed-phrase-hunters have no way of knowing a seed phrase generating an empty wallet has coins in a wallet using that seed with a passphrase.


A lesson I learned a long time ago and the only one that makes sense without requiring the user to be technically advanced. No matter what hardware someone uses, they should always additionally protect their seed with a passphrase that is complicated enough to withstand any brute force attack.

3. I assume it's only a matter of time before Ledger's key extraction scheme gets hacked, presumably at the firmware level. That'll be a much more difficult hack to pull off, but it'll be much worse than this ColdCard hack because Ledger is a huge honeypot.

It's going to be a shitshow of epic proportions, no doubt about it. A company that has repeatedly shown that it is incapable of protecting its clients' data is perfect as a potential target for countless hackers.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits PREDICT..
█████████████████████████
█████████████████████████
███████████▀▀░░░░▀▀██████
██████████░░▄████▄░░████
█████████░░████████░░████
█████████░░████████░░████
█████████▄▀██████▀▄████
████████▀▀░░░▀▀▀▀░░▄█████
██████▀░░░░██▄▄▄▄████████
████▀░░░░▄███████████████
█████▄▄█████████████████
█████████████████████████
█████████████████████████
.
.WHERE EVERYTHING IS A MARKET..
█████
██
██







██
██
██████
Will Bitcoin hit $200,000
before January 1st 2027?

    No @1.15         Yes @6.00    
█████
██
██







██
██
██████

  CHECK MORE > 
knuckey
Sr. Member
****
Offline

Activity: 1610
Merit: 273



View Profile
July 31, 2026, 01:32:07 PM
 #57

It seems that Coldcard users have not been fully proven to be affected by the Ill Bloom vulnerability, but because there are several users affected, Coldcard's name is dragged, however, anyone who uses Coldcard here, especially those who use it before 2026, must remain vigilant, for the sake of bitcoin security, it is better to move everything to a new wallet until the origin of this theft problem is known.

Coldcard confirmed the vulnerability: https://x.com/COLDCARDwallet/status/2082961993070247948
A quick discovery. COLDCARD has also prepared a migration guide to a safer one. It's best to do this as soon as possible or move to another wallet first. Don't use COLDCARD temporarily. Although they say Mk4, Q, and Mk5 won't affect it, it could be risky.

I've never encountered a problem like this before. My question is, will COLDCARD cover the losses?

████
██









██
████



███████████████▄▄███████████████▄███████████████▄█████████████████████████████▄
███████████████████████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████████████████████████
█████████████████████████████████████████████████████████████████████████████████
█████████████████████████████████████████████████████████████████████████████████████▄█████▄█████▄███████▄
███████████████████████████████████████████████████████████████████████████████████████████████████████
███████████████▀▀███████████████▀███████████████▀████████████████████████████████▀█████▀█████▀██████
████
██









██
████
████
██









██
████

🍒
████
██









██
████
████
██









██
████

⚽️
████
██









██
████
████
██









██
████
 
 IIIIIFASTEST GROWING CASINO & SPORTSBOOK  [ Play Now ]
████
██









██
████
flatfly (OP)
Legendary
*
Offline

Activity: 1288
Merit: 1258

Joined: 2012


View Profile
July 31, 2026, 01:57:35 PM
 #58

There are fresh reports of wallet sweeps on CT.

Move your coins off Coldcard vulnerable addresses ASAP.

Did you know? Counterparty is still alive! It's the Bitcoin-native DEX with a fascinating history, running with zero downtime since 2014.
fillippone
Legendary
*
Online Online

Activity: 2968
Merit: 21157


Duelbits.com - Rewarding, beyond limits.


View Profile WWW
July 31, 2026, 02:03:25 PM
Merited by vapourminer (1), Lucius (1)
 #59

I've never seen that before in any hack!

The attacker has swept addresses, not UTXO, holding more than 0.15 BTC.
As had an address-balance index, not a UTXO set, aggregating balances per address requires a separate indexing layer: an Electrum node, a blockchain API, or a public dataset dump. That's a real infrastructure commitment (a full address index is on the order of a terabyte and takes days to sync), or a third-party dependency (which is very improbable for obvious opsec reasons).

The target list was built in batches well before execution: you don't aggregate address balances across the chain within a 15-minute window.

A strange consequence is that taking the small outputs inside the address that had accumulated 200 UTXOs costs him a fee and blockspace for negligible value. He did it anyway because his unit of work was the address. That's deliberate engineering, or bad engineering.

An idea is that 0.15 may not be a chosen parameter at all. If he sorted candidates by balance descending and truncated at the top N, the floor is simply wherever the last one landed. The sweep ran across exactly 500 transactions, a very round number. If the count is 500, the binding constraint was target count, not index size, and 0.15 is simply a consequence.

The remaining addresses are not safe. Suspect the attacker could launch a second wave of attacks, targeting the remaining unsecured balances. He surely already has all the keys; he just needs to run the script again.

To me, this screams AI engineered tools to swipe the balances.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits PREDICT..
█████████████████████████
█████████████████████████
███████████▀▀░░░░▀▀██████
██████████░░▄████▄░░████
█████████░░████████░░████
█████████░░████████░░████
█████████▄▀██████▀▄████
████████▀▀░░░▀▀▀▀░░▄█████
██████▀░░░░██▄▄▄▄████████
████▀░░░░▄███████████████
█████▄▄█████████████████
█████████████████████████
█████████████████████████
.
.WHERE EVERYTHING IS A MARKET..
█████
██
██







██
██
██████
Will Bitcoin hit $200,000
before January 1st 2027?

    No @1.15         Yes @6.00    
█████
██
██







██
██
██████

  CHECK MORE > 
goldkingcoiner
Legendary
*
Offline

Activity: 2856
Merit: 3059


HoDL


View Profile WWW
July 31, 2026, 02:08:32 PM
 #60

https://x.com/Rob1Ham/status/2082896614218203616

[EDIT]

Vendor advisory post:
https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/

Technical deep dive:
https://blog.coinkite.com/entropy-technical-backgrounder/


From Reddit:

Quote
Hoax__

It doesn't appear to be an isolated theft. The receiving address 'bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0' has received about 594 BTC (approx $37.8M) from 500 different addresses in a 15 min window (between 01:31-01:56 UTC 30/07/26). Many of the other sending addresses have been dormant for years, similar to your address. All the affected addresses contained more that 0.15 BTC at the time of the transactions.

The only way to issue a sending transaction is to have the associated private key/seed phrase. For the volume of address suspected to be compromised there could be two potential attack vectors. Either be a supply chain attack, when the hardware device purchased was compromised. Or it could be a cryptographic flaw within the hardware device where the device generates users seed phrases in such a way that an attacker could predict them, similar to the Ill Bloom vulnerability from earlier in the month.

Theft address has consolidated most of the funds in bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.

Oh wow. I get the feeling that nothing, not even hardware wallets are 100% safe in this world. And that is unfortunately the reality that we live in, meaning nothing is every definitely safe. Safe from being stolen, safe from being broken.... All just illusions.

The only safety one can rely on is onself. But then again it is the self that betrays by forgetting, getting lazy or simply making a dumb human error.

I hope the thief gets caught though. If there is something I believe in, it is justice/karma.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits PREDICT..
█████████████████████████
█████████████████████████
███████████▀▀░░░░▀▀██████
██████████░░▄████▄░░████
█████████░░████████░░████
█████████░░████████░░████
█████████▄▀██████▀▄████
████████▀▀░░░▀▀▀▀░░▄█████
██████▀░░░░██▄▄▄▄████████
████▀░░░░▄███████████████
█████▄▄█████████████████
█████████████████████████
█████████████████████████
.
.WHERE EVERYTHING IS A MARKET..
█████
██
██







██
██
██████
Will Bitcoin hit $200,000
before January 1st 2027?

    No @1.15         Yes @6.00    
█████
██
██







██
██
██████

  CHECK MORE > 
Pages: « 1 2 [3] 4 5 6 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!