Bitcoin Forum
August 01, 2026, 06:58:50 PM *
News: COLDCARD users only: critical vulnerability risks funds stored on COLDCARD devices; immediate action required
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 7 [8]  All
  Print  
Author Topic: Large-scale Coldcard compromise (1128.47 BTC stolen so far)  (Read 2183 times)
oll
Full Member
***
Offline

Activity: 319
Merit: 151


old oll


View Profile
Today at 02:41:18 PM
 #141

In my locale, we always come to the conclusion in discussions that open source wallets are better than closed ones, obviously because they do not conceal surprises. But in the age of AI development in open source, if people don't see mistakes, AI will see them, which we witnessed (Coinkite wrote about the use of AI by intruders). If this vulnerability has not been found in the five years of its existence, it has given a false feeling that the code is perfect..
 Of course, the developers are also to blame for making the low-entropy decision. But I think that all developers with open source code should not disdain unnecessary code reviews, both by their own specialists and by the most intelligent AI...
DireWolfM14
Copper Member
Legendary
*
Offline

Activity: 2940
Merit: 5760



View Profile WWW
Today at 02:45:08 PM
 #142

I just want to know from DireWolfM14, how does it develop if you are still using this wallet?
I hope your BTC is not affected by this case.

I do use my ColdCard as my primary hardware wallet, but none of my seeds were generated on it.  I used a different method/device to generate my seeds and I use strong passphrases on every wallet, including the ones that are mostly transitory.  When generating the seed for my cold wallet I added analogue entropy as well.  So far so good, my bitcoin is still sitting pretty, AlhamduliLah.

Definitely a scary situation, though.  I feel bad for those who lost their stash and hopefully the hacker gets busted.

░░░░▄▄████████████▄
▄████████████████▀
▄████████████████▀▄█▄
▄██████▀▀░░▄███▀▄████▄
▄██████▀░░░▄███▀▀██████▄
██████▀░░▄████▄░░░▀██████
██████░░▀▀▀▀▄▄▄▄░░██████
██████▄░░░▀████▀░░▄██████
▀██████▄▄███▀░░░▄██████▀
▀████▀▄████░░▄▄███████▀
▀█▀▄████████████████▀
▄████████████████▀
▀████████████▀▀░░░░
 
 CCECASH 
greysonz
Newbie
*
Offline

Activity: 21
Merit: 1


View Profile
Today at 03:01:54 PM
 #143

It's very concerning, I see Coldcard wallet is recommended by Jameson Lopp on his blog too.
https://www.lopp.net/bitcoin-information/recommended-wallets.html
Quote
~
Will it be time for him to remove Coldcard from his Recommended wallets list?

Ledger should also be removed because of that seed phrase recovery update they introduced some time ago.

Now the phrase in the phrase "your keys - your coins", the first "your" now means only self-generated, by own hands
goldphysicalbitcoin
Member
**
Offline

Activity: 79
Merit: 11


View Profile WWW
Today at 03:16:13 PM
 #144

The actions of the malicious attacker are truly regrettable. For those new to Bitcoin investment, purchasing an ETF or using a custodial service like Coinbase is likely the most suitable option at present; before the advent of mainstream hardware wallets, self-custody relied primarily on paper wallets—a method that remains secure to this day—whereas hardware wallets introduce additional risks that cannot be overlooked.

2014 Gold BTC relics: gold coins fused w/ BTC keys. https://goldphysicalbitcoin.com
PrivacyG
Legendary
*
Offline

Activity: 1596
Merit: 2906


Fight for Privacy.


View Profile
Today at 03:25:12 PM
 #145

This particular bug comes from a weakened entropy source. They used some Python-based RNG instead of their on-device more secure hardware RNG by accident while replacing the GPLv3 code (their obsession with GPL is ultimately what sunk them in the end).
You would think a company that produces Hardware Wallets and develops their Firmware would audit the code before publishing a new version for everyone else to see.  I am not an expert coder my self but looking at the way this vulnerability is described, it sounds like a really stupid mistake that would be easily recognized by an advanced developer like those I assume are developing at Coldcard.

-----

That just doesn't make sense! Anyone with the skills to pull this off shouldn't make such a rookie mistake, unless the account is owned by a scapegoat.
Or could it just be an amateur who's in way over his head? Someone who accidentally stumbled upon this weakness, and suddenly ended up with $70 million in stolen funds?
Is my mind playing really bad games on me right now or years ago there actually was a couple that was showing off their suspiciously luxurious life style on the Internet and they ended up being exposed as the actual thieves of one of the largest Bitcoin hacks in history?

There are so many options!  Such as planning to leave the country with all that Bitcoin to some where you can not be extradited from and being caught right before finishing the plan.  To be honest with you, having the intelligence to steal in a way others did not find yet does not also imply having the intelligence to not get caught.  In fact.  Thieves do extremely stupid mistakes a lot more often than you would think, particularly in the heat of the moment!

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
Pmalek
Legendary
*
Offline

Activity: 3570
Merit: 9408



View Profile
Today at 03:51:44 PM
 #146

I just saw an X post that claims that seedphrases generated on Coldcard Mk4s are beginning to be drained now as well. They were considered vulnerable already but the entropy was allegedly not as weak as the one on Mk3 with the affected firmware versions. Here is one such post.

Someone has also reported that they found a critical vulnerability in Bitkey. Perhaps there is a connection or AI found something.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
JiiBs
Sr. Member
****
Offline

Activity: 924
Merit: 288



View Profile
Today at 03:58:55 PM
 #147

Quote
it could be a cryptographic flaw within the hardware device where the device generates users seed phrases in such a way that an attacker could predict them, similar to the Ill Bloom vulnerability from earlier in the month.

This is the part that catches my interest, how possible can this be, it’s speaks highly of a possible vulnerability that I don’t wish to believe exists within the system. It sounds like an impossibility and could make users believe that the pathway to seed phrase generation isn’t safe.

The volume of Bitcoin that was stolen form this attack though, that’s a lot and in the millions of dollars, quite extreme.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT|
4,000+ GAMES
███████████████████
██████████▀▄▀▀▀████
████████▀▄▀██░░░███
██████▀▄███▄▀█▄▄▄██
███▀▀▀▀▀▀█▀▀▀▀▀▀███
██░░░░░░░░█░░░░░░██
██▄░░░░░░░█░░░░░▄██
███▄░░░░▄█▄▄▄▄▄████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
█████████
▀████████
░░▀██████
░░░░▀████
░░░░░░███
▄░░░░░███
▀█▄▄▄████
░░▀▀█████
▀▀▀▀▀▀▀▀▀
█████████
░░░▀▀████
██▄▄▀░███
█░░█▄░░██
░████▀▀██
█░░█▀░░██
██▀▀▄░███
░░░▄▄████
▀▀▀▀▀▀▀▀▀
|||
▄▄████▄▄
▀█▀
▄▀▀▄▀█▀
▄░░▄█░██░█▄░░▄
█░▄█░▀█▄▄█▀░█▄░█
▀▄░███▄▄▄▄███░▄▀
▀▀█░░░▄▄▄▄░░░█▀▀
░░██████░░█
█░░░░▀▀░░░░█
▀▄▀▄▀▄▀▄▀▄
▄░█████▀▀█████░▄
▄███████░██░███████▄
▀▀██████▄▄██████▀▀
▀▀████████▀▀
.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
░▀▄░▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄░▄▀
███▀▄▀█████████████████▀▄▀
█████▀▄░▄▄▄▄▄███░▄▄▄▄▄▄▀
███████▀▄▀██████░█▄▄▄▄▄▄▄▄
█████████▀▄▄░███▄▄▄▄▄▄░▄▀
███████████░███████▀▄▀
███████████░██▀▄▄▄▄▀
███████████░▀▄▀
████████████▄▀
███████████
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▀▄███░░░▀████░███▄▀██▄
███░████░░░░░▀██░████░███
███░████░█▄░░░░▀░████░███
███░████░███▄░░░░████░███
▀██▄▀███░█████▄░░███▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
OFFICIAL PARTNERSHIP
SOUTHAMPTON FC
FAZE CLAN
SSC NAPOLI
Mate2237
Hero Member
*****
Offline

Activity: 1526
Merit: 675


View Profile WWW
Today at 04:10:26 PM
 #148

If Coldcard knew about this (presumably), I'm thinking what could they have said to protect the victims? This is a critical vulnerability that targets cold storage users, something that hasn't ever occurred before, if I'm not mistaken.

I remember there was an Electrum vulnerability that directed the users to download a malware, but airgapped users were unaffected. This particular case must be unique, and I'm curious how the Coldcard team could have informed the victims without revealing to the attackers the source of the problem (so they could take advantage immediately.)

Good news for people who were drained - they appear to have found the identity of the attacker


Coldcard Wallet theft has an estimated rise to $70M

Galaxy Research has expanded its analysis of the Coldcard wallet incident, and identified 1,196 addresses that lost 1,082.65 BTC, which is approximately $70 million within a 41-minute time period.

Galaxy's on-chain analysis traced the losses across nearly 1,200 wallets, all affected during the same narrow timeframe, suggesting a coordinated exploit.

Source
Italian Panic
Hero Member
*****
Offline

Activity: 1092
Merit: 737


NO DEPO CODE VEGAR7, NO KYC Casino


View Profile WWW
Today at 04:24:08 PM
 #149

It seems the hacker left some traces along the way, such as paying for a blockchain service to check addresses with larger amounts, so it’s safe to say they had carefully studied where and how to strike. It also appears there was a limit of 200 transactions per wallet in the research method, leaving transactions beyond that limit untouched, this indicates a rudimentary approach to the software, which avoided wallets with overly complex transaction histories.

██████
██
██

████████████████
███████████████
█████████████
█████████████▄▄████▄▄████▄▄███████▌██▄▄████▄██
████████████▄██▀▀▀▀██▄██▄███▀███████▄██▀▀▀▀███
██████████▐██▄▄▄▄▄▄██▌▐██▀███████▌▐███████▐██
████████████▐██▀▀▀▀▀▀▀▀▐██▄███████▌▐██▄████▐██
█████████████▀██▄▄▄▄█████▀███▄▄▄██▀██▀██▄▄▄▄███
██████████████▀▀▀▀▀▀██████▀▀▀▀▀▀▄▌███▀▀▀▀▀▀▀
████████████████████████████▄███▄██
███████████████████████████▀█████▀










██
██
██████
▄▄███████▄▄
▄███████████████▄
▄███████████████████▄
▄█████████████████████▄
▄███████████████████████
████████████████████████
█████████████████████████
████████████████████████
▀███████████████████████▀
█████████████████████▀
▀███████████████████▀
▀███████████████▀
▀▀███████▀▀
 
  150 FS NO DEPOSIT BONUS ..... Subscribe to Our Telegram ( > ) .....   PLAY NOW   
gmaxwell
Staff
Legendary
*
Offline

Activity: 4816
Merit: 11274



View Profile WWW
Today at 04:24:57 PM
Merited by Welsh (5), F2b (1), stwenhao (1)
 #150

In my locale, we always come to the conclusion in discussions that open source wallets are better than closed ones, obviously because they do not conceal surprises. But in the age of AI development in open source, if people don't see mistakes, AI will see them, which we witnessed (Coinkite wrote about the use of AI by intruders). If this vulnerability has not been found in the five years of its existence, it has given a false feeling that the code is perfect..
 Of course, the developers are also to blame for making the low-entropy decision. But I think that all developers with open source code should not disdain unnecessary code reviews, both by their own specialists and by the most intelligent AI...

This vulnerability would be just as fast to find with AI if closed source, maybe even faster.

If I were analyzing the firmware of a closed source wallet, I'd have the AI disassemble it and look for where the HW TRNG was read and trace from there.  In this case it wouldn't be read at all (or the code that did would be dead code), and so it would be obvious that it was vulnerable.

In a strange way the open source code was a distraction that hid the behavior because it mostly looked correct.  After the theft reports but before the cause of this was known someone I was talking to mentioned pointing AI at it and I said "Might want to disassemble the firmware to make sure a build issue hasn't made this code get used (link to the fallback PRNG)" and "Challenge it to show you in the disassembly".  --- it can be easy to get confused by misleading code but the binary is definitive.  AI makes analysis of the binary much easier.

A useful lesson to extract from this is that especially now that we have AI these devices should be both reviewed from a source code *and* binary basis, because some vulnerabilities (like this one) would be more obvious from the binary.  It's not an entirely new lesson-- e.g. in libsecp256k1 we've used binary level review (esp for things like timing sidechannels) but now its enough easier that it should be done regularly.

A good review approach would intentionally inject serious faults like this one, and make sure the review process catches it... with the hope that this implies if there were any unknown faults they'd be found too. With AI this could even be automated.
NotATether
Legendary
*
Offline

Activity: 2408
Merit: 10031


┻┻ ︵㇏(°□°㇏)


View Profile WWW
Today at 04:46:37 PM
 #151

I just saw an X post that claims that seedphrases generated on Coldcard Mk4s are beginning to be drained now as well. They were considered vulnerable already but the entropy was allegedly not as weak as the one on Mk3 with the affected firmware versions. Here is one such post.

Someone has also reported that they found a critical vulnerability in Bitkey. Perhaps there is a connection or AI found something.

OK, Coldcard as a brand is finished.

There's no coming back from this for them

And that Bitkey vulnerability better be fixed before it gets exploited too.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
Majestic-milf
Hero Member
*****
Offline

Activity: 1610
Merit: 754



View Profile
Today at 05:04:46 PM
 #152

It seems the hacker left some traces along the way, such as paying for a blockchain service to check addresses with larger amounts, so it’s safe to say they had carefully studied where and how to strike. It also appears there was a limit of 200 transactions per wallet in the research method, leaving transactions beyond that limit untouched, this indicates a rudimentary approach to the software, which avoided wallets with overly complex transaction histories.
So let's say this will help in the investigation, how many users can recover their stolen Bitcoin. In relation to the ColdCard matter, River seems to benefit from this upset or vulnerability because over 3,679 Bitcoin have been recorded as an inflow. It appears that more people are now focused more on institutions managing their funds than trusting hardware wallets.

free-bit.co.in
Hero Member
*****
Offline

Activity: 1834
Merit: 569


Leading Crypto Sports Betting & Casino Platform


View Profile
Today at 05:21:28 PM
 #153

This whole thread is scary to look. To think a bug can destroy your whole life worth of savings os really horrible. Everyone trusts hardware wallets a little more because they are the most secure wallets. But if a bug causes bitcoins to be drained from the wallet like this, then I don't know which hardware wallet to trust the most.

I feel very bad for those who have been affected by this. I hope that the theft of such a huge amount will definitely be caught.

You are right, we actually buy hardware wallet with expectation that it will never generate private key in vulnerable way. But this incident showed that just buying a hardware wallet doesn't automatically guarantee security. Implementation of seed generation is also very important. If you only update the firmware, it won't make an old seed secure if it was generated with a flawed implementation.

However, this particular case should not lead to conclusion that all hardware wallet are insecure.
At the same time, we should not trust any wallet blindly. No matter which wallet you are using it is always good to protect it with strong passphrase.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
nerd225639
Brand new
*
Offline

Activity: 0
Merit: 0


View Profile
Today at 06:26:39 PM
Last edit: Today at 06:37:23 PM by nerd225639
 #154

Hello, I’m new to this forum, and I’m very sorry about what happened. I’ll be very direct there will be a second wave of attacks by Russian attackers. This attack came from Russia.

Some time ago, I saw that several repositories on GitHub were taken down after being reported by someone who had previously stolen 1,000 BTC from a Bitcoin Core wallet.dat. The repositories belonged to a well known user who sells brute force tools.

The Russians are ruthless, and I apologize if I offend anyone by saying that, but that is the reality they have no compassion. I hope the FBI catches those damn thieves. I was going to upload a screenshot showing people in a large Russian speaking group attempting it again.

I’m not trying to justify it, but Telegram should shut those groups down and cooperate with the FBI. I doubt this was the work of a single person it was probably some kind of group or multiple individuals. I seriously doubt they will return the funds.

I read a reply in this thread, and I’m very sorry for the person who lost 1 BTC because of this tragedy.

We know that a 40 bit space is vulnerable to attacks, although some people still believe the keys were effectively protected by the full 256 bit space. In reality, the vulnerable generation process reduced the search space to 40 bits, which is an enormous difference.

Screenshot of the russian group:

https://imgur.com/a/4gHTPzi

I'm not accusing them directly, but it's clear they're creating tools to continue stealing funds.
JangoUnchained
Member
**
Offline

Activity: 214
Merit: 34


View Profile
Today at 06:36:46 PM
 #155

I ran back to the forum after I heard this sad news from a friend today, like wow, is my Bitcoin even safe like this? What is the. Assurance now that Trezor can't be next? I  saw CZ post on twitter and he said that nothing is 100% SaFU, he isn't even helping at all.

AI must have helped to figure that vulnerability out? It's just a guess, I could be wrong, but then again , this is not encouraging at all, the person who did this must be arrested, I hope he get caught in the end.
F2b
Hero Member
*****
Online Online

Activity: 2173
Merit: 936


View Profile
Today at 06:41:29 PM
 #156

The actions of the malicious attacker are truly regrettable. For those new to Bitcoin investment, purchasing an ETF or using a custodial service like Coinbase is likely the most suitable option at present; before the advent of mainstream hardware wallets, self-custody relied primarily on paper wallets—a method that remains secure to this day—whereas hardware wallets introduce additional risks that cannot be overlooked.

Please do not push users towards unsafe solutions. Paper wallets, even if generated offline, were hot wallets (generated on your computer, sent to a printer), and had only one address, which is extremely bad for privacy.
The cryptography behind paper wallets is just as safe as any other wallet, but everything else really isn't.

I just saw an X post that claims that seedphrases generated on Coldcard Mk4s are beginning to be drained now as well. They were considered vulnerable already but the entropy was allegedly not as weak as the one on Mk3 with the affected firmware versions. Here is one such post.

For the record, he posted an update recently telling that the seed was in fact generated on a Mk3 and then migrated to an Mk4.
Which does't mean that Mk4, Mk5 and Q are safe. They aren't.



Also, if anyone wants a technical post-mortem, I've come across this one that has just been published by Kevin Loaec from Wizardsardine (Liana): https://wizardsardine.com/blog/coldcard-rng-vulnerability/

npub1zc4r69x9nxg7h0qcs705k6c5yt7xaydtjrlsthk99vmgg2t2xgssd7mdde
Pages: « 1 2 3 4 5 6 7 [8]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!