|
eaLiTy
|
Good news for people who were drained - they appear to have found the identity of the attacker Even if funds are recovered by authorities, how are they ever going to return them? The addresses they came from are compromised, and it would be possible for anyone who brute-forces the keys to claim ownership of the funds. We have the precedent of Bitfinex and Mt. Gox, just like @NotATether mentioned. Once the funds are recovered, victims will be asked to provide full KYC and prove ownership of their original wallet by signing a message. They will then have the funds credited to a new wallet address. It will be a long and time-consuming process for the victims, but it is good to hear that they actually found the attacker.
|
| EARNBET | | | ⚽ 🏀 🏈 🏓 🎯 🥊 |
| ⚾ 🎾 ⛳ 🏐 🏏 🏎️ | | |
███████▄▄███████████ ████▄██████████████████ ██▄▀▀███████████████▀▀███ █▄████████████████████████ ▄▄████████▀▀▀▀▀████████▄▄██ ███████████████████████████ █████████▌████▀████████████ ███████████████████████████ ▀▀███████▄▄▄▄▄█████████▀▀██ █▀█████████████████████▀██ ██▀▄▄███████████████▄▄███ ████▀██████████████████ ███████▀▀███████████ | ....HIGHEST.... VIP REWARDS ✔ G U A R A N T E E D
| | | 🜲 | KING OF THE CASTLE $200K in prizes | | | ..PLAY NOW.. |
|
|
|
NotATether
Legendary

Activity: 2408
Merit: 10031
┻┻ ︵㇏(°□°㇏)
|
What is the evidence that he used AI?
https://x.com/nvk/status/2083216713693151552To every other developer: we believe this is a sober reality of the new AI paradigm. AI-assisted code review can now find latent bugs at a speed that is outpacing even the industry’s most seasoned experts. If your firmware is open-source or has ever been public, assume it's already being read by attackers and defenders alike.
It's speculation, but it's strongly suspected that AI was used since this public explorer part of the heist was said to be carried out amateurishly. To be clear, I disagree with nvk here about the implication that open-source somehow makes the firmware weaker. In fact, I would argue that closed source firmware is a major vulnerability in and of itself.
|
|
|
|
cygan
Legendary

Activity: 3962
Merit: 12923
icarus-cards.eu
|
a fifth address: bc1qtfrwa4j6rmj9rsgspv6a0yjumkg39js2numu75, has now been identified as the location of the stolen BTCitcoins and on the following website, you can find more information and check for yourself whether your address(es) have been drained by this hack: https://coldcard-watch.vercel.app/
|
|
|
|
Karl_3000
Full Member
 

Activity: 364
Merit: 187
Bitcoin can not fail you
|
 |
Today at 09:35:24 AM |
|
Well if it's an amateur doing all this (he used AI for the exploit so can't be a professional hacker), then chances are, we are going to see a law enforcement announcement sooner than we think. What is the evidence that he used AI? There is no evidence that the hackers used AI to do his bad work but we all know that AI are used for bad works like this today. I will not blame it on AI at all because if Coldcard did not do something stupid that got the bitcoin of their users lost, AI will not see any vulnerability if there is no vulnerability.
|
|
|
|
|
crypto_curious
|
 |
Today at 10:17:04 AM |
|
I hope you see this message. The Attacker (...) You stole from a family
Why didn't you use an additional passphrase with your seed? You have to enter it every time you access your wallet. Without the passphrase, the 24-word seed on its own is useless. Sorry, but this is partly your own fault. That's exactly what I did. I bought a hardware wallet years ago, generated and safely stored my seed. Later I learned that I could protect it with an additional passphrase. I immediately scrapped that seed, generated a brand-new one, and enabled the passphrase. The option has been available for many, many years. Why you chose not to use it is beyond me. Using a passphrase should be mandatory for all 24-word seed wallets.
|
|
|
|
|
LoyceV
Legendary

Activity: 4116
Merit: 22396
Thick-Skinned Gang Leader and Golden Feather 2021
|
this is partly your own fault. Victim blaming isn't helping anyone. Using a passphrase should be mandatory for all 24-word seed wallets. That adds the risk of losing your passphrase. Storing keys is always a compromise between the risk of someone else gaining access, and the risk of losing access by yourself.
|
¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
|
|
|
BobbysTransactions
Jr. Member
Online
Activity: 42
Merit: 20
|
Good news for people who were drained - they appear to have found the identity of the attacker Even if funds are recovered by authorities, how are they ever going to return them? The addresses they came from are compromised, and it would be possible for anyone who brute-forces the keys to claim ownership of the funds. We have the precedent of Bitfinex and Mt. Gox, just like @NotATether mentioned. Once the funds are recovered, victims will be asked to provide full KYC and prove ownership of their original wallet by signing a message. They will then have the funds credited to a new wallet address. It will be a long and time-consuming process for the victims, but it is good to hear that they actually found the attacker. But if the seedphrase is compromised can't anyone sign a message with the private key? Or do you mean somehow link it to the physical hardware device?
|
|
|
|
|
|
eaLiTy
|
Good news for people who were drained - they appear to have found the identity of the attacker Even if funds are recovered by authorities, how are they ever going to return them? The addresses they came from are compromised, and it would be possible for anyone who brute-forces the keys to claim ownership of the funds. We have the precedent of Bitfinex and Mt. Gox, just like @NotATether mentioned. Once the funds are recovered, victims will be asked to provide full KYC and prove ownership of their original wallet by signing a message. They will then have the funds credited to a new wallet address. It will be a long and time-consuming process for the victims, but it is good to hear that they actually found the attacker. But if the seedphrase is compromised can't anyone sign a message with the private key? Or do you mean somehow link it to the physical hardware device? The original exchange withdrawal records and transaction details link your KYC to the real world and the Coldcard wallet. The attacker cannot forge your entire historical transaction trail.
|
| EARNBET | | | ⚽ 🏀 🏈 🏓 🎯 🥊 |
| ⚾ 🎾 ⛳ 🏐 🏏 🏎️ | | |
███████▄▄███████████ ████▄██████████████████ ██▄▀▀███████████████▀▀███ █▄████████████████████████ ▄▄████████▀▀▀▀▀████████▄▄██ ███████████████████████████ █████████▌████▀████████████ ███████████████████████████ ▀▀███████▄▄▄▄▄█████████▀▀██ █▀█████████████████████▀██ ██▀▄▄███████████████▄▄███ ████▀██████████████████ ███████▀▀███████████ | ....HIGHEST.... VIP REWARDS ✔ G U A R A N T E E D
| | | 🜲 | KING OF THE CASTLE $200K in prizes | | | ..PLAY NOW.. |
|
|
|
stompix
Legendary

Activity: 3696
Merit: 7250
|
The original exchange withdrawal records and transaction details link your KYC to the real world and the Coldcard wallet. The attacker cannot forge your entire historical transaction trail.
What about the people that bought the coins P2P, got them from an ATM, mixed them before moving there, exchanged them on a DEX, or bought the coins from a CEX that is now out of business, people that moved their coins from another wallet they have it no more, and many, many others? I'm genuinely concerned why anyone on Bitcointalk would assume everyone can be linked through KYC to his stash. Good news for people who were drained - they appear to have found the identity of the attacker
That whole thing screams engagement BS!
|
| DΞX.fo | | | | | | ▄▄██████ █████████ ██████████ ██████████ ██████████ █████████ ▀▀██████
▄███████ ▄██████████ ████████████ █████████████ █████████████ | | | | ▄▄█ ▄████▀ ▄███▀█▄ ▄██▀█▄██ █████▀▀█ ████████ ████████ ▀██▄████ ▄████▄▄█ ▄█████▀███ ▄█████▀████▀ █████▀███████ ▀██▀█████████ | | | | | BTC XMR DAI LTC Fees 0.8% |
|
|
|
|
bangjoe
|
 |
Today at 12:42:28 PM |
|
Updated total drained: 1082.65 BTC
It's crazy, I just found out this, fortunately at the beginning of this year I didn't buy that hard wallet, even though my bitcoin wasn't much, but I would be disappointed if it happened like this. So this sentence is a lie!  Now of all the victims affected, will Coldcard make up for it, or what will be the end result? This is a big question and probably victims will be too, if the problem lies with the security wallets that have been compromised.
|
|
|
|
|
eaLiTy
|
 |
Today at 12:50:49 PM |
|
The original exchange withdrawal records and transaction details link your KYC to the real world and the Coldcard wallet. The attacker cannot forge your entire historical transaction trail.
What about the people that bought the coins P2P, got them from an ATM, mixed them before moving there, exchanged them on a DEX, or bought the coins from a CEX that is now out of business, people that moved their coins from another wallet they have it no more, and many, many others? I'm genuinely concerned why anyone on Bitcointalk would assume everyone can be linked through KYC to his stash. P2P platforms have transaction history, and ATM transactions have paper receipts alongside bank statements showing the exact fiat transaction. The only issue you will have proving ownership is if you used a mixer before sending the coins to your Coldcard wallet. Other than that, you should be able to prove your ownership with the physical hardware at your disposal.
|
| EARNBET | | | ⚽ 🏀 🏈 🏓 🎯 🥊 |
| ⚾ 🎾 ⛳ 🏐 🏏 🏎️ | | |
███████▄▄███████████ ████▄██████████████████ ██▄▀▀███████████████▀▀███ █▄████████████████████████ ▄▄████████▀▀▀▀▀████████▄▄██ ███████████████████████████ █████████▌████▀████████████ ███████████████████████████ ▀▀███████▄▄▄▄▄█████████▀▀██ █▀█████████████████████▀██ ██▀▄▄███████████████▄▄███ ████▀██████████████████ ███████▀▀███████████ | ....HIGHEST.... VIP REWARDS ✔ G U A R A N T E E D
| | | 🜲 | KING OF THE CASTLE $200K in prizes | | | ..PLAY NOW.. |
|
|
|
vapourminer
Legendary

Activity: 5110
Merit: 6594
what is this "brake pedal" you speak of?
|
 |
Today at 12:53:55 PM |
|
That just doesn't make sense! Anyone with the skills to pull this off shouldn't make such a rookie mistake, unless the account is owned by a scapegoat. Or could it just be an amateur who's in way over his head? Someone who accidentally stumbled upon this weakness, and suddenly ended up with $70 million in stolen funds?
vibe coded? sounds like an AI took the easy way out on scanning for balances/public keys..
|
|
|
|
|
Lucius
Legendary

Activity: 4046
Merit: 7667
|
 |
Today at 12:56:48 PM |
|
~snip~ Even though my own wallet appears unaffected, I am seriously considering abandoning Coldcard. My decision will depend heavily on the quality and transparency of Coinkite’s response, and on what it does for those who lost their funds.
After everything that happened, you're just thinking about it? If I were one of the owners who hasn't been hacked yet, I would have sent my coins to another wallet the moment I read the news.
this is partly your own fault. Victim blaming isn't helping anyone. ~snip~That member has not provided any proof that he is really a victim (so far), so his posts should be viewed with a certain amount of skepticism. Besides, his post was 100% created with AI. (tested with copyleaks)
|
| . .Duelbits..REWARDING, BEYOND LIMITS... | █████████████████████████ █████████████████████████ ███████████▀▀░░▀█▄░░▀████ ████████▀░░░░░░░░▀█▄░████ ███████░░░░▄▄░░▄░░░▀█████ ██████░░░░░▀▀▄██▀░░░░████ █████░░░██░▄██▀▄▄░░░█████ ████░░░░░▄██▀░░▀▀░░██████ █████▄░░▀█▀░██░░░░███████ ████░▀█▄░░░░░░░░▄████████ ████▄░░▀█▄░░▄▄███████████ █████████████████████████ █████████████████████████ | █████████████████████████ █████████████████████████ █████████▀░░▀░███████████ ████████░░░▄░█░██████████ ███████████▌▐██░█████████ ███████████░███▌▐████████ ██████████░█████░████████ ██████▀░▄░▀███▀░▄░▀██████ █████░▄▀░░░░█░▄▀░░░░█████ █████░░░░░░░█░░░░░░░█████ ██████▄░░░▄███▄░░░▄██████ █████████████████████████ █████████████████████████ | █ █ █ █ █ █ █ █ █ █ █ █ █ | |
| | █ █ █ █ █ █ █ █ █ █ █ █ █ | PLAY NOW |
|
|
|
m2017
Legendary

Activity: 2562
Merit: 1693
keep walking, Johnnie
|
 |
Today at 12:57:14 PM |
|
I'm really shocked that this happened to Coldcard, I always thought that this was the best crypto wallet, the most secure one and I was supporting Coldcard over Passport when it was about security (but in general I was suggesting passport for a better user interface and experience). Anyways, I think that this was a huge hit to hardware wallets because the security of Coldcard was thought to be one of the best if not the best.
This incident demonstrates that the BTC-community needs to reconsider its attitude toward hardware wallets as a completely safe and secure way to store cryptocurrencies. Nothing is perfect. And take this into account when organizing your "crypto storage". This isn't a huge hit to hardware wallets, but rather a dispelled illusion that this devices are invulnerable. This was bound to happen one day. We all relaxed, placing the burden of ensuring secure storage entirely on hardware wallet manufacturers. With financial assets, as we see, the cost of error is very high. Putting aside the emotions and "shock", what conclusions can we draw? Risk diversification. Those who didn't store all their funds on a single coldcard device were able to preserve some of their savings. Therefore, you should abandon the illusion of " one of the best if not the best" and store your assets separated across devices from different manufacturers (I hope you don't make the mistake of trusting Ledger?  ). I wonder what happens if someone didn't declare their coins and law enforcements manage to recover lost coins.
We'd better prepare ourselves for another sudden increase in the price of Monero.  By the way, are coldcard owners still using these devices after the firmware update? I wonder if this company can stay in business after their devices failed to perform their most basic function. It's like the car you bought doesn't drive. Would you continue to push a car downhill just to make it move? 
|
|
|
|
stompix
Legendary

Activity: 3696
Merit: 7250
|
 |
Today at 01:05:41 PM |
|
and ATM transactions have paper receipts alongside bank statements showing the exact fiat transaction.
Yeah, now I know why you thought KYC would solve this!  ~snip~ Even though my own wallet appears unaffected, I am seriously considering abandoning Coldcard. My decision will depend heavily on the quality and transparency of Coinkite’s response, and on what it does for those who lost their funds.
After everything that happened, you're just thinking about it? If I were one of the owners who hasn't been hacked yet, I would have sent my coins to another wallet the moment I read the news. Well, technically, the hardware wallet is still fine if you import a seed from a different source.
|
| DΞX.fo | | | | | | ▄▄██████ █████████ ██████████ ██████████ ██████████ █████████ ▀▀██████
▄███████ ▄██████████ ████████████ █████████████ █████████████ | | | | ▄▄█ ▄████▀ ▄███▀█▄ ▄██▀█▄██ █████▀▀█ ████████ ████████ ▀██▄████ ▄████▄▄█ ▄█████▀███ ▄█████▀████▀ █████▀███████ ▀██▀█████████ | | | | | BTC XMR DAI LTC Fees 0.8% |
|
|
|
Wind_FURY
Legendary

Activity: 3724
Merit: 2208
|
 |
Today at 01:07:49 PM |
|
I'm a software engineer with an MSc in Computer Science and 25+ years in the industry. Here's why Coinkite's Coldcard bug isn't an oopsy, it's disqualifying. Coldcard's seed generation silently fell back to a non-cryptographic "random" number generator for 5 years. Not because crypto is hard, but because Coinkite violated the most basic rule of secure system design: fail closed, never open. When a security-critical path can't be verified, the system refuses to run and throws an error. It does not quietly substitute something weaker and carry on. This code should have refused to produce a seed. Instead it produced a predictable one and continue silently. ☠️ A company that lets its most critical code path go unverified for half a decade cannot be trusted with your keys.
Throw away your Coldcards. Never buy one again. https://x.com/janrothen/status/2083388740496478361 💀 There are people in X that are also saying that the founder of CoinKite/ColdCard is deleting his posts. Can negligence be used as a strong case against CoinKite/ColdCard? The company should be strictly liable for this situation, no?
|
|
|
|
|
suzanne5223
|
 |
Today at 01:31:59 PM |
|
Updated total drained: 1082.65 BTC
It's crazy, I just found out this, fortunately at the beginning of this year I didn't buy that hard wallet, even though my bitcoin wasn't much, but I would be disappointed if it happened like this. So this sentence is a lie!  Now of all the victims affected, will Coldcard make up for it, or what will be the end result? This is a big question and probably victims will be too, if the problem lies with the security wallets that have been compromised. Yes, it is a lie, and it is a marketing campaign just like how Trust Wallet once claimed to be an open-source wallet. In this crypto space, I don't think it is nice for any Bitcoiners to trust the statement of every brand unless it's something confirmed to be real by the community.
|
| Kings Game | 🎰 🎲 ⚽ | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | ████████████████████████████
████████████████████████████ | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | ████████████████████████████
| ..500%.. | WELCOME BONUS + 250 FREE SPINS |
████████████████████████████ | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | WIN NOW |
|
|
|
|
abaeze
|
 |
Today at 01:41:57 PM |
|
Using a passphrase should be mandatory for all 24-word seed wallets. That adds the risk of losing your passphrase. Storing keys is always a compromise between the risk of someone else gaining access, and the risk of losing access by yourself. After a long time or 10 years later if someone steals BTC from wallets with strong security provided with these 24 seeds and secret passphrase and makes transaction to another wallets, is it user error/weakness or the ability of hackers? Because in the current context, how much is there any logical guarantee that this will not happen, so the question is now on everyone's mind.
|
|
|
|
examplens
Legendary

Activity: 4088
Merit: 4853
|
Well if it's an amateur doing all this (he used AI for the exploit so can't be a professional hacker), then chances are, we are going to see a law enforcement announcement sooner than we think. What is the evidence that he used AI? There is no evidence that the hackers used AI to do his bad work but we all know that AI are used for bad works like this today. I will not blame it on AI at all because if Coldcard did not do something stupid that got the bitcoin of their users lost, AI will not see any vulnerability if there is no vulnerability. It may not be AI, but automation is certainly recognized. Signature: every sweep paid an identical hardcoded 30.0 sat/vB — a 30-75x overpay vs the 0.4-1.0 sat/vB median that week — and left no change output. That looks like an automated tool spending keys it already held, not owners moving funds. Victims: 1,183 native segwit (BIP-84), 7 BIP-49, 6 BIP-44 — consistent with multi-path key scanning.  Source: Galaxy Research on X https://x.com/glxyresearch/status/2083181683067506899?s=20
|
|
|
|
|
Oluwa-btc
|
 |
Today at 02:02:03 PM |
|
I know this sounds like a lot, but it's really not hard.
Self custody comes with self responsibility. Your security is your job. It has to be done right.
This is the moral lesson of everything that happened with the compromise of Coldcard. Hopefully victims affected by this are patience enough until their funds are ready for disbursement. They stand a high risk of being attacked by recovering scammers impersonating Coldcard or one of these top financial bodies and if they can not be recovered, then a proper update should be given to this victims from Coldcard. I'm sorry and at the same time not sorry for the victims ( Because, they have refused to be their own selfcustody and bank ). I'm worried this shouldn't bring a lot of negativity towards cryptocurrency, the reviews and criticism already are overwhelming. I still believe people can be their own security chief, banks and self custody after all these. Indeed a rough in the crypto sphere.
|
| ..Stake.com.. | | | ▄████████████████████████████████████▄ ██ ▄▄▄▄▄▄▄▄▄▄ ▄▄▄▄▄▄▄▄▄▄ ██ ▄████▄ ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██ ██████ ██ ██████████ ██ ██ ██████████ ██ ▀██▀ ██ ██ ██ ██████ ██ ██ ██ ██ ██ ██ ██████ ██ █████ ███ ██████ ██ ████▄ ██ ██ █████ ███ ████ ████ █████ ███ ████████ ██ ████ ████ ██████████ ████ ████ ████▀ ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██ ██ ▀▀▀▀▀▀▀▀▀▀ ██ ▀█████████▀ ▄████████████▄ ▀█████████▀ ▄▄▄▄▄▄▄▄▄▄▄▄███ ██ ██ ███▄▄▄▄▄▄▄▄▄▄▄▄ ██████████████████████████████████████████ | | | | | | ▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄ █ ▄▀▄ █▀▀█▀▄▄ █ █▀█ █ ▐ ▐▌ █ ▄██▄ █ ▌ █ █ ▄██████▄ █ ▌ ▐▌ █ ██████████ █ ▐ █ █ ▐██████████▌ █ ▐ ▐▌ █ ▀▀██████▀▀ █ ▌ █ █ ▄▄▄██▄▄▄ █ ▌▐▌ █ █▐ █ █ █▐▐▌ █ █▐█ ▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█ | | | | | | ▄▄█████████▄▄ ▄██▀▀▀▀█████▀▀▀▀██▄ ▄█▀ ▐█▌ ▀█▄ ██ ▐█▌ ██ ████▄ ▄█████▄ ▄████ ████████▄███████████▄████████ ███▀ █████████████ ▀███ ██ ███████████ ██ ▀█▄ █████████ ▄█▀ ▀█▄ ▄██▀▀▀▀▀▀▀██▄ ▄▄▄█▀ ▀███████ ███████▀ ▀█████▄ ▄█████▀ ▀▀▀███▄▄▄███▀▀▀ | | | ..PLAY NOW.. |
|
|
|
|