Bitcoin Forum
August 02, 2026, 07:27:43 PM *
News: COLDCARD users only: critical vulnerability risks funds stored on COLDCARD devices; immediate action required
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 7 8 [9] 10 11 12 »  All
  Print  
Author Topic: Large-scale Coldcard compromise (1360.23 BTC stolen so far)  (Read 3114 times)
BobbysTransactions
Jr. Member
*
Offline

Activity: 46
Merit: 21


View Profile
August 01, 2026, 09:28:50 PM
 #161

Also, if anyone wants a technical post-mortem, I've come across this one that has just been published by Kevin Loaec from Wizardsardine (Liana): https://wizardsardine.com/blog/coldcard-rng-vulnerability/

That article contains the following sentence:
Quote
"This is the heart of the matter. The STM32 chip in the Coldcard does contain a TRNG, and it works perfectly. It is just that, by the time the seed was generated, nothing was talking to it any more."

Genuine question: How do we really know that the "true random number generator" inside that chip is really spitting out truly random numbers?
PrivacyG
Legendary
*
Offline

Activity: 1596
Merit: 2913


Fight for Privacy.


View Profile
August 01, 2026, 09:35:51 PM
Last edit: August 01, 2026, 09:50:47 PM by PrivacyG
Merited by Pmalek (3), vapourminer (1)
 #162

Genuine question: How do we really know that the "true random number generator" inside that chip is really spitting out truly random numbers?
At the end of the day, you have to trust something.  And this comes from me who questions most things I am using.  If you take the overly paranoid route and question absolutely every thing, you will not only go insane but it will also be impossible to finish questioning and verifying every single thing you work with.  If you do not trust that the TRNG is spitting out truly random numbers, use dice as an entropy source to generate your own from scratch.  That way, you at least know only your hands, your dice and your mind were put at work.

Edit.  But to directly answer your question, I looked it up and found this document (https://www.st.com/resource/en/application_note/dm00073853-stm32-microcontroller-random-number-generation-validation-using-the-nist-statistical-test-suite-stmicroelectronics.pdf) that will answer your question in a ton of detail.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
abel1337
Legendary
*
Online Online

Activity: 2562
Merit: 1147



View Profile WWW
August 01, 2026, 09:36:27 PM
 #163

I just saw an X post that claims that seedphrases generated on Coldcard Mk4s are beginning to be drained now as well. They were considered vulnerable already but the entropy was allegedly not as weak as the one on Mk3 with the affected firmware versions. Here is one such post.

Someone has also reported that they found a critical vulnerability in Bitkey. Perhaps there is a connection or AI found something.
I read the thread but it still wasn't confirmed if the mk4s are really being attacked currently, as the keys are created on mk3 and just migrated on mk4. There is still investigation happening.

People are really active on this issue as this is a large compromise and would most likely affects the integrity of hard wallet companies. This compromise would certainly affect the reputation of coinkite and other hardware companies given that people would think that having a hardware wallet isn't as safe as we thought.

This issue also make other hackers realize that hardware wallet isn't impossible to penetrate.

Mia Chloe
Legendary
*
Offline

Activity: 1148
Merit: 2256


Contact me for your designs...


View Profile
August 01, 2026, 09:37:44 PM
 #164

~snip
I've been using the phrase paper wallet for a long time to refer to simply writing down your seed and yeah it's still the best your opinion may differ buh it doesn't mean you are right and I'm wrong. By the way, the attacker would have not been able to exploit them if those seeds were created in some other airgapped device running Electrum offline.

It may feel like I'm nitpicking on you, but frankly, why do you bring up the "quantum" word? For what reason, seriously? The gravity of this desaster isn't a playfield for bullshit bingo.
Yes you are and what I find offensive is choice of words btw. First off the entire quantum gist all comes from making literally any entropy seem weak only difference is there you're talking more on using public keys instead. Plus I already stated it was neither.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits PREDICT..
█████████████████████████
█████████████████████████
███████████▀▀░░░░▀▀██████
██████████░░▄████▄░░████
█████████░░████████░░████
█████████░░████████░░████
█████████▄▀██████▀▄████
████████▀▀░░░▀▀▀▀░░▄█████
██████▀░░░░██▄▄▄▄████████
████▀░░░░▄███████████████
█████▄▄█████████████████
█████████████████████████
█████████████████████████
.
.WHERE EVERYTHING IS A MARKET..
█████
██
██







██
██
██████
Will Bitcoin hit $200,000
before January 1st 2027?

    No @1.15         Yes @6.00    
█████
██
██







██
██
██████

  CHECK MORE > 
Rymaster
Member
**
Offline

Activity: 469
Merit: 38

-Squidster-


View Profile
August 01, 2026, 10:04:31 PM
 #165

Another coldcard theft reported.

“A total of 1,367.05 BTC has been stolen from 4,585 addresses”

https://x.com/BitcoinMagazine/status/2083634238104940884

Join us over in the Reddit group!  www.reddit.com/r/CryptoCollectibles
promise444c5
Legendary
*
Offline

Activity: 1092
Merit: 1059


All things are numbers


View Profile WWW
August 01, 2026, 10:55:24 PM
 #166

Another coldcard theft reported.

“A total of 1,367.05 BTC has been stolen from 4,585 addresses”

https://x.com/BitcoinMagazine/status/2083634238104940884
Likely didn’t,move their funds out of … Or didn’t update to  create a new seed because they don’t even know what’s going on  Tongue.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits PREDICT..
█████████████████████████
█████████████████████████
███████████▀▀░░░░▀▀██████
██████████░░▄████▄░░████
█████████░░████████░░████
█████████░░████████░░████
█████████▄▀██████▀▄████
████████▀▀░░░▀▀▀▀░░▄█████
██████▀░░░░██▄▄▄▄████████
████▀░░░░▄███████████████
█████▄▄█████████████████
█████████████████████████
█████████████████████████
.
.WHERE EVERYTHING IS A MARKET..
█████
██
██







██
██
██████
Will Bitcoin hit $200,000
before January 1st 2027?

    No @1.15         Yes @6.00    
█████
██
██







██
██
██████

  CHECK MORE > 
Meuserna
Sr. Member
****
Offline

Activity: 331
Merit: 540


View Profile WWW
August 01, 2026, 11:29:04 PM
Merited by LoyceV (4)
 #167

It's very concerning, I see Coldcard wallet is recommended by Jameson Lopp on his blog too.
https://www.lopp.net/bitcoin-information/recommended-wallets.html
Quote
~
Will it be time for him to remove Coldcard from his Recommended wallets list?

Ledger should also be removed because of that seed phrase recovery update they introduced some time ago.

Now the phrase in the phrase "your keys - your coins", the first "your" now means only self-generated, by own hands

That's the approach I took in 2022, when Ledger's key extraction API was revealed. I immediately stopped using my Ledgers, because they're closed source and I couldn't trust the code.

But when I moved to new hardware, I kept asking myself, "How do I prove what this thing generates is correct?" I went a little overboard, but looking back on it... what I did paid off.

First, I generated my own random seed. I printed the BIP39 word list basically in columns and I chopped it into strips. One word per strip. I put the strips in a popcorn bowl. Stir. Pick a word. Write it down. Put the word back in the bowl. Stir. Pick again. I did that 23 times.

I entered the 23 words into Krux to have it generate the 24th word/checksum. I then loaded that 24 word seed into Blockstream Jade to confirm it was legit.

I didn't do this because I don't trust Krux or Jade. I did it because I worried about seeds generated by code. I didn't expect something like this ColdCard hack, but I did wonder about the difference between randomness by code vs randomness I could verify with my own eyes.

I don't know if I mentioned it in this forum, but there's a much easier way to do what I did:

Quote
Entropia v2 Seed Tablets

Choose 11 or 23 words at random, and then use a bitcoin signing device like SeedSigner to calculate the final checksum word that completes your seed phrase.

Here's the link for Entropia, available on BTC Hardware Solutions.

I will always hate Hate HATE Ledger, but I'm thankful that their shady ways taught me to think differently about self custody.

Don't trust. Verify.

Pumpsta
Member
**
Offline

Activity: 64
Merit: 13


View Profile
August 01, 2026, 11:51:00 PM
 #168

What I'm trying to understand about this compromise is if anyone else is at risk? Like if I have a wallet that wasn't generated using a Coldcard then I'm not affected, right? And I'm also unaffected if I generate one on a Coldcard that's not running the compromised version?
Meuserna
Sr. Member
****
Offline

Activity: 331
Merit: 540


View Profile WWW
Today at 12:20:51 AM
Merited by bitmover (3)
 #169

What I'm trying to understand about this compromise is if anyone else is at risk? Like if I have a wallet that wasn't generated using a Coldcard then I'm not affected, right? And I'm also unaffected if I generate one on a Coldcard that's not running the compromised version?

The wallets at risk are those generated on a ColdCard after March 2021, when the bug in ColdCard's firmware was introduced, assuming the wallet was not generated using custom entropy such as dice rolls.

ColdCard's firmware was supposed to do this:
...if custom entropy exists, bypass standard entropy.
Instead, it did this:
...if the option to use custom entropy exists, bypass standard entropy.
This caused ColdCards to always bypass standard entropy.
(oversimplification)

Thus, it became easy for hackers to generate the same seeds as those generated on ColdCards. It's still a lot of seeds to search, but it's a small enough pool that hackers can find 'em and drain wallets.

This entire catastrophe is limited to seeds generated on ColdCards after March 2021 which did not use custom entropy such as dice rolls.

What some people are finding out the hard way is, they're still at risk if they created their seed on a ColdCard but moved it to a different device.

Devices aren't being hacked. Thieves are hunting for wallets generated by ColdCards, because ColdCard effed up how their devices generate seeds.

Bitcoins101
Hero Member
*****
Offline

Activity: 993
Merit: 515


View Profile
Today at 12:22:23 AM
 #170

What I'm trying to understand about this compromise is if anyone else is at risk? Like if I have a wallet that wasn't generated using a Coldcard then I'm not affected, right? And I'm also unaffected if I generate one on a Coldcard that's not running the compromised version?
All ColdCards are effectively compromised. I am hearing about other models getting hacked too. I'm sure some are fine, but are you really going to parse through the lines to see if yours isn't?

Other wallets are not affected, as far as we know.

Karl_3000
Full Member
***
Offline

Activity: 364
Merit: 187


Bitcoin can not fail you


View Profile WWW
Today at 12:23:43 AM
 #171

What I'm trying to understand about this compromise is if anyone else is at risk? Like if I have a wallet that wasn't generated using a Coldcard then I'm not affected, right? And I'm also unaffected if I generate one on a Coldcard that's not running the compromised version?
There are many wallets, we do not know about them all, close source wallets should be very avoided. If the wallet that you are using is trustworthy from community like this forum, you can use passphrase with it. Another one is to use a multisig wallet that is generated from different wallet brands like Electrum, Sparrow and Trezor in 2 of 3 multisig.

bitmover
Legendary
*
Online Online

Activity: 3108
Merit: 7649


Trêvoid █ No KYC-AML Crypto Swaps


View Profile WWW
Today at 12:42:12 AM
 #172

https://x.com/glxyresearch/status/2083623511126638642

Updated estimate:  1,367.05 BTC (~$88.6m) stolen, across 4,585 addresses.

Looks like there are 3 holding addresses.  Which are they?

I know this is one of them



▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|  BTC     XMR  
  DAI     LTC  
   Fees  0.8%    
Pumpsta
Member
**
Offline

Activity: 64
Merit: 13


View Profile
Today at 12:45:08 AM
 #173

WTF that's terrible man!!! So this is happening to seeds generated since 2021, not just the latest update?! Terrifying's an understatement! Shocked

What some people are finding out the hard way is, they're still at risk if they created their seed on a ColdCard but moved it to a different device.

Devices aren't being hacked. Thieves are hunting for wallets generated by ColdCards, because ColdCard effed up how their devices generate seeds.
Just to be clear, you mean it's a risk only if they use the same seed in another hw, not if they transfer the btc to another seed, right?
Meuserna
Sr. Member
****
Offline

Activity: 331
Merit: 540


View Profile WWW
Today at 01:06:57 AM
Merited by vapourminer (4), LoyceV (4)
 #174

WTF that's terrible man!!! So this is happening to seeds generated since 2021, not just the latest update?! Terrifying's an understatement! Shocked

What some people are finding out the hard way is, they're still at risk if they created their seed on a ColdCard but moved it to a different device.

Devices aren't being hacked. Thieves are hunting for wallets generated by ColdCards, because ColdCard effed up how their devices generate seeds.
Just to be clear, you mean it's a risk only if they use the same seed in another hw, not if they transfer the btc to another seed, right?

It's a risk if they use the same seed. The hardware isn't the problem. Hardware isn't being hacked. Wallets are being found because ColdCard's crap code made it possible to guess seeds generated on a ColdCard.

Move the coins to a properly generated seed? You're good!

This is a good reminder that Bitcoin is not in your wallet. It's on the blockchain. That's how thieves are stealing it without needing to access anybody's hardware wallet. ColdCard's crap code made it possible to guess seeds generated on a ColdCard. Thieves are generating those same seeds, searching 'em, and draining the wallets. This would be impossible if ColdCard's generated seeds correctly... but there was an error in ColdCard firmware... and Rodolfo Novak thought he was being oh so clever by making ColdCard's firmware "Source Viewable" instead of Open Source. Same thing, right? Wrong. Since other devs couldn't use his code in their own work, they weren't working with it. Fewer devs actually using the code meant fewer opportunities to find errors and fix them.

This bug should have been found five years ago. I believe, if ColdCard had remained open source, this bug would have been found and fixed years ago.

This is ColdCard's fault.

OLDBOY 003
Newbie
*
Offline

Activity: 4
Merit: 22


View Profile
Today at 01:49:11 AM
Merited by Akuma_ (22)
 #175

This is a painful reminder that behind every Bitcoin address is a real person.

The loss of nearly 1.8 BTC isn't simply a number on a blockchain. For the victim, it represented years of saving, sacrifice, and a plan to protect his family.

Stories like this highlight an important reality of Bitcoin: **self-custody means self-responsibility.**

Before storing significant funds in a wallet, users should:

• Use a hardware wallet for long-term holdings
• Never share seed phrases or private keys
• Verify wallet addresses and transactions carefully
• Keep recovery phrases offline and securely backed up
• Avoid connecting a valuable wallet to unknown Apps
• Revoke suspicious permissions when necessary
• Consider using a separate wallet for everyday transactions
• Test with a small amount before making large transfers

Blockchain transactions are generally irreversible. Once funds are transferred to an attacker-controlled address, recovering them can be extremely difficult.

Most importantly, never assume that a Bitcoin wallet belongs to a wealthy person.

It could belong to a student, a worker, a parent, a retiree—or an entire family's future.

**Bitcoin may be decentralized, but the people behind the addresses are not.**

Stay vigilant. Verify everything before you sign a transaction.
philipma1957
Legendary
*
Online Online

Activity: 4928
Merit: 12309


'The right to privacy matters'


View Profile WWW
Today at 01:58:20 AM
Last edit: Today at 02:17:21 AM by philipma1957
 #176

so

cold card promises

2 to the 256 th power seed


and gave

2 to the 40th power seeds


my key board has 94 letters numbers and symbols.

i can assign 94 tiles to the letters numbers and symbols

this would mean if i picked out from the pile of 94

24 times

i would have a passphrase that is 94 to the 24th power.



i am lazy

but

give me a minute

so 2 to the 256 is 115,792,089,237,316,195,423,570,985,008,687,907,853,269,984,665,640,564,039,457,584,007,913,129,639,936

2 to the 72nd  power  is :                                                                                                             4,722,366,482,869,645,213,696

2 to the 40th   power is :                                                                                                                                 1,099,511,627,776


it is easy to see that cold card set  of seeds is way smaller than a proper set of seeds


but add a passphrase using these tiles.


https://www.amazon.com/100pcs-Wooden-Number-Wedding-Decoration/dp/B07MBJ3DLR/ref=sr_1_9?


I will  put numbers 1 to 94 in a bag shake them

pull out a tile

mark it down

put tile back

pull out a tile mark it down

do this 24 times

giving me a random passphrase of 94 to the 24 power or


The full number form of 94 to the 24th power is 22,650,014,605,289,804,187,822,243,772,656,756,034,402,621,8496


      Ai missed a comma but this should be a tough passphrase

that 24 number passphrase and the seed even the shit seed would be strong.


also if you have a trezor

you can add five passphrase wallets

with five different phases.

my method to make the passphrase would work.

now lose that passphrase and oh well doom..


btw a full 50 long passphrase for trezor is this number in decimal


Copilot Search Branding


94 to the 50th Power as a Full Decimal
The value of 94 to the 50th power is:
453,307,265,607,291,900,093,893,524,017,969,378,495,921,663,609,353,280,195,500,520,148,471,896,610,338,590,954,561,957,187,813,376 Visual Fractions+1.


it is more difficult to crack than a 2 to the 256th power seed.

got the number via A. I.



▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
████████████████████████████████▀
██████████████████████████████▀██▄█
████████████████████████████▀██████
█████████████████████████▀█████████
██████████████████████▀████████████
█▄██▀▀█████████████▀███████▄▄▄█████
███▄████▀▀██████▀▀█████▄▄▀▀▀███████
█████▄▄█████▀▀█▀██████████▄████████
████████▀▀███▄███████████▄█████████
█████████▄██▀▀▀▀███▀▀██████████████
███████████▄▄█▀████▄███████████████
███████████████▄▄██████████████████

 AltairTech.io    Miners  Parts 🖰 Accessories 
_______Based in Missouri, USA._________________Your One-Stop Shop for Bitcoin Mining Solutions_____________________Mining Farm Consulting__________
.
.🛒SHOP NOW .
rdluffy
Legendary
*
Offline

Activity: 3038
Merit: 2032



View Profile WWW
Today at 02:34:33 AM
Merited by LoyceV (4), vapourminer (1)
 #177

Coldcard has just announced that it is sending emails to Coldcard users


https://x.com/COLDCARDwallet/status/2083741922070352247

The saddest part is that most people who receive one of these emails and aren't aware of the attacks will think it's just another one of those phishing emails
I would think so, it looks exactly like those emails we constantly get from “Ledger”

heslo
Legendary
*
Offline

Activity: 1342
Merit: 1360


View Profile
Today at 03:07:56 AM
 #178

Coldcard has just announced that it is sending emails to Coldcard users


https://x.com/COLDCARDwallet/status/2083741922070352247

The saddest part is that most people who receive one of these emails and aren't aware of the attacks will think it's just another one of those phishing emails
I would think so, it looks exactly like those emails we constantly get from “Ledger”



I'm also getting phising emails that look like this from "Coinkite" trying to take advantage of the situation; I have the Ledger leak to thank for that
NotATether
Legendary
*
Offline

Activity: 2408
Merit: 10045


┻┻ ︵㇏(°□°㇏)


View Profile WWW
Today at 03:11:42 AM
Merited by Foxpup (3), vapourminer (1)
 #179

Apparently this draining has been happening for years to a few unsuspecung users, meaning that someone was aware of the randomness flaw since a few years ago.

In 2022, a brand new Coldcard user was drained after transferring funds to it.

https://www.reddit.com/r/Bitcoin/s/NJXFF7hI0a





This definitely makes it a scandal now, given that the victim was blocked for reporting this, and this could possibly see Coinkite employees getting put on trial for this.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
JeffBrad12
Hero Member
*****
Offline

Activity: 3584
Merit: 550


View Profile
Today at 03:18:03 AM
Merited by NotATether (2)
 #180

Coldcard has just announced that it is sending emails to Coldcard users

The saddest part is that most people who receive one of these emails and aren't aware of the attacks will think it's just another one of those phishing emails
I would think so, it looks exactly like those emails we constantly get from “Ledger”
Could've created simple webpage for their victims and the fact that they left the communication open by stating there will be multiple emails coming. Tho I guess they want to wake up their users who buys bitcoin and forget in case they don't know. What victim really needs right now is clear plan to make them whole.

This definitely makes it a scandal now, given that the victim was blocked for reporting this, and this could possibly see Coinkite employees getting put on trial for this.
Several X posts I read said Coinkite's bounty program was bad and researchers are getting personalized "Bugmug" for their findings which is quite ridiculous smh.
Pages: « 1 2 3 4 5 6 7 8 [9] 10 11 12 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!