Bitcoin Forum
August 01, 2026, 06:52:56 PM *
News: COLDCARD users only: critical vulnerability risks funds stored on COLDCARD devices; immediate action required
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 [7] 8 »  All
  Print  
Author Topic: Large-scale Coldcard compromise (1128.47 BTC stolen so far)  (Read 2179 times)
eaLiTy
Hero Member
*****
Offline

Activity: 2926
Merit: 976


Have Fun )@@( Stay Safe


View Profile
Today at 06:47:26 AM
Merited by vapourminer (1)
 #121

Good news for people who were drained - they appear to have found the identity of the attacker
Even if funds are recovered by authorities, how are they ever going to return them? The addresses they came from are compromised, and it would be possible for anyone who brute-forces the keys to claim ownership of the funds.
We have the precedent of Bitfinex and Mt. Gox, just like @NotATether mentioned. Once the funds are recovered, victims will be asked to provide full KYC and prove ownership of their original wallet by signing a message. They will then have the funds credited to a new wallet address. It will be a long and time-consuming process for the victims, but it is good to hear that they actually found the attacker.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
NotATether
Legendary
*
Offline

Activity: 2408
Merit: 10031


┻┻ ︵㇏(°□°㇏)


View Profile WWW
Today at 07:06:20 AM
Merited by vapourminer (1), ABCbits (1)
 #122

What is the evidence that he used AI?

https://x.com/nvk/status/2083216713693151552

Quote
To every other developer: we believe this is a sober reality of the new AI paradigm. AI-assisted code review can now find latent bugs at a speed that is outpacing even the industry’s most seasoned experts. If your firmware is open-source or has ever been public, assume it's already being read by attackers and defenders alike.

It's speculation, but it's strongly suspected that AI was used since this public explorer part of the heist was said to be carried out amateurishly.

To be clear, I disagree with nvk here about the implication that open-source somehow makes the firmware weaker. In fact, I would argue that closed source firmware is a major vulnerability in and of itself.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
cygan
Legendary
*
Offline

Activity: 3962
Merit: 12923


icarus-cards.eu


View Profile WWW
Today at 07:23:45 AM
Merited by vapourminer (1), ABCbits (1), nc50lc (1), Stalker22 (1)
 #123

a fifth address: bc1qtfrwa4j6rmj9rsgspv6a0yjumkg39js2numu75, has now been identified as the location of the stolen BTCitcoins
and on the following website, you can find more information and check for yourself whether your address(es) have been drained by this hack: https://coldcard-watch.vercel.app/

█████████████████████████
██████████████▀▄▄▄▀██████
████████▀▀▄▄████▄▄▀███
██████████████
████▀▄▄████████████
██▀██▀▀▀▀██
███▄▀▀███████
█▀███████████▄█
█▄▀▄██▀███▄████▄██
███▄█████▄▄▄████
█████▄████▄▄▄▀▀▄▄██████
███████▄▀▀▀▀▄▄▄██████████
█████████████████████████
.
 Jackpot ter .....  COMMUNITY POWERED CRYPTO CASINO  
▄███████████████████████▄
█████████████████████████
█████████████████████████
██████▄░▄▄▀██████▀▄██████
███████▄░█▄░███▀▄████████
█████████▄▀█░▀▄██████████
██████████▄▀█▄▀██████████
██████████▀▄░█▄▀█████████
████████▀▄███░██░▀███████
██████▀▄██████░▀▀░▀██████
█████████████████████████
█████████████████████████
▀███████████████████████▀
▄███████████████████████▄
█████████████████████████
█████████████████████████
███████████████▀▀░░▐█████
███████████▀▀░░░░░░██████
███████▀▀░░░▄▄▀░░░░██████
████▀░░░░░▄█▀░░░░░▐██████
██████▄▄██▀░░░░░░░▐██████
███████████▄░░░░░░███████
██████████████▄░░▄███████
█████████████████████████
█████████████████████████
▀███████████████████████▀
▄███████████████████████▄
█████████████████████████
█████████████████████████
██████▀░░░▀▀▀▀▀░░░▀██████
█████▀░░░░░░░░░░░░░▀█████
████▀░░░░░░░░░░░░░░░▀████
████░░░░▄█▄░░░▄█▄░░░░████
███▌░░░░▀█▀░░░▀█▀░░░░▐███
███▌░░░░▄░░░░░░░▄░░░░▐███
█████▄▄░▄█▄▄▄▄▄█▄░▄▄█████
█████████████████████████
█████████████████████████
▀███████████████████████▀
 
  PLAY NOW  
Karl_3000
Full Member
***
Offline

Activity: 364
Merit: 187


Bitcoin can not fail you


View Profile WWW
Today at 09:35:24 AM
 #124

Well if it's an amateur doing all this (he used AI for the exploit so can't be a professional hacker), then chances are, we are going to see a law enforcement announcement sooner than we think.
What is the evidence that he used AI?
There is no evidence that the hackers used AI to do his bad work but we all know that AI are used for bad works like this today. I will not blame it on AI at all because if Coldcard did not do something stupid that got the bitcoin of their users lost, AI will not see any vulnerability if there is no vulnerability.

crypto_curious
Full Member
***
Offline

Activity: 950
Merit: 182


View Profile
Today at 10:17:04 AM
 #125

I hope you see this message. The Attacker
(...)
You stole from a family

Why didn't you use an additional passphrase with your seed? You have to enter it every time you access your wallet. Without the passphrase, the 24-word seed on its own is useless. Sorry, but this is partly your own fault.

That's exactly what I did. I bought a hardware wallet years ago, generated and safely stored my seed. Later I learned that I could protect it with an additional passphrase. I immediately scrapped that seed, generated a brand-new one, and enabled the passphrase.

The option has been available for many, many years. Why you chose not to use it is beyond me.

Using a passphrase should be mandatory for all 24-word seed wallets.
LoyceV
Legendary
*
Offline

Activity: 4116
Merit: 22396


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
Today at 10:39:51 AM
Merited by vapourminer (1), F2b (1)
 #126

this is partly your own fault.
Victim blaming isn't helping anyone.

Quote
Using a passphrase should be mandatory for all 24-word seed wallets.
That adds the risk of losing your passphrase. Storing keys is always a compromise between the risk of someone else gaining access, and the risk of losing access by yourself.

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
BobbysTransactions
Jr. Member
*
Offline

Activity: 42
Merit: 20


View Profile
Today at 11:50:26 AM
Merited by vapourminer (1)
 #127

Good news for people who were drained - they appear to have found the identity of the attacker
Even if funds are recovered by authorities, how are they ever going to return them? The addresses they came from are compromised, and it would be possible for anyone who brute-forces the keys to claim ownership of the funds.
We have the precedent of Bitfinex and Mt. Gox, just like @NotATether mentioned. Once the funds are recovered, victims will be asked to provide full KYC and prove ownership of their original wallet by signing a message. They will then have the funds credited to a new wallet address. It will be a long and time-consuming process for the victims, but it is good to hear that they actually found the attacker.

But if the seedphrase is compromised can't anyone sign a message with the private key? Or do you mean somehow link it to the physical hardware device?
eaLiTy
Hero Member
*****
Offline

Activity: 2926
Merit: 976


Have Fun )@@( Stay Safe


View Profile
Today at 12:25:12 PM
Merited by vapourminer (1)
 #128

Good news for people who were drained - they appear to have found the identity of the attacker
Even if funds are recovered by authorities, how are they ever going to return them? The addresses they came from are compromised, and it would be possible for anyone who brute-forces the keys to claim ownership of the funds.
We have the precedent of Bitfinex and Mt. Gox, just like @NotATether mentioned. Once the funds are recovered, victims will be asked to provide full KYC and prove ownership of their original wallet by signing a message. They will then have the funds credited to a new wallet address. It will be a long and time-consuming process for the victims, but it is good to hear that they actually found the attacker.
But if the seedphrase is compromised can't anyone sign a message with the private key? Or do you mean somehow link it to the physical hardware device?
The original exchange withdrawal records and transaction details link your KYC to the real world and the Coldcard wallet. The attacker cannot forge your entire historical transaction trail.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
stompix
Legendary
*
Offline

Activity: 3696
Merit: 7250



View Profile WWW
Today at 12:38:28 PM
Merited by LoyceV (2), vapourminer (1)
 #129

The original exchange withdrawal records and transaction details link your KYC to the real world and the Coldcard wallet. The attacker cannot forge your entire historical transaction trail.

What about the people that bought the coins P2P, got them from an ATM, mixed them before moving there, exchanged them on a DEX, or bought the coins from a CEX that is now out of business, people that moved their coins from another wallet they have it no more, and many, many others?

I'm genuinely concerned why anyone on Bitcointalk would assume everyone can be linked through KYC to his stash.

Good news for people who were drained - they appear to have found the identity of the attacker

That whole thing screams engagement BS!

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|  BTC     XMR  
  DAI     LTC  
   Fees  0.8%    
bangjoe
Hero Member
*****
Offline

Activity: 2240
Merit: 951


Bitcoin $1 Million


View Profile WWW
Today at 12:42:28 PM
 #130

Updated total drained: 1082.65 BTC

It's crazy, I just found out this, fortunately at the beginning of this year I didn't buy that hard wallet, even though my bitcoin wasn't much, but I would be disappointed if it happened like this.

So this sentence is a lie!



Now of all the victims affected, will Coldcard make up for it, or what will be the end result?
This is a big question and probably victims will be too, if the problem lies with the security wallets that have been compromised.

eaLiTy
Hero Member
*****
Offline

Activity: 2926
Merit: 976


Have Fun )@@( Stay Safe


View Profile
Today at 12:50:49 PM
 #131

The original exchange withdrawal records and transaction details link your KYC to the real world and the Coldcard wallet. The attacker cannot forge your entire historical transaction trail.

What about the people that bought the coins P2P, got them from an ATM, mixed them before moving there, exchanged them on a DEX, or bought the coins from a CEX that is now out of business, people that moved their coins from another wallet they have it no more, and many, many others?

I'm genuinely concerned why anyone on Bitcointalk would assume everyone can be linked through KYC to his stash.
P2P platforms have transaction history, and ATM transactions have paper receipts alongside bank statements showing the exact fiat transaction. The only issue you will have proving ownership is if you used a mixer before sending the coins to your Coldcard wallet. Other than that, you should be able to prove your ownership with the physical hardware at your disposal.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
vapourminer
Legendary
*
Offline

Activity: 5110
Merit: 6593


what is this "brake pedal" you speak of?


View Profile
Today at 12:53:55 PM
 #132

That just doesn't make sense! Anyone with the skills to pull this off shouldn't make such a rookie mistake, unless the account is owned by a scapegoat.
Or could it just be an amateur who's in way over his head? Someone who accidentally stumbled upon this weakness, and suddenly ended up with $70 million in stolen funds?

vibe coded? sounds like an AI took the easy way out on scanning for balances/public keys..

Lucius
Legendary
*
Offline

Activity: 4046
Merit: 7667



View Profile WWW
Today at 12:56:48 PM
 #133

~snip~
Even though my own wallet appears unaffected, I am seriously considering abandoning Coldcard. My decision will depend heavily on the quality and transparency of Coinkite’s response, and on what it does for those who lost their funds.


After everything that happened, you're just thinking about it? If I were one of the owners who hasn't been hacked yet, I would have sent my coins to another wallet the moment I read the news.



this is partly your own fault.
Victim blaming isn't helping anyone.
~snip~


That member has not provided any proof that he is really a victim (so far), so his posts should be viewed with a certain amount of skepticism. Besides, his post was 100% created with AI. (tested with copyleaks)

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits..REWARDING, BEYOND LIMITS...
█████████████████████████
█████████████████████████
███████████▀▀░░▀█▄░░▀████
████████▀░░░░░░░░▀█▄░████
███████░░░░▄▄░░▄░░░▀█████
██████░░░░░▀▀▄██▀░░░░████
█████░░░██░▄██▀▄▄░░░█████
████░░░░░▄██▀░░▀▀░░██████
█████▄░░▀█▀░██░░░░███████
████░▀█▄░░░░░░░░▄████████
████▄░░▀█▄░░▄▄███████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████▀░░▀░███████████
████████░░░▄░█░██████████
███████████▌▐██░█████████
███████████░███▌▐████████
██████████░█████░████████
██████▀░▄░▀███▀░▄░▀█████
█████░▄▀░░░░█░▄▀░░░░█████
█████░░░░░░░█░░░░░░░█████
██████▄░░░▄███▄░░░▄██████
█████████████████████████
█████████████████████████


























  PLAY NOW  
m2017
Legendary
*
Offline

Activity: 2562
Merit: 1693


keep walking, Johnnie


View Profile
Today at 12:57:14 PM
 #134

I'm really shocked that this happened to Coldcard, I always thought that this was the best crypto wallet, the most secure one and I was supporting Coldcard over Passport when it was about security (but in general I was suggesting passport for a better user interface and experience).
Anyways, I think that this was a huge hit to hardware wallets because the security of Coldcard was thought to be one of the best if not the best.
This incident demonstrates that the BTC-community needs to reconsider its attitude toward hardware wallets as a completely safe and secure way to store cryptocurrencies. Nothing is perfect. And take this into account when organizing your "crypto storage".

This isn't a huge hit to hardware wallets, but rather a dispelled illusion that this devices are invulnerable. This was bound to happen one day. We all relaxed, placing the burden of ensuring secure storage entirely on hardware wallet manufacturers. With financial assets, as we see, the cost of error is very high.

Putting aside the emotions and "shock", what conclusions can we draw?

Risk diversification. Those who didn't store all their funds on a single coldcard device were able to preserve some of their savings. Therefore, you should abandon the illusion of "one of the best if not the best" and store your assets separated across devices from different manufacturers (I hope you don't make the mistake of trusting Ledger? Smiley).

I wonder what happens if someone didn't declare their coins and law enforcements manage to recover lost coins.
We'd better prepare ourselves for another sudden increase in the price of Monero. Wink

By the way, are coldcard owners still using these devices after the firmware update? I wonder if this company can stay in business after their devices failed to perform their most basic function. It's like the car you bought doesn't drive. Would you continue to push a car downhill just to make it move? Smiley

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits PREDICT..
█████████████████████████
█████████████████████████
███████████▀▀░░░░▀▀██████
██████████░░▄████▄░░████
█████████░░████████░░████
█████████░░████████░░████
█████████▄▀██████▀▄████
████████▀▀░░░▀▀▀▀░░▄█████
██████▀░░░░██▄▄▄▄████████
████▀░░░░▄███████████████
█████▄▄█████████████████
█████████████████████████
█████████████████████████
.
.WHERE EVERYTHING IS A MARKET..
█████
██
██







██
██
██████
Will Bitcoin hit $200,000
before January 1st 2027?

    No @1.15         Yes @6.00    
█████
██
██







██
██
██████

  CHECK MORE > 
stompix
Legendary
*
Offline

Activity: 3696
Merit: 7250



View Profile WWW
Today at 01:05:41 PM
 #135

and ATM transactions have paper receipts alongside bank statements showing the exact fiat transaction.

Yeah, now I know why you thought KYC would solve this!  Wink

~snip~
Even though my own wallet appears unaffected, I am seriously considering abandoning Coldcard. My decision will depend heavily on the quality and transparency of Coinkite’s response, and on what it does for those who lost their funds.


After everything that happened, you're just thinking about it? If I were one of the owners who hasn't been hacked yet, I would have sent my coins to another wallet the moment I read the news.

Well, technically, the hardware wallet is still fine if you import a seed from a different source.

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|  BTC     XMR  
  DAI     LTC  
   Fees  0.8%    
Wind_FURY
Legendary
*
Offline

Activity: 3724
Merit: 2208



View Profile
Today at 01:07:49 PM
 #136

Quote

I'm a software engineer with an MSc in Computer Science and 25+ years in the industry. Here's why Coinkite's Coldcard bug isn't an oopsy, it's disqualifying.

Coldcard's seed generation silently fell back to a non-cryptographic "random" number generator for 5 years. Not because crypto is hard, but because Coinkite violated the most basic rule of secure system design: fail closed, never open. When a security-critical path can't be verified, the system refuses to run and throws an error.

It does not quietly substitute something weaker and carry on. This code should have refused to produce a seed. Instead it produced a predictable one and continue silently. ☠️

A company that lets its most critical code path go unverified for half a decade cannot be trusted with your keys.

Throw away your Coldcards. Never buy one again
.

https://x.com/janrothen/status/2083388740496478361


  💀

There are people in X that are also saying that the founder of CoinKite/ColdCard is deleting his posts. Can negligence be used as a strong case against CoinKite/ColdCard? The company should be strictly liable for this situation, no?

suzanne5223
Hero Member
*****
Offline

Activity: 3388
Merit: 747


Want top-notch marketing for your brand, Hire me


View Profile WWW
Today at 01:31:59 PM
 #137

Updated total drained: 1082.65 BTC

It's crazy, I just found out this, fortunately at the beginning of this year I didn't buy that hard wallet, even though my bitcoin wasn't much, but I would be disappointed if it happened like this.

So this sentence is a lie!



Now of all the victims affected, will Coldcard make up for it, or what will be the end result?
This is a big question and probably victims will be too, if the problem lies with the security wallets that have been compromised.
Yes, it is a lie, and it is a marketing campaign just like how Trust Wallet once claimed to be an open-source wallet.
In this crypto space, I don't think it is nice for any Bitcoiners to trust the statement of every brand unless it's something confirmed to be real by the community.

▄▄███████████████████▄▄
▄███████████████████████▄
███████████████████████
████████▀▀▀▀██▀█▄▀███████
███▀▀██▄▄██▄██▌▄▄▄▄▄██
████▄█████▐██▀▄█▀▀█████
█████▌██▀▀▄█▀██▄██▄███
██▄▄▄▄███████████▐███████
████████▐█████████▀▀█████
███████▄██████▀█▄▄▄▄▄████
███████████████████████

▀███████████████████████▀
▀▀███████████████████▀▀

 Kings Game  
 
 🎰   🎲   ⚽ 
████
██
██
██
██
██
██
██
██
██
██
██
████
████████████████████████████


RAKEBACK
..UP TO 30%..
████████████████████████████
████
██
██
██
██
██
██
██
██
██
██
██
████
████
██
██
██
██
██
██
██
██
██
██
██
████
████████████████████████████
 
..500%..
WELCOME BONUS
+ 250 FREE SPINS
████████████████████████████
████
██
██
██
██
██
██
██
██
██
██
██
████

   WIN NOW     
abaeze
Full Member
***
Offline

Activity: 490
Merit: 172



View Profile
Today at 01:41:57 PM
 #138

Quote
Using a passphrase should be mandatory for all 24-word seed wallets.
That adds the risk of losing your passphrase. Storing keys is always a compromise between the risk of someone else gaining access, and the risk of losing access by yourself.
After a long time or 10 years later if someone steals BTC from wallets with strong security provided with these 24 seeds and secret passphrase and makes transaction to another wallets, is it user error/weakness or the ability of hackers? Because in the current context, how much is there any logical guarantee that this will not happen, so the question is now on everyone's mind.

examplens
Legendary
*
Offline

Activity: 4088
Merit: 4853



View Profile WWW
Today at 01:58:11 PM
Merited by BlackHatCoiner (4)
 #139

Well if it's an amateur doing all this (he used AI for the exploit so can't be a professional hacker), then chances are, we are going to see a law enforcement announcement sooner than we think.
What is the evidence that he used AI?
There is no evidence that the hackers used AI to do his bad work but we all know that AI are used for bad works like this today. I will not blame it on AI at all because if Coldcard did not do something stupid that got the bitcoin of their users lost, AI will not see any vulnerability if there is no vulnerability.
It may not be AI, but automation is certainly recognized.

Signature: every sweep paid an identical hardcoded 30.0 sat/vB — a 30-75x overpay vs the 0.4-1.0 sat/vB median that week — and left no change output. That looks like an automated tool spending keys it already held, not owners moving funds. Victims: 1,183 native segwit (BIP-84), 7 BIP-49, 6 BIP-44 — consistent with multi-path key scanning.


Source: Galaxy Research on X https://x.com/glxyresearch/status/2083181683067506899?s=20

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
Oluwa-btc
Hero Member
*****
Offline

Activity: 1638
Merit: 659


Leading Crypto Sports Betting & Casino Platform


View Profile WWW
Today at 02:02:03 PM
 #140

I know this sounds like a lot, but it's really not hard.

Self custody comes with self responsibility. Your security is your job. It has to be done right.

This is the moral lesson of everything that happened with the compromise of Coldcard.

Hopefully victims affected by this are patience enough until their funds are ready for disbursement. They stand a high risk of being attacked by recovering scammers impersonating Coldcard or one of these top financial bodies and if they can not be recovered,  then a proper update should be given to this victims from Coldcard. I'm sorry and at the same time not sorry for the victims ( Because, they have refused to be their own selfcustody and bank ). I'm worried this shouldn't bring a lot of negativity towards cryptocurrency,  the reviews and criticism already are overwhelming. I still believe people can be their own security chief, banks and self custody after all these. Indeed a rough in the crypto sphere.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
Pages: « 1 2 3 4 5 6 [7] 8 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!