Bit-Mj1014
Jr. Member

Activity: 110
Merit: 2
|
 |
July 31, 2026, 05:45:44 PM |
|
Seeing a massive sweep like this is just brutal. My heart goes out to anyone who got hit by this. It really shakes your confidence in the hardware we rely on. I'm trying to wrap my head around the technical side did this only affect people who relied on the internal setup, or are people who used manual dice rolls safe? https://blog.coinkite.com/entropy-technical-backgrounder/
|
|
|
|
|
|
Meuserna
|
This would hurt more than we might expect
The trust associated with cold storage, airgapped and the likes is strained
Now many would have to reconsider and ask how sure are they that their funds are really safe.
Random generator is only random till it isn't.
Seedphrase with great entropy was okay then now we need paraphrase, multisig
And don't place all your coins in one basket ( Which should be common knowledge by now)
At the end, Nothing is truly safe.
The cost and lesson from this vulnerability is very much expensive
And not the first time we having issues with seedphrase generator with claimed randomness.
I guess Randomness is the foundation and When it fails air-gaps, metal backups, multiple Backup cannot fully save you.
Here's what's safe: 1. Generate your own seed and do it right. 100 dice rolls, or, do it manually using something like Entropia Tablets (a jar filled with seed words printed on pill-shaped plastic). You'll need a hardware wallet to generate the final word (the checksum). This isn't a security issue since the last word for a 24 word seed phrase will be one of 7 or 8 words that can mathematically form a valid checksum. Generating your own seed means there's no chance borked code can cause your seed phrase to be vulnerable. 2. Write your words on paper. Make a metal backup. Store those items somewhere only you have access to. 3. Use a passphrase or multisig. As seed phrase hunters churn through billions of seeds, if they generate and test yours, they'll never know because your seed by itself generates a wallet that's never been used. If you're using a passphrase, write it on paper. Make a metal backup. Store it separately from where you store your seed. If you're doing multisig, document your work every step of the way and store that separately from your seeds. 4. Get a fully open source hardware wallet that is stateless and airgapped. I recommend ShieldSigner, which is a SeedSigner fork that adds encrypted Seed QR, passphrase QR, and smartcard compatibility, among many other features. Stateless means your seed isn't saved on the device. If the device gets stolen, no worries. There's nothing on it. Airgapped means the device cannot connect to the internet. Online hackers can't reach it. 5. Test everything before sending coins to your wallet. The easiest way to do this is by saving the first address generated by the wallet (better yet, save the _pub). Then wipe out the wallet and rebuild it from scratch using the seed phrase and passphrase or multisig seeds you wrote down. If the wallet you just generated has the exact same first address or _pub, you're golden. You just proved it's correct, and you proved you know how to restore your wallet in a worst case scenario. I know this sounds like a lot, but it's really not hard. Self custody comes with self responsibility. Your security is your job. It has to be done right.
|
|
|
|
Smack That Ace
Legendary

Activity: 2576
Merit: 1141
Assalamu Alekum from Pakistan ~ 🇵🇰
|
 |
July 31, 2026, 06:13:52 PM |
|
I sold about 30% of my coins today.
wth, do you really think AI can crack private key? This Coldcard issue or any of the recent exploits have nothing to do with AI "breaking safety measure". In most cases, these are caused by our errors. Maybe supply chain attack or firmware vulnerabilities or bad implementation. AI is just a tool, I dont think it can brute-force an ECDSA private key, at least with current technology. No, I do not think AI “cracked” Bitcoin private keys or broke ECDSA. A properly generated 256-bit private key remains computationally out of reach. The possible role of AI is completely different. AI could have helped an attacker review the publicly available firmware, trace the seed-generation code, identify that the wallet was producing seeds from a drastically reduced entropy space, and then assist in writing or optimizing the tools needed to exploit that flaw. This is probably what is called panic selling  . philipma1957 may have been scared by some of the snarky comments from some users in this thread and sold 30% of his holdings. Anyway, if any of you have such weak faith in Bitcoin that a sudden threat would make you panic and sell, then Bitcoin is probably not for you in the long term. Bitcoin's protocol & consensus mechanism is 100% intact. So I would definitely not sell my hard money for weak fiat just out of fear of hypothetical AI attacks.
|
|
|
|
Mia Chloe
Legendary

Activity: 1148
Merit: 2255
Contact me for your designs...
|
 |
July 31, 2026, 06:15:58 PM |
|
~snip
The whole stuff is really messy I've been reading on it for a while now and it's crazy how everything gets less and less safe every damn day. At this point it's so bad that you can't even trust hardware related storages anyone to the fullest. To a huge extent it seems paper backups remain the best. As for the AI talk I don't think there's any direct relationship at the moment however if it turns out to be a quantum related attack they you might be able to link it to AI.
|
|
|
|
NotATether
Legendary

Activity: 2408
Merit: 10020
┻┻ ︵㇏(°□°㇏)
|
 |
July 31, 2026, 06:23:24 PM |
|
Updated total drained: 1082.65 BTC
Jeez. The guy doing this must be 5-star wanted by now. There's going to be a huge manhunt for sure once they trace the bitcoins.
|
|
|
|
OmegaStarScream
Staff
Legendary

Activity: 4284
Merit: 7496
|
 |
July 31, 2026, 06:46:57 PM |
|
There's going to be a huge manhunt for sure once they trace the bitcoins.
Someone at Bitkey tweeted this earlier: https://x.com/clay_garrett/status/2083247006139503065I don't see how would someone make this mistake... but one can only hope that the account in question is linked to the exploiter's identity.
|
|
|
|
LittleBitFunny
Full Member
 

Activity: 1428
Merit: 130
little little bit
|
 |
July 31, 2026, 07:27:18 PM |
|
I do not need too much exposure in the space. I sold about 30% of my coins today.
I am really scared after reading this thread.  Especially when philipma1957 said that he has already sold his 30% holding, it makes me even more scared. Can anyone please tell me if my funds in the Electrum wallet are safe, or should I move my funds from Electrum now? If not, then could this same incident happen to Electrum wallet users in future?
|
|
|
|
OgNasty
Donator
Legendary

Activity: 5544
Merit: 6432
Leading Crypto Sports Betting & Casino Platform
|
 |
July 31, 2026, 07:34:25 PM |
|
I feel really bad for anyone affected by this. Users protecting their funds with cold storage only to have them stolen like this is a worst case scenario. It would be great if some of the people draining these wallets were caught and funds recovered for victims. I assume most is ending up in mixers though…
|
| ..Stake.com.. | | | ▄████████████████████████████████████▄ ██ ▄▄▄▄▄▄▄▄▄▄ ▄▄▄▄▄▄▄▄▄▄ ██ ▄████▄ ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██ ██████ ██ ██████████ ██ ██ ██████████ ██ ▀██▀ ██ ██ ██ ██████ ██ ██ ██ ██ ██ ██ ██████ ██ █████ ███ ██████ ██ ████▄ ██ ██ █████ ███ ████ ████ █████ ███ ████████ ██ ████ ████ ██████████ ████ ████ ████▀ ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██ ██ ▀▀▀▀▀▀▀▀▀▀ ██ ▀█████████▀ ▄████████████▄ ▀█████████▀ ▄▄▄▄▄▄▄▄▄▄▄▄███ ██ ██ ███▄▄▄▄▄▄▄▄▄▄▄▄ ██████████████████████████████████████████ | | | | | | ▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄ █ ▄▀▄ █▀▀█▀▄▄ █ █▀█ █ ▐ ▐▌ █ ▄██▄ █ ▌ █ █ ▄██████▄ █ ▌ ▐▌ █ ██████████ █ ▐ █ █ ▐██████████▌ █ ▐ ▐▌ █ ▀▀██████▀▀ █ ▌ █ █ ▄▄▄██▄▄▄ █ ▌▐▌ █ █▐ █ █ █▐▐▌ █ █▐█ ▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█ | | | | | | ▄▄█████████▄▄ ▄██▀▀▀▀█████▀▀▀▀██▄ ▄█▀ ▐█▌ ▀█▄ ██ ▐█▌ ██ ████▄ ▄█████▄ ▄████ ████████▄███████████▄████████ ███▀ █████████████ ▀███ ██ ███████████ ██ ▀█▄ █████████ ▄█▀ ▀█▄ ▄██▀▀▀▀▀▀▀██▄ ▄▄▄█▀ ▀███████ ███████▀ ▀█████▄ ▄█████▀ ▀▀▀███▄▄▄███▀▀▀ | | | ..PLAY NOW.. |
|
|
|
Karl_3000
Full Member
 

Activity: 364
Merit: 186
Bitcoin can not fail you
|
 |
July 31, 2026, 07:40:49 PM |
|
Can anyone please tell me if my funds in the Electrum wallet are safe, or should I move my funds from Electrum now?
Electrum users are not affected, only some Coldcard users were affected. If not, then could this same incident happen to Electrum wallet users in future?
Create a new wallet on Electrum but with a passphrase that will be difficult to brute force. It is better you have your bitcoin on more wallets instead of one. I am not talking about more wallets of the same wallet brand but I am talking about more wallet on different wallet brands that are good and trustworthy with passphrase.
|
|
|
|
Ayers
Legendary

Activity: 3178
Merit: 1055
will trade PGP for Bitcoin...
|
 |
July 31, 2026, 07:45:33 PM |
|
I am really scared after reading this thread.  Especially when philipma1957 said that he has already sold his 30% holding, it makes me even more scared. Can anyone please tell me if my funds in the Electrum wallet are safe, or should I move my funds from Electrum now? No, Electrum software wallet is not affected by this issue. However whether you need to move your fund depends on where your wallet's seed phrase was generated. This thread is about a specific seed generation/entropy security issue with Coldcard hardware wallet. It is not about Electrum software wallet. If you have generated your seed phrase directly within the Electrum software, your funds are not at risk. However, if you are using a Coldcard hardware wallet and are using Electrum as watch-only software then you should immediately transfer your funds to a new and secure seed phrase. If not, then could this same incident happen to Electrum wallet users in future?
I don't know about the future, but using a multisig setup might be a good solution.
|
|
|
|
|
Myleschetty
|
 |
July 31, 2026, 07:46:18 PM Last edit: July 31, 2026, 07:59:16 PM by Myleschetty |
|
Everyone affected should not throw away or smash their Coldcard devices is here why. https://x.com/zherbert/status/2083261221726220638?s=20I feel really bad for anyone affected by this. Users protecting their funds with cold storage only to have them stolen like this is a worst case scenario. It would be great if some of the people draining these wallets were caught and funds recovered for victims. I assume most is ending up in mixers though…
Yes, it's a depressing experience to use various methods to accumulate BTC for months or years only for someone to come and steal it, but it also serves as an eye-opener that using a passphrase or multisig should be our top priority. According to what I read about the attack, the funds in the wallet that used it are safe
|
|
|
|
|
|
Mahiyammahi
|
 |
July 31, 2026, 08:05:39 PM |
|
Sorry, but I couldn't understand what the bug itself is and how they manage to steal the coins Can they find out the seeds of the addresses? But how do you know, what are the addresses generated by this wallet? Anyway, I still can't quite understand how this situation works...  There was a serious bug in the device's or software's RNG. As a result it does not generate completely random numbers. Rather, it relied on predictable pattern or weak entropy source while generating seed phrase or private key. Because of this the keys generated here were not unique enough. Attackers may have pre-calculated or brute-forced the predictable range of seeds generated by this faulty algorithm! So they don't need to find wallet address one by one. This whole thread is scary to look. To think a bug can destroy your whole life worth of savings os really horrible. Everyone trusts hardware wallets a little more because they are the most secure wallets. But if a bug causes bitcoins to be drained from the wallet like this, then I don't know which hardware wallet to trust the most. I feel very bad for those who have been affected by this. I hope that the theft of such a huge amount will definitely be caught.
|
|
|
|
BALIK
Copper Member
Hero Member
   
Online
Activity: 2884
Merit: 632
🍓 BALIK Never DM First
|
 |
July 31, 2026, 08:12:26 PM |
|
I feel really bad for anyone affected by this. Users protecting their funds with cold storage only to have them stolen like this is a worst case scenario. It would be great if some of the people draining these wallets were caught and funds recovered for victims. I assume most is ending up in mixers though…
well, I assume most of the data is stored in Mixer. nothing to deny. Actually mixer is a neutral privacy tool. So, main problem here is not the existence of mixer company. Actual problem is how a leading hardware wallet provider failed to protect the security of its users core keys in the first place! I know that there is no point in complaining about what happened already. But at least we could hold our vendors accountable for security flaws. They should not be allowed to escape responsibility anyhow.
|
|
|
|
AakZaki
Legendary

Activity: 2674
Merit: 2380
Lightning⚡zkNodes
|
 |
July 31, 2026, 08:13:36 PM |
|
 In this forum, DireWolfM14 also seems to have a Coldcard MK4 Wallet, as can be seen from the feedback he gave to the developer of the wallet, nvK. nvK was also said to be "Anti-OpenSource" by dkbit98 hereI just want to know from DireWolfM14, how does it develop if you are still using this wallet? I hope your BTC is not affected by this case.
|
|
|
|
Karl_3000
Full Member
 

Activity: 364
Merit: 186
Bitcoin can not fail you
|
 |
July 31, 2026, 08:21:41 PM |
|
I don't know about the future, but using a multisig setup might be a good solution.
It will also be good if the seed phrase or the keys of the multisig wallet is generated on different wallets and not generate all the keys on the same wallets. In a 2 of 3, you can generate one key on Electrum, the second key on Sparrow and the third key on Trezor. Know that multisig is good but anyone that want to use it should be very careful and do a proper seed phrase backup.
|
|
|
|
taufik123
Legendary

Activity: 3332
Merit: 2412
Duelbits.com
|
 |
July 31, 2026, 08:33:38 PM |
|
I feel really bad for anyone affected by this. Users protecting their funds with cold storage only to have them stolen like this is a worst case scenario. It would be great if some of the people draining these wallets were caught and funds recovered for victims. I assume most is ending up in mixers though…
It's sad when we have secured Bitcoin as our main asset in Coldwallet which is already considered very safe, but lost very easily. Not only buying a hard wallet, but we also buy a security, If a breach case like this occurs, of course Coinkite as a Coldcard manufacturer must be responsible and must compensate the victim. There are many heartbreaking stories on the loss of assets at Coldcard that are happening today, not only impacting those who are wealthy who have more assets. They also come from people who accumulate little by little BTC, but then lose it all. Now, I wonder if there is no safe place to store Bitcoin or digital assets that are completely out of the touch of others? Or should I keep my money under my bed again?
|
|
|
|
|
Volgastallion
|
 |
July 31, 2026, 08:40:42 PM |
|
Since im not a specialist on this matter and most of you knows a lot more than me i dont want to say something that is wrong so im gonna limit me to only said i feel sorry for all of those who lose his precious BTC in this issue, i really feel sorry for them, i cant understand how much pain some of them are gonna feel when you discover maybe all your funds saved to the rest of your life or supporting your actual life are gone thanks to this fail and some shit persons.
As always i can recomend the msot easy thing to do in life with everything, dont put everything in the same basquet. Spread it the most you can. I know is a little more work but that could safe you always.
|
|
|
|
|
rdluffy
Legendary

Activity: 3038
Merit: 2019
|
 |
July 31, 2026, 08:44:35 PM |
|
I do not need too much exposure in the space. I sold about 30% of my coins today.
I am really scared after reading this thread.  Especially when philipma1957 said that he has already sold his 30% holding, it makes me even more scared. Can anyone please tell me if my funds in the Electrum wallet are safe, or should I move my funds from Electrum now? If not, then could this same incident happen to Electrum wallet users in future? Only users of the Coldcard wallet, specifically the Mk3 model are being affected The problem is that everyone is scared, and some are panicking, unfortunately And I don’t blame those who are, it’s scary to fear losing all your BTC at once like that However, so far this is an isolated issue for Coldcard Keep following the news and discussion threads If you generated your seed in Electrum, preferably offline and don’t store it online or expose your seed, you should be safe enough
|
|
|
|
|
Stalker22
Legendary

Activity: 2310
Merit: 1605
|
 |
July 31, 2026, 08:55:48 PM |
|
Can anyone please tell me if my funds in the Electrum wallet are safe, or should I move my funds from Electrum now?
Electrum itself is secure. The risk lies in where the seed phrase was generated. Your funds are only at risk if your Electrum wallet is acting as a software interface for a Coldcard hardware wallet or if you imported a seed phrase created on one, depending on the device firmware at the time of creation. If not, then could this same incident happen to Electrum wallet users in future?
Its hard to say what the future holds. Theoretically, any wallet software or hardware device that relies on a Pseudo-Random Number Generator (PRNG) to create private keys and seed phrases can suffer from an entropy flaw. But it is highly unlikely that such a mistake would happen to Electrum developers, especially considering that it is a very popular software with completely open source code that is checked and tested by many people.
|
|
|
|
fillippone
Legendary
Online
Activity: 2968
Merit: 21159
Duelbits.com - Rewarding, beyond limits.
|
 |
July 31, 2026, 09:06:45 PM |
|
There's going to be a huge manhunt for sure once they trace the bitcoins.
Someone at Bitkey tweeted this earlier: https://x.com/clay_garrett/status/2083247006139503065I don't see how would someone make this mistake... but one can only hope that the account in question is linked to the exploiter's identity. Wow, I thought about that possibility in my previous post, but tough: nah, you cannot be so stupid. That's a real infrastructure commitment (a full address index is on the order of a terabyte and takes days to sync), or a third-party dependency (which is very improbable for obvious opsec reasons).
And actually.... that was the case. Seems the hacker was very good at prompting, nothing more. I bet he's going to make some very basic error in moving the funds. I am confident we will know more.
|
|
|
|
|