Bitcoin Forum
August 04, 2026, 11:25:01 AM *
News: COLDCARD users only: critical vulnerability risks funds stored on COLDCARD devices; immediate action required
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 [13] 14 15 »  All
  Print  
Author Topic: Large-scale Coldcard compromise (1360.23 BTC stolen so far)  (Read 4479 times)
Somegory
Full Member
***
Offline

Activity: 364
Merit: 185



View Profile
August 03, 2026, 05:58:59 AM
Merited by vapourminer (1)
 #241

It's looking like the attack isn't over yet, coin telegraph released this 3 hours ago.




My question to ColdCard team is what the hell are they doing to put an end to this attacks? It's slowly leaving the MK3 and into the supposed better versions of their hardware wallets.

The 4TH wave ?


Alex Thorn isn't even part of the team and he knew this already?




ColdCard shouldn't have existed, maybe too much of everything is happening here? If Trezor and Electrum is all we had in crypto space maybe it's for the best? Different companies are coming out with different hardware wallets, who is testing them for vulnerability?

I thought hardware wallets always go through rigourous testing? I thought hardware wallet been new always find people who are capable of jailbreaking their innovation and pay them in return like some Bounty of vulnerability?  I doubt that ColdCard went through this?

Wind_FURY
Legendary
*
Offline

Activity: 3724
Merit: 2210



View Profile
August 03, 2026, 06:28:48 AM
 #242

The ColdCard situation showed the community that Bitcoin still has a very long journey before it actually reaches mass adoption.

But TODAY, we lost some users. We can't blame those people. You would probably have the same viewpoint if you lost your entire life-savings held in Bitcoin.

 Cry

Quote

8 years of stacking, gone. I think it's time to move on.

I believed in Bitcoin. Holding it gave me peace of mind because my country has faced several FATF sanctions. I was glad to find a kind of money that cannot be censored or debased because I just want to protect myself from the money printing and my country's weak and inflated currency comapred to the dollar.

I’m 39, and I was hoping to have a good financial cushion before 50. But today, my 2 BTC were drained.

Losing my Bitcoin has changed my mindset. It’s no longer about finishing the race first. At this point, I just want to finish it. But losing my BTC feels like I’m back at the starting line. I lost years of hard work and time.

I thought I was secure because Cold Card was always praised as one of the best and most secure wallets. It’s open source, so anyone can verify.

I’m done with Bitcoin. I’m not even sure if I still believe in it. I don’t know what the future holds for it anymore. I could have stayed with traditional investments and lived a normal life. Maybe I should have just moved everything into a Bitcoin ETF when they launched. But I don't know. It's too late to do it.

To everyone who has lost their BTC, I wish you the best and good health. I hope you find the strength to start again.

https://www.reddit.com/r/Bitcoin/comments/1vclm91/8_years_of_stacking_gone_i_think_its_time_to_move/



This gets to me man.

I feel for this person.


Personally, I believe CoinKite/ColdCard should be investigated and sued. The posts I'm reading in X show that the actors behind the development of that hardware wallet were negligent, AND therefore liable.

Those users who lost their Bitcoin don't deserve to be in their current situation.

Italian Panic
Hero Member
*****
Offline

Activity: 1092
Merit: 752


NO DEPO CODE VEGAR7, NO KYC Casino


View Profile WWW
August 03, 2026, 07:42:31 AM
 #243

The attack is not ended, maybe another one hackers or hack team is on work to drain more BTC in people addresses.
At this point, we can safely say that Coldcard can be flushed down the toilet and we can move on to something else. I don’t think they wil regain the trust of their current and future customers.

Projected BTC drained count tell about:





██████
██
██

████████████████
███████████████
█████████████
█████████████▄▄████▄▄████▄▄███████▌██▄▄████▄██
████████████▄██▀▀▀▀██▄██▄███▀███████▄██▀▀▀▀███
██████████▐██▄▄▄▄▄▄██▌▐██▀███████▌▐███████▐██
████████████▐██▀▀▀▀▀▀▀▀▐██▄███████▌▐██▄████▐██
█████████████▀██▄▄▄▄█████▀███▄▄▄██▀██▀██▄▄▄▄███
██████████████▀▀▀▀▀▀██████▀▀▀▀▀▀▄▌███▀▀▀▀▀▀▀
████████████████████████████▄███▄██
███████████████████████████▀█████▀










██
██
██████
▄▄███████▄▄
▄███████████████▄
▄███████████████████▄
▄█████████████████████▄
▄███████████████████████
████████████████████████
█████████████████████████
████████████████████████
▀███████████████████████▀
█████████████████████▀
▀███████████████████▀
▀███████████████▀
▀▀███████▀▀
 
  150 FS NO DEPOSIT BONUS ..... Subscribe to Our Telegram ( > ) .....   PLAY NOW   
negotiation4
Newbie
*
Offline

Activity: 9
Merit: 15


View Profile
August 03, 2026, 07:59:26 AM
Merited by LoyceV (4), BlackHatCoiner (4), vapourminer (1), ABCbits (1)
 #244

Seeing some of the responses to this makes my blood boil a bit on behalf of the victims.

"Oh they should have added passphrase, should have used dice, etc."

Sure - in hindsight, obviously, that would have protected them from this attack. But this is not correlated with whether this is something they should have done. In my mind - this is not what a passphrase is meant to protect against. It is for the case where your exact seed gets exposed, if your backup gets stolen, if it's accidentally uploaded to the internet, etc.

An equivalent bug could have seen the initial seed be perfectly fine, and then adding a passphrase through some bug eliminates a lot of that initial seed entropy. Or that the dice roll entries delete the initial entropy. Then what would people say? "Oh you should have verified the code and trusted the hardware RNG." It's easy to be wise after the fact.

It's just a mixture of bad luck and negligence on the part of the developer(s).

What scares me about this is that it just feels so random, so unavoidable on the part of the users. It feels like how when you get on a plane you're hoping it doesn't crash, but one in a few million will go down just out of sheer bad luck, through no fault of your own.

I think my biggest taking from this is just that spreading across 2-4 different technologies is probably worthwhile. Other than that I'm not sure there is much of a lesson here for the end user. It just sucks.

I'm sorry.
cygan
Legendary
*
Online Online

Activity: 3962
Merit: 12977


icarus-cards.eu


View Profile WWW
August 03, 2026, 08:01:45 AM
Merited by Foxpup (5), ABCbits (5), vapourminer (4), LoyceV (4), bitmover (4), virginorange (3), hosemary (2), NotATether (2), mole0815 (1), julerz12 (1), flatfly (1)
 #245

for everyone: here's a visual representation and explanation of how the entropy attack came about...





https://x.com/Bitcoin_Devs

█████████████████████████
██████████████▀▄▄▄▀██████
████████▀▀▄▄████▄▄▀███
██████████████
████▀▄▄████████████
██▀██▀▀▀▀██
███▄▀▀███████
█▀███████████▄█
█▄▀▄██▀███▄████▄██
███▄█████▄▄▄████
█████▄████▄▄▄▀▀▄▄██████
███████▄▀▀▀▀▄▄▄██████████
█████████████████████████
.
 Jackpot ter .....  COMMUNITY POWERED CRYPTO CASINO  
▄███████████████████████▄
█████████████████████████
█████████████████████████
██████▄░▄▄▀██████▀▄██████
███████▄░█▄░███▀▄████████
█████████▄▀█░▀▄██████████
██████████▄▀█▄▀██████████
██████████▀▄░█▄▀█████████
████████▀▄███░██░▀███████
██████▀▄██████░▀▀░▀██████
█████████████████████████
█████████████████████████
▀███████████████████████▀
▄███████████████████████▄
█████████████████████████
█████████████████████████
███████████████▀▀░░▐█████
███████████▀▀░░░░░░██████
███████▀▀░░░▄▄▀░░░░██████
████▀░░░░░▄█▀░░░░░▐██████
██████▄▄██▀░░░░░░░▐██████
███████████▄░░░░░░███████
██████████████▄░░▄███████
█████████████████████████
█████████████████████████
▀███████████████████████▀
▄███████████████████████▄
█████████████████████████
█████████████████████████
██████▀░░░▀▀▀▀▀░░░▀██████
█████▀░░░░░░░░░░░░░▀█████
████▀░░░░░░░░░░░░░░░▀████
████░░░░▄█▄░░░▄█▄░░░░████
███▌░░░░▀█▀░░░▀█▀░░░░▐███
███▌░░░░▄░░░░░░░▄░░░░▐███
█████▄▄░▄█▄▄▄▄▄█▄░▄▄█████
█████████████████████████
█████████████████████████
▀███████████████████████▀
 
  PLAY NOW  
OmegaStarScream
Staff
Legendary
*
Offline

Activity: 4284
Merit: 7523



View Profile
August 03, 2026, 08:32:18 AM
Merited by vapourminer (1)
 #246

So according to Alex thorn (from Galaxy)[1] a coldcard victim had 17 BTC stolen from his wallet, swapped to ETH (through Thorchain) and then sent to a KYCed account in Duel's gambling platform.

This does not look however, like it's from the original exploiter:

-snip-
unfortunately, these funds are not part of the large wave 1, 2, and 3 waves identified by
@glxyresearch
 

there are now smaller operators and copycats out here attacking remaining coldcard seeds



It also looks like wallets that have passphrases are being drained as well[2].

Added context, passphrase was two regular words, nothing super complex.

Main takeaway: attackers have moved from not only attacking low hanging fruit of low entropy seeds onto also brute forcing low entropy passphrases in combination.

[1] https://x.com/intangiblecoins/status/2083792644048597326
[2] https://x.com/BTCsessions/status/2084024733511921691

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
UmerIdrees
Hero Member
*****
Offline

Activity: 3024
Merit: 950



View Profile WWW
August 03, 2026, 09:00:07 AM
 #247

My question to ColdCard team is what the hell are they doing to put an end to this attacks? It's slowly leaving the MK3 and into the supposed better versions of their hardware wallets.

The 4TH wave ?

If Coldcard were that capable on handling this, they wouldn't have left the Loophole in the first place.

But my concern is what are people doing here?  If anyone says that their wallet has been drained off in the 4th wave, what was he doing before? Why can't everyone move their funds out immediately? It's not a centralised exchange or something where they can put a halt on your withdrawals ?

I would call it laziness on the people too.

ultrloa
Legendary
*
Offline

Activity: 3458
Merit: 1471



View Profile WWW
August 03, 2026, 09:01:46 AM
Merited by vapourminer (1)
 #248

The ColdCard situation showed the community that Bitcoin still has a very long journey before it actually reaches mass adoption.

But TODAY, we lost some users. We can't blame those people. You would probably have the same viewpoint if you lost your entire life-savings held in Bitcoin.

 Cry

Quote

8 years of stacking, gone. I think it's time to move on.

I believed in Bitcoin. Holding it gave me peace of mind because my country has faced several FATF sanctions. I was glad to find a kind of money that cannot be censored or debased because I just want to protect myself from the money printing and my country's weak and inflated currency comapred to the dollar.

I’m 39, and I was hoping to have a good financial cushion before 50. But today, my 2 BTC were drained.

Losing my Bitcoin has changed my mindset. It’s no longer about finishing the race first. At this point, I just want to finish it. But losing my BTC feels like I’m back at the starting line. I lost years of hard work and time.

I thought I was secure because Cold Card was always praised as one of the best and most secure wallets. It’s open source, so anyone can verify.

I’m done with Bitcoin. I’m not even sure if I still believe in it. I don’t know what the future holds for it anymore. I could have stayed with traditional investments and lived a normal life. Maybe I should have just moved everything into a Bitcoin ETF when they launched. But I don't know. It's too late to do it.

To everyone who has lost their BTC, I wish you the best and good health. I hope you find the strength to start again.

https://www.reddit.com/r/Bitcoin/comments/1vclm91/8_years_of_stacking_gone_i_think_its_time_to_move/



This gets to me man.

I feel for this person.


Personally, I believe CoinKite/ColdCard should be investigated and sued. The posts I'm reading in X show that the actors behind the development of that hardware wallet were negligent, AND therefore liable.

Those users who lost their Bitcoin don't deserve to be in their current situation.

Look at the regulators response after that exploit happened on Coldcard .

Quote
The incident unfolded as regulators from the European Union Agency for Cybersecurity (ENISA), the UK’s National Cyber Security Centre (NCSC), and the U.S. National Institute of Standards and Technology (NIST) intensified their push for secure-by-design development. Though these two stories may appear unrelated—one involving a cryptocurrency hardware wallet, the other a broad regulatory shift they converge on the same urgent lesson: modern security failures begin long before an attacker strikes, often in the invisible assumptions embedded in cryptographic implementations and system architecture.

Got that information in this site https://overcentral.com/en/coldcard-flaw-bitcoin-theft

So instead of advising or pushing to develop a more secure wallet. Why not do some investigation on them right? Because who knows maybe they could find something that can help to file a case against CoinKite and give proper justice to those people got affected in this incident.

Sad to read those stories shared by people got affected with this exploit. Many of them really thinks they are using a safe wallet and there funds is safe with them.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT|
4,000+ GAMES
███████████████████
██████████▀▄▀▀▀████
████████▀▄▀██░░░███
██████▀▄███▄▀█▄▄▄██
███▀▀▀▀▀▀█▀▀▀▀▀▀███
██░░░░░░░░█░░░░░░██
██▄░░░░░░░█░░░░░▄██
███▄░░░░▄█▄▄▄▄▄████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
█████████
▀████████
░░▀██████
░░░░▀████
░░░░░░███
▄░░░░░███
▀█▄▄▄████
░░▀▀█████
▀▀▀▀▀▀▀▀▀
█████████
░░░▀▀████
██▄▄▀░███
█░░█▄░░██
░████▀▀██
█░░█▀░░██
██▀▀▄░███
░░░▄▄████
▀▀▀▀▀▀▀▀▀
||.
|
▄▄████▄▄
▀█▀
▄▀▀▄▀█▀
▄░░▄█░██░█▄░░▄
█░▄█░▀█▄▄█▀░█▄░█
▀▄░███▄▄▄▄███░▄▀
▀▀█░░░▄▄▄▄░░░█▀▀
░░██████░░█
█░░░░▀▀░░░░█
▀▄▀▄▀▄▀▄▀▄
▄░█████▀▀█████░▄
▄███████░██░███████▄
▀▀██████▄▄██████▀▀
▀▀████████▀▀
.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
░▀▄░▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄░▄▀
███▀▄▀█████████████████▀▄▀
█████▀▄░▄▄▄▄▄███░▄▄▄▄▄▄▀
███████▀▄▀██████░█▄▄▄▄▄▄▄▄
█████████▀▄▄░███▄▄▄▄▄▄░▄▀
███████████░███████▀▄▀
███████████░██▀▄▄▄▄▀
███████████░▀▄▀
████████████▄▀
███████████
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▀▄███░░░▀████░███▄▀██▄
███░████░░░░░▀██░████░███
███░████░█▄░░░░▀░████░███
███░████░███▄░░░░████░███
▀██▄▀███░█████▄░░███▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
OFFICIAL PARTNERSHIP
SOUTHAMPTON FC
FAZE CLAN
SSC NAPOLI
hosemary
Legendary
*
Offline

Activity: 3206
Merit: 7146



View Profile
August 03, 2026, 09:21:19 AM
Merited by OmegaStarScream (2), vapourminer (1)
 #249

But my concern is what are people doing here?  If anyone says that their wallet has been drained off in the 4th wave, what was he doing before? Why can't everyone move their funds out immediately? It's not a centralised exchange or something where they can put a halt on your withdrawals ?
Not all people are aware of what's happening with Coldcard wallets.
Many users probably generated a wallet on Coldcard, sent their funds to it, and assumed they would be 100% safe.

You can't expect all Bitcoin investors to stay up to date with every new development. The incident only started three days ago.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits..REWARDING, BEYOND LIMITS...
█████████████████████████
█████████████████████████
███████████▀▀░░▀█▄░░▀████
████████▀░░░░░░░░▀█▄░████
███████░░░░▄▄░░▄░░░▀█████
██████░░░░░▀▀▄██▀░░░░████
█████░░░██░▄██▀▄▄░░░█████
████░░░░░▄██▀░░▀▀░░██████
█████▄░░▀█▀░██░░░░███████
████░▀█▄░░░░░░░░▄████████
████▄░░▀█▄░░▄▄███████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████▀░░▀░███████████
████████░░░▄░█░██████████
███████████▌▐██░█████████
███████████░███▌▐████████
██████████░█████░████████
██████▀░▄░▀███▀░▄░▀█████
█████░▄▀░░░░█░▄▀░░░░█████
█████░░░░░░░█░░░░░░░█████
██████▄░░░▄███▄░░░▄██████
█████████████████████████
█████████████████████████


























  PLAY NOW  
decodx
Hero Member
*****
Offline

Activity: 1484
Merit: 960


#kycfree 🗽


View Profile
August 03, 2026, 09:30:19 AM
Merited by LoyceV (4), vapourminer (2), tvbcof (1), NotFuzzyWarm (1)
 #250

My question to ColdCard team is what the hell are they doing to put an end to this attacks? It's slowly leaving the MK3 and into the supposed better versions of their hardware wallets.

The 4TH wave ?

If Coldcard were that capable on handling this, they wouldn't have left the Loophole in the first place.

But my concern is what are people doing here?  If anyone says that their wallet has been drained off in the 4th wave, what was he doing before? Why can't everyone move their funds out immediately? It's not a centralised exchange or something where they can put a halt on your withdrawals ?

I would call it laziness on the people too.

First of all, it's the middle of summer in the Northern Hemisphere, for goodness sake! Holidays, travel, school break… Millions upon millions are all around, away on vacation, thousands of miles away from their houses, businesses, or bank vaults where their hardware wallets might be stored. It's a physical device, after all.

Cold storage exists so you don't have to constantly monitor social media or panic-check Telegram channels every single day. These devices are tucked away in bank vaults, home safes, or locked away miles away from where people are currently traveling.

If a hardware setup requires users to drop everything, race home from a trip, and move their funds within hours just to survive a vendor's screw-up, the fault lies entirely with the broken hardware - not the owner enjoying their life.

▄███████████████████████▄
███████████████████████
████████████▀▀██████████
████████████████████████
██████████▄▄██████████
█████████████████████
███████████████████████
█████████████████████
██████████▀▀██████████
████████████████████████
██████████▄▄████████████
███████████████████████
▀███████████████████████▀
 
 MoBit 
████
██
██
██
██
██
██
██
██
██
██
██
████
 NO   LOGS
 
 LOW  FEES
 
 PGP  GUARANTEE
████
██
██
██
██
██
██
██
██
██
██
██
████
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
negotiation4
Newbie
*
Offline

Activity: 9
Merit: 15


View Profile
August 03, 2026, 10:15:22 AM
 #251

So according to Alex thorn (from Galaxy)[1] a coldcard victim had 17 BTC stolen from his wallet, swapped to ETH (through Thorchain) and then sent to a KYCed account in Duel's gambling platform.
(...)

Honestly surprising they would use a KYCed account. Duel seems to process amounts this large without KYC with no problem.
JangoUnchained
Member
**
Offline

Activity: 217
Merit: 35


View Profile
August 03, 2026, 10:56:38 AM
Merited by NotFuzzyWarm (1)
 #252

We have the answer already, it's too obvious that coldcard Devs aren't capable at all, I did my own research only to find out that they don't even pay their bug hunters in the past, like after that who would want to look into their security? They aren't going to pay anyway.


I did my research, at first everything seem normal right? Some behaviours you can get from other companies as well. But that's not the case with CoinKite.



👆 This is who CoinKite/ColdCard company truly is.
Once you innovate a new hardware wallet what else would you do? Launch bug hunting season on it, let hackers find a bug or more for rewards, not for the sake of your company but to make sure that what you built is reliable.
BlackHatCoiner
Legendary
*
Offline

Activity: 2100
Merit: 10005


Cross Chain Crypto Swap


View Profile
August 03, 2026, 11:10:54 AM
Merited by vapourminer (1)
 #253

https://x.com/BTCsessions/status/2084024733511921691

The attackers have started draining wallets on Coldcard devices WITH passphrase. As per the tweet, it was a pretty simple passphrase (two extra words), but this shows the attack is active and they are searching everything. If you personally know any Coldcard user who feels safe with his "strong passphrase", it's best to reach them out as soon as possible.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
negotiation4
Newbie
*
Offline

Activity: 9
Merit: 15


View Profile
August 03, 2026, 11:28:44 AM
Merited by BlackHatCoiner (4), vapourminer (1)
 #254

https://x.com/BTCsessions/status/2084024733511921691

The attackers have started draining wallets on Coldcard devices WITH passphrase. As per the tweet, it was a pretty simple passphrase (two extra words), but this shows the attack is active and they are searching everything. If you personally know any Coldcard user who feels safe with his "strong passphrase", it's best to reach them out as soon as possible.
Two extra words from the 2048 standard seed dictionary yields 23 bits of entropy, 10 million possibilities for every wallet. I think that is beyond the realm of where this attack becomes economically feasible. My guess is it was a very simple two word combo that may be in the 10000 most common passwords or something.
crypto_curious
Full Member
***
Offline

Activity: 951
Merit: 182


View Profile
August 03, 2026, 11:53:42 AM
 #255

this is partly your own fault.
Victim blaming isn't helping anyone.

Quote
Using a passphrase should be mandatory for all 24-word seed wallets.
That adds the risk of losing your passphrase. Storing keys is always a compromise between the risk of someone else gaining access, and the risk of losing access by yourself.

The victim does bear some responsibility here. There is no denying that, no matter how much people dislike hearing it.

When a passphrase is optional and users choose not to use it, they significantly increase the risk of becoming victims sooner or later. Unfortunately, that's the direction it almost inevitably leads.
_act_
Legendary
*
Offline

Activity: 1694
Merit: 1946



View Profile
August 03, 2026, 12:07:49 PM
 #256

The victim does bear some responsibility here. There is no denying that, no matter how much people dislike hearing it.

When a passphrase is optional and users choose not to use it, they significantly increase the risk of becoming victims sooner or later. Unfortunately, that's the direction it almost inevitably leads.
This reminded me of a wallet that I have used in the past called Samourai wallet. The wallet was later taken down by the government because of whirlpool, a coinjoin that it has which was linked to criminals. The wallet made passphrase mandatory, but it warns users that if they lose the passphrase, that they will not be able to recover their bitcoin. But I also like how passphrase is optional, there is no Samourai wallet anymore, but I am still using passphrase on other wallets. People should always learn about something before they finally decide to use the thing.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits..REWARDING, BEYOND LIMITS...
█████████████████████████
█████████████████████████
███████████▀▀░░▀█▄░░▀████
████████▀░░░░░░░░▀█▄░████
███████░░░░▄▄░░▄░░░▀█████
██████░░░░░▀▀▄██▀░░░░████
█████░░░██░▄██▀▄▄░░░█████
████░░░░░▄██▀░░▀▀░░██████
█████▄░░▀█▀░██░░░░███████
████░▀█▄░░░░░░░░▄████████
████▄░░▀█▄░░▄▄███████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████▀░░▀░███████████
████████░░░▄░█░██████████
███████████▌▐██░█████████
███████████░███▌▐████████
██████████░█████░████████
██████▀░▄░▀███▀░▄░▀█████
█████░▄▀░░░░█░▄▀░░░░█████
█████░░░░░░░█░░░░░░░█████
██████▄░░░▄███▄░░░▄██████
█████████████████████████
█████████████████████████


























  PLAY NOW  
hosemary
Legendary
*
Offline

Activity: 3206
Merit: 7146



View Profile
August 03, 2026, 12:18:47 PM
 #257

When a passphrase is optional and users choose not to use it, they significantly increase the risk of becoming victims sooner or later. Unfortunately, that's the direction it almost inevitably leads.
I'm not saying a passphrase is never needed, but a 12 word BIP39 seed phrase provides 128 bits of entropy and is secure enough, if has been generated in the correct way, and not in the flawed way Coldcard generated seed phrases.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits..REWARDING, BEYOND LIMITS...
█████████████████████████
█████████████████████████
███████████▀▀░░▀█▄░░▀████
████████▀░░░░░░░░▀█▄░████
███████░░░░▄▄░░▄░░░▀█████
██████░░░░░▀▀▄██▀░░░░████
█████░░░██░▄██▀▄▄░░░█████
████░░░░░▄██▀░░▀▀░░██████
█████▄░░▀█▀░██░░░░███████
████░▀█▄░░░░░░░░▄████████
████▄░░▀█▄░░▄▄███████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████▀░░▀░███████████
████████░░░▄░█░██████████
███████████▌▐██░█████████
███████████░███▌▐████████
██████████░█████░████████
██████▀░▄░▀███▀░▄░▀█████
█████░▄▀░░░░█░▄▀░░░░█████
█████░░░░░░░█░░░░░░░█████
██████▄░░░▄███▄░░░▄██████
█████████████████████████
█████████████████████████


























  PLAY NOW  
NotATether
Legendary
*
Offline

Activity: 2408
Merit: 10078


┻┻ ︵㇏(°□°㇏)


View Profile WWW
August 03, 2026, 12:45:19 PM
Merited by vapourminer (1)
 #258


This is your account?

I gave it a follow Smiley

So according to Alex thorn (from Galaxy)[1] a coldcard victim had 17 BTC stolen from his wallet, swapped to ETH (through Thorchain) and then sent to a KYCed account in Duel's gambling platform.

This was resolved by the Duel representative on X

https://x.com/korraflow/status/2083812755409191373

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
philipma1957
Legendary
*
Offline

Activity: 4928
Merit: 12316


'The right to privacy matters'


View Profile WWW
August 03, 2026, 01:13:25 PM
Merited by OmegaStarScream (3), vapourminer (1)
 #259

My question to ColdCard team is what the hell are they doing to put an end to this attacks? It's slowly leaving the MK3 and into the supposed better versions of their hardware wallets.

The 4TH wave ?

If Coldcard were that capable on handling this, they wouldn't have left the Loophole in the first place.

But my concern is what are people doing here?  If anyone says that their wallet has been drained off in the 4th wave, what was he doing before? Why can't everyone move their funds out immediately? It's not a centralised exchange or something where they can put a halt on your withdrawals ?

I would call it laziness on the people too.

SO YOUR WALLET / cold card is sitting in a bank safety box in the USA . you are on business in Europe . catching a flight to get to the card and withdraw the coins does not happen quickly.

Better yet. you wallet is in your local bank.

You miss the news on Friday night. Find out at 3:30pm Saturday .The  bank is closed until 9am today. so bye bye coins.

cold storage. you were clever the wallet was in a bank vault the seeds in a different bank vault. and you had to wait until 9am this morning by by coins.

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|..BTC......XMR...
..USDT.....LTC...
....Fees  0.8%.....
kTimesG
Sr. Member
****
Offline

Activity: 910
Merit: 263


View Profile
August 03, 2026, 01:20:13 PM
Merited by tvbcof (1)
 #260

Quote
A complex and subtle series of bugs prevented the hardware RNG from contributing randomness in certain versions of the firmware. We were unaware of the bug until today

I wonder what is so complex from basically failing to properly use a C preprocessor define. Such an elementary mistake should have caught the eye of even an amateur code reviewer, let alone any rudimentary IDE. Why would a PRNG implementation even exist at all, inside the firmware of a device that deals with real money? Nevermind the rubbish code that actually seeds the PRNG, which is not even the 72 bits as they claim, but much much less. And they were well aware of it, even the code comments admit that the numbers are biased, so they.... hash it to cover the fuckup and pass the tests. LMFAO! How does such a company still exist today? They will definitely not be able to cover for 5 years of compromised entropy onto which who knows how much real BTC sits.

Quote
The COLDCARD source code has always been open and publicly available, so we have to assume that someone used AI to review previous versions of our firmware and stumbled upon this issue. A few weeks ago, we used one of the best available AI models to review our code for security issues, and it did not find this bug or anything serious.

And still they managed to write and deploy something much worse than AI would have produced. I guess an actual human code reviewer was too costly, so they let the part-time Python student do their firmware, or what?

Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 [13] 14 15 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!