Bitcoin Forum
August 02, 2026, 08:22:34 PM *
News: COLDCARD users only: critical vulnerability risks funds stored on COLDCARD devices; immediate action required
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 7 8 9 [10] 11 12 »  All
  Print  
Author Topic: Large-scale Coldcard compromise (1360.23 BTC stolen so far)  (Read 3148 times)
heslo
Legendary
*
Offline

Activity: 1342
Merit: 1360


View Profile
Today at 03:57:00 AM
 #181

Apparently this draining has been happening for years to a few unsuspecung users, meaning that someone was aware of the randomness flaw since a few years ago.

In 2022, a brand new Coldcard user was drained after transferring funds to it.

https://www.reddit.com/r/Bitcoin/s/NJXFF7hI0a





This definitely makes it a scandal now, given that the victim was blocked for reporting this, and this could possibly see Coinkite employees getting put on trial for this.

Wow, that's pretty damning
NotATether
Legendary
*
Offline

Activity: 2408
Merit: 10045


┻┻ ︵㇏(°□°㇏)


View Profile WWW
Today at 05:02:55 AM
Merited by Italian Panic (2)
 #182

Mk4, Q, and Mk5 devices are now also getting drained

https://x.com/i/status/2083530439101239380


 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
stompix
Legendary
*
Offline

Activity: 3696
Merit: 7251



View Profile WWW
Today at 05:11:21 AM
Merited by vapourminer (1)
 #183

This is the moral lesson of everything that happened with the compromise of Coldcard.

Hopefully victims affected by this are patience enough until their funds are ready for disbursement. They stand a high risk of being attacked by recovering scammers impersonating Coldcard or one of these top financial bodies and if they can not be recovered,  then a proper update should be given to this victims from Coldcard. I'm sorry and at the same time not sorry for the victims ( Because, they have refused to be their own selfcustody and bank ). I'm worried this shouldn't bring a lot of negativity towards cryptocurrency,  the reviews and criticism already are overwhelming. I still believe people can be their own security chief, banks and self custody after all these. Indeed a rough in the crypto sphere.

Nutildah !!!!!!!!!!!
Just do it!

There are one hundred times where this moron could have posted his quota shit but no, he chose the most serious thread of all, a discussion about thousands of victims being robbed and he slapped this garbage on top of it!


Mk4, Q, and Mk5 devices are now also getting drained

https://x.com/i/status/2083530439101239380




Let's not spread further panic because of a piece of s***** attention seeker on Twitter


▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|  BTC     XMR  
  DAI     LTC  
   Fees  0.8%    
Meuserna
Sr. Member
****
Offline

Activity: 331
Merit: 540


View Profile WWW
Today at 05:33:52 AM
Merited by vapourminer (4), LoyceV (4), Foxpup (2)
 #184

Mk4, Q, and Mk5 devices are now also getting drained

2-of-3 multisig wallets are next, assuming the owners of those wallets didn't use custom entropy or a passphrase too. Those thefts won't be by the same hacker though.

Now that everyone knows about the flaw in ColdCard's code, three things are clear:

1. Every wannabe hacker will be trying too, and many of them will have significantly better skills than the thief of this heist has.

2. Every wannabe hacker will be looking for similar-ish exploits in other hardware wallets. Especially older ones, or any that are closed source.

3. I'll say it again. 2-of-3 multisig wallets are next, because ColdCard's flawed scheme for generating seeds led to a significantly smaller pool of possible seeds. Hackers are going to create scripts that churn through combinations of those seeds to find multisig wallets. I doubt anything more complex than 2-of-3 can be found, but I do think some 2-of-3 wallets will. And unlike this heist, those will be drained one by one as they are found, because every hacker knows he's competing against every other hacker to find wallets using this exploit.

I could be wrong, but it seems pretty clear that the person who pulled off this heist wasn't very skilled. It sure seems like they used an LLM to find the flaw and create scripts to reproduce the flawed way of generating mnemonics. And it sure seems like they didn't understand the scripts the LLM created for them.

For example: They weren't draining wallets. They were draining addresses. It appears the script stopped searching a wallet when it found an unused address, meaning it left behind any coins after that address.

That tells us, whatever script they had the LLM generate, the script returned a list of addresses and address keys rather than a list of the mnemonics that generated them.

And it appears they were using a script to look up addresses on a block explorer, presumably using an API. That's an incredibly inefficient (ie: slow) way to do it, considering there are published lists of every address with a balance. They could have created a lightning fast database. Doing it the way they did had to take significantly longer. 4x longer? 10x longer?

They left a digital trail. I have to assume they're going to be caught. The sooner the better.

philipma1957
Legendary
*
Online Online

Activity: 4928
Merit: 12309


'The right to privacy matters'


View Profile WWW
Today at 05:35:19 AM
 #185

well if you have a trezor adding a 24 passphrase means

a lot of safety

▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
████████████████████████████████▀
██████████████████████████████▀██▄█
████████████████████████████▀██████
█████████████████████████▀█████████
██████████████████████▀████████████
█▄██▀▀█████████████▀███████▄▄▄█████
███▄████▀▀██████▀▀█████▄▄▀▀▀███████
█████▄▄█████▀▀█▀██████████▄████████
████████▀▀███▄███████████▄█████████
█████████▄██▀▀▀▀███▀▀██████████████
███████████▄▄█▀████▄███████████████
███████████████▄▄██████████████████

 AltairTech.io    Miners  Parts 🖰 Accessories 
_______Based in Missouri, USA._________________Your One-Stop Shop for Bitcoin Mining Solutions_____________________Mining Farm Consulting__________
.
.🛒SHOP NOW .
Italian Panic
Hero Member
*****
Offline

Activity: 1092
Merit: 743


NO DEPO CODE VEGAR7, NO KYC Casino


View Profile WWW
Today at 05:59:26 AM
 #186

Mk4, Q, and Mk5 devices are now also getting drained

https://x.com/i/status/2083530439101239380



The count now is 1367.05 BTC.

There are some differences from previus attacks, now the stolen founds are send to more addresses. Probably there are some changes in attacker software for his/there security.

██████
██
██

████████████████
███████████████
█████████████
█████████████▄▄████▄▄████▄▄███████▌██▄▄████▄██
████████████▄██▀▀▀▀██▄██▄███▀███████▄██▀▀▀▀███
██████████▐██▄▄▄▄▄▄██▌▐██▀███████▌▐███████▐██
████████████▐██▀▀▀▀▀▀▀▀▐██▄███████▌▐██▄████▐██
█████████████▀██▄▄▄▄█████▀███▄▄▄██▀██▀██▄▄▄▄███
██████████████▀▀▀▀▀▀██████▀▀▀▀▀▀▄▌███▀▀▀▀▀▀▀
████████████████████████████▄███▄██
███████████████████████████▀█████▀










██
██
██████
▄▄███████▄▄
▄███████████████▄
▄███████████████████▄
▄█████████████████████▄
▄███████████████████████
████████████████████████
█████████████████████████
████████████████████████
▀███████████████████████▀
█████████████████████▀
▀███████████████████▀
▀███████████████▀
▀▀███████▀▀
 
  150 FS NO DEPOSIT BONUS ..... Subscribe to Our Telegram ( > ) .....   PLAY NOW   
BlackHatCoiner
Legendary
*
Offline

Activity: 2100
Merit: 9981


Cross Chain Crypto Swap


View Profile
Today at 06:49:48 AM
Last edit: Today at 08:04:47 AM by BlackHatCoiner
Merited by vapourminer (1)
 #187

So, I believe the next status quo for securing a cold storage is:

  • Don't trust your device's RNG.
  • Roll a dice 100 times.
  • Verify once that the dice rolls and the seed phrase generated from your hardware wallet signing device equates the one from the iancoleman site. That way you know the seed is really produced from your dice rolls.
  • Use at least either a passphrase or multi-sig.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
Pmalek
Legendary
*
Offline

Activity: 3570
Merit: 9409



View Profile
Today at 06:55:28 AM
 #188

For the record, he posted an update recently telling that the seed was in fact generated on a Mk3 and then migrated to an Mk4.
Which does't mean that Mk4, Mk5 and Q are safe. They aren't.
Yes, I can see that update now as well. However, there are other posts and reports from users claiming to have lost bitcoin from Coldcard Mk4s and seeds generated on that device, not imported recovery phrases from an Mk3 like in the first example. My guess is that we will see more and more of those with time.




What I'm trying to understand about this compromise is if anyone else is at risk? Like if I have a wallet that wasn't generated using a Coldcard then I'm not affected, right? And I'm also unaffected if I generate one on a Coldcard that's not running the compromised version?
It's difficult to tell at the moment. I think it's better not to trust anything that comes out of NVK's mouth right now. If you have a Coldcard and your BTC is still there, I would carefully set up a different cold wallet and move my bitcoin. It's important to not panic and be in a hurry because that's when mistakes happen.

No one can tell you what wallet will be next or if any wallet will be next. Coldcard owners believed they were safe for years and all that changed a few days ago.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
Meuserna
Sr. Member
****
Offline

Activity: 331
Merit: 540


View Profile WWW
Today at 06:56:28 AM
Merited by vapourminer (1)
 #189

Mk4, Q, and Mk5 devices are now also getting drained

https://x.com/i/status/2083530439101239380



The count now is 1367.05 BTC.

There are some differences from previus attacks, now the stolen founds are send to more addresses. Probably there are some changes in attacker software for his/there security.

The reason these attacks are different is surely because they're being done by different attackers.

Once the flaw in ColdCard's way of generating seed phrases became known, hackers worldwide started replicating it to search for wallets.

This is only going to get worse. And it's going to spread to other wallets if AI can find flaws in how they generate seeds - or, in Ledger's case, how the key extraction firmware can be exploited.

As I said above, I believe even 2-of-3 multisig wallets aren't safe from this attack if the seeds were all generated on a ColdCard (which you're not supposed to do!).

If you are unsure about the security of your wallet, please do the following:

1. Generate your own random 24 word seed phrase by randomly choosing 23 words from the BIP39 word list and letting a hardware wallet calculate the 24th word (the checksum). RANDOM! I cannot over-emphasize that word. The words must be chosen randomly. This ColdCard attack is due to a lack of true randomness.

2. Write the seed phrase on paper. Make a metal backup. Store the seed phrase somewhere only you have access to.

3. Use a strong passphrase. I recommend 7 words or more, all lowercase, with a space between each word. That's uncrackable and it's easily human readable, which protects you from your own errors. Write the passphrase on paper. Make a metal backup. Store the passphrase somewhere only you have access to, separate from where the seed phrase is stored.

4. Save the first address for the wallet. Then, wipe the wallet out and restore it manually, from scratch, to confirm you get the same first address.

I rattled this post off quickly. Apologies for typos.

UmerIdrees
Hero Member
*****
Offline

Activity: 3024
Merit: 948



View Profile WWW
Today at 06:59:39 AM
 #190

so

cold card promises

2 to the 256 th power seed


and gave

2 to the 40th power seeds


Yeah, that's the problem with Cold Card, and I heard that they have been doing this for the older version of their wallet and not on their latest versions. Does this mean that anyone who has a new or recent Coldcard wallet is safe ?

And for the older ones, if they still have funds in their wallet, it's better to transfer them somewhere else, maybe Electrum in the first place, so they do not lose their bitcoins.

LoyceV
Legendary
*
Offline

Activity: 4116
Merit: 22399


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
Today at 07:56:48 AM
Merited by vapourminer (1)
 #191

So, I believe the next status quo for securing a cold storage is:
  • Don't trust your device's RNG.
  • Roll a dice 100 times.
  • Verify once that the dice rolls and the seed phrase generated from your hardware wallet equates the one from the iancoleman site. That way you know the seed is really produced from your dice rolls.
  • Use at least either a passphrase or multi-sig.
That still doesn't protect you if the hardware wallet broadcasts your seed phrase, and after Ledger's betrayal, my confidence in black box devices didn't get any higher.

RANDOM! I cannot over-emphasize that word. The words must be chosen randomly.
For the majority of users, this is probably a very bad idea. The many weak brainwallets from years ago show how bad humans are at this.
It would be good to "combine" randomness: get a random seed from a hardware wallet, create your own random seed, add them together, wrap around the 2^256 limit if needed, and you'll have a seed phrase made from the combined randomness of 2 random seeds. Even if one of them is flawed, the end-result is still random. But, as far as I know, there's no standard software for doing this.

Does this mean that anyone who has a new or recent Coldcard wallet is safe ?
Can you ever trust a company again after such a major fuckup?

Quote
And for the older ones, if they still have funds in their wallet, it's better to transfer them somewhere else, maybe Electrum in the first place, so they do not lose their bitcoins.
For large amounts, create that Electrum wallet offline an a system that won't go online again. Keep your keys cold.

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
BlackHatCoiner
Legendary
*
Offline

Activity: 2100
Merit: 9981


Cross Chain Crypto Swap


View Profile
Today at 08:04:26 AM
Merited by LoyceV (4)
 #192

That still doesn't protect you if the hardware wallet broadcasts your seed phrase, and after Ledger's betrayal, my confidence in black box devices didn't get any higher.
My bad, signing device, not hardware wallet.

Quote
For large amounts, create that Electrum wallet offline an a system that won't go online again. Keep your keys cold.
I would stay away from any RNG other than dice rolls. If the AI could find this subtle line in Coldcard' source code, and vulnerabilities in critical software like the linux kernel, I expect more subtle issues to be found near the system.

Electrum is one of the best choices as open-source reputable wallet software, but the weakness will be found in the firmware or the kernel level, not the wallet. I recommend signing devices, dice rolls for entropy, and multi-sig and/or passphrase.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
LoyceV
Legendary
*
Offline

Activity: 4116
Merit: 22399


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
Today at 08:10:15 AM
 #193

I recommend signing devices, dice rolls for entropy, and multi-sig and/or passphrase.
So far for Bitcoin ever going mainstream Sad

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
BlackHatCoiner
Legendary
*
Offline

Activity: 2100
Merit: 9981


Cross Chain Crypto Swap


View Profile
Today at 08:14:03 AM
 #194

So far for Bitcoin ever going mainstream Sad
You didn't really thought being your own bank would be that easy. A new age for self-custody begins.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
Meuserna
Sr. Member
****
Offline

Activity: 331
Merit: 540


View Profile WWW
Today at 08:50:30 AM
 #195

So far for Bitcoin ever going mainstream Sad
You didn't really thought being your own bank would be that easy. A new age for self-custody begins.

You are right.

Going forward, those not ready for the challenges of doing self custody should probably just buy into ETFs. It saddens me to say that, but I believe it to be the truth.

Those with the technical ability to do self custody should probably create their own seed phrases as explained above, and also use a strong passphrase. And they should only use fully open source hardware wallets.

The days of "buy this brand's hardware wallet and you're good" are coming to an end, and really, that mentality was never wise.

F2b
Hero Member
*****
Offline

Activity: 2175
Merit: 937


View Profile
Today at 09:45:55 AM
 #196

Why doesn't coldcard rent a bunch of GPU's and attack the seed phrases themselves before the hackers get any more?  This way they can save at least some people from losing their coins.

Well in this case, once they're done rugging their users, how do they determine which addresses to send the bitcoins to?


RANDOM! I cannot over-emphasize that word. The words must be chosen randomly.
For the majority of users, this is probably a very bad idea. The many weak brainwallets from years ago show how bad humans are at this.
It would be good to "combine" randomness: get a random seed from a hardware wallet, create your own random seed, add them together, wrap around the 2^256 limit if needed, and you'll have a seed phrase made from the combined randomness of 2 random seeds. Even if one of them is flawed, the end-result is still random. But, as far as I know, there's no standard software for doing this.

Yeah that's what I pointed out earlier. Thanks for stressing it Smiley

npub1zc4r69x9nxg7h0qcs705k6c5yt7xaydtjrlsthk99vmgg2t2xgssd7mdde
SamReomo
Hero Member
*****
Offline

Activity: 1610
Merit: 970


Automatic Exchange


View Profile
Today at 10:15:52 AM
 #197

Electrum is better option for holders especially for those who use it as a cold wallet and never make that wallet online. Cold wallet is the only safe option to hold your coins, I never supported hardware wallets and I'll never support those in future. It's better to have an open source software wallet like Electrum than having a hardware wallet. Those who're holding their coins at hardware wallets should at least be more cautious now because they might lose their coins to an hacker if somehow the hacker finds a loophole or vulnerability in the wallet's firmware.

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|  BTC     XMR  
  DAI     LTC  
   Fees  0.8%    
NotATether
Legendary
*
Offline

Activity: 2408
Merit: 10045


┻┻ ︵㇏(°□°㇏)


View Profile WWW
Today at 10:32:56 AM
 #198

Electrum is better option for holders especially for those who use it as a cold wallet and never make that wallet online. Cold wallet is the only safe option to hold your coins, I never supported hardware wallets and I'll never support those in future. It's better to have an open source software wallet like Electrum than having a hardware wallet. Those who're holding their coins at hardware wallets should at least be more cautious now because they might lose their coins to an hacker if somehow the hacker finds a loophole or vulnerability in the wallet's firmware.

Hey, I use electrum, but I would much rather have the coins stored on an offline device, with a seed of my choosing, than attached as a wallet file on a PC which can theoretically be copied elsewhere.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
Cricktor
Legendary
*
Offline

Activity: 1568
Merit: 4191



View Profile
Today at 10:38:31 AM
Merited by vapourminer (1)
 #199

Also, if anyone wants a technical post-mortem, I've come across this one that has just been published by Kevin Loaec from Wizardsardine (Liana): https://wizardsardine.com/blog/coldcard-rng-vulnerability/
Thanks for this article, quite nicely written and a good deep dive. To me it confirms that Coinkite screwed up really badly. You don't leave a code path in your firmware that yields terrible security. Your firmware has to fail hard and refuse to generate terrible security. EVERY hardware firmware has to be like that (to fail hard, instead of producing and using predictable entropy, I mean)!

It's bonkers that this left unnoticed for half a decade. It shouldn't come as a surprise when there'll likely be some more free riders in addition to the initial attacker to take advantage of such a terrible low-entropy flaw.


Why doesn't coldcard rent a bunch of GPU's and attack the seed phrases themselves before the hackers get any more?  This way they can save at least some people from losing their coins.
Could in theory be saving all those poor Coldcard users who aren't aware of the severe flaw of their hardware wallet. But, there'll be a big issue for the real wallet owner to prove it's his wallet and seed when the seed is basically public.

And, shrug..., you want to rely on a company which screwed up their coding so badly?


The saddest part is that most people who receive one of these emails and aren't aware of the attacks will think it's just another one of those phishing emails
I would think so, it looks exactly like those emails we constantly get from “Ledger”
If Coinkite were any professional, they could've sent their emails as properly cryptographically signed messages, maybe as Bitcoin signed message from a safe(!) Bitcoin address they published from their early days.

I would want to see that from every company that makes hardware wallets. The reality is rather sad on this subject.

Easily verifiable and unspoofable, cryptographically signed emails from hardware wallet companies could also end all those scam emails of evil pretenders.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits..REWARDING, BEYOND LIMITS...
█████████████████████████
█████████████████████████
███████████▀▀░░▀█▄░░▀████
████████▀░░░░░░░░▀█▄░████
███████░░░░▄▄░░▄░░░▀█████
██████░░░░░▀▀▄██▀░░░░████
█████░░░██░▄██▀▄▄░░░█████
████░░░░░▄██▀░░▀▀░░██████
█████▄░░▀█▀░██░░░░███████
████░▀█▄░░░░░░░░▄████████
████▄░░▀█▄░░▄▄███████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████▀░░▀░███████████
████████░░░▄░█░██████████
███████████▌▐██░█████████
███████████░███▌▐████████
██████████░█████░████████
██████▀░▄░▀███▀░▄░▀█████
█████░▄▀░░░░█░▄▀░░░░█████
█████░░░░░░░█░░░░░░░█████
██████▄░░░▄███▄░░░▄██████
█████████████████████████
█████████████████████████


























  PLAY NOW  
zabzob
Member
**
Offline

Activity: 161
Merit: 57


View Profile
Today at 11:41:55 AM
 #200

Won't be easy for the thieves to spend the stolen coins. Will take a lot of mixing.
Pages: « 1 2 3 4 5 6 7 8 9 [10] 11 12 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!