BobbysTransactions
Jr. Member

Activity: 47
Merit: 21
|
 |
August 03, 2026, 01:50:49 PM |
|
Yes, but is this a credible error? Why would the developer think "let me use #ifndef rather than #if"?
Yes, it's a common error particularly when working across different codebases with different styles. In the case of coldcard there were three relevant codebases: micropython, libngu, and the coldcard codebase itself. Likelyhood with be greater with less experience with C but this is the sort of error that even the most experienced C developers can make: Both styles-- value and defineness checking-- are commonly used for configuration and you can mix them up. *Usually* the result of doing so is something that is obviously wrong and gets caught right away. But because of the PRNG fallback in micropython the bad behavior was difficult to detect because it would look and act like real randomness and pass most tests you might throw at it. The more I think about it I'm not so sure. Disabling the build flag for the TRNG and mangling the sense check with ~ifndef is a double error. Hard at this stage to dismiss the possibility that this was done on purpose and made to look like an oversight.
|
|
|
|
|
vapourminer
Legendary

Activity: 5110
Merit: 6606
what is this "brake pedal" you speak of?
|
But my concern is what are people doing here? If anyone says that their wallet has been drained off in the 4th wave, what was he doing before? Why can't everyone move their funds out immediately? It's not a centralised exchange or something where they can put a halt on your withdrawals ?
Not all people are aware of what's happening with Coldcard wallets. Many users probably generated a wallet on Coldcard, sent their funds to it, and assumed they would be 100% safe. You can't expect all Bitcoin investors to stay up to date with every new development. The incident only started three days ago. plus some folks make cold storage deliberately time consuming to access to protect against duress or impulsiveness. so it may well take several days to get to the seed or wallet to xfer the coins out.
|
|
|
|
|
bitmover
Legendary

Activity: 3108
Merit: 7652
Trêvoid █ No KYC-AML Crypto Swaps
|
 |
August 03, 2026, 04:33:11 PM |
|
plus some folks make cold storage deliberately time consuming to access to protect against duress or impulsiveness. so it may well take several days to get to the seed or wallet to xfer the coins out.
Yeah, cold wallets can be used for trading but lots of people dont touch them for months. Some people might be traveling and without access to the wallet. This happens to me a lot. This is a very sad and desperate situation for so many people... I wonder what will the hacker do with all those coins. Are they north Korean? Why would someone want so much money? He could have drained just a few hundread btc if it is just a small group.
|
| DΞX.fo | | | | | | ▄▄██████ █████████ ██████████ ██████████ ██████████ █████████ ▀▀██████
▄███████ ▄██████████ ████████████ █████████████ █████████████ | | | | ▄▄█ ▄████▀ ▄███▀█▄ ▄██▀█▄██ █████▀▀█ ████████ ████████ ▀██▄████ ▄████▄▄█ ▄█████▀███ ▄█████▀████▀ █████▀███████ ▀██▀█████████ | | | | | BTC XMR DAI LTC Fees 0.8% |
|
|
|
DaveF
Legendary

Activity: 4284
Merit: 7423
✅ NO KYC
|
 |
August 03, 2026, 04:44:28 PM |
|
And the scammers being scamming.  The schedule link looks like it wants to install something. h t t p s : / / b o o k . c o i n k i t e a d v i s o r y . c o m / reported if others can to that would be great.Domain Name: coldcardblog.org Registry Domain ID: REDACTED Registrar WHOIS Server: whois.squarespace.domains Registrar URL: https://domains.squarespace.comUpdated Date: 2026-08-03T11:03:53Z Creation Date: 2026-08-03T10:56:49Z Registry Expiry Date: 2027-08-03T10:56:49Z Registrar: Squarespace Domains LLC Registrar IANA ID: 3827 Registrar Abuse Contact Email: abuse-complaints@squarespace.comRegistrar Abuse Contact Phone: +1.6466935324 Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibitedDomain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibitedDomain Status: addPeriod https://icann.org/epp#addPeriodName Server: nsc1.squarespacedns.com Name Server: nsc2.squarespacedns.com Name Server: nsc3.squarespacedns.com Name Server: nsc4.squarespacedns.com DNSSEC: signedDelegation URL of the ICANN Whois Inaccuracy Complaint Form: https://icann.org/wicf/>>> Last update of WHOIS database: 2026-08-03T16:31:56Z <<<
|
|
|
|
philipma1957
Legendary
Online
Activity: 4928
Merit: 12315
'The right to privacy matters'
|
 |
August 03, 2026, 04:45:13 PM |
|
plus some folks make cold storage deliberately time consuming to access to protect against duress or impulsiveness. so it may well take several days to get to the seed or wallet to xfer the coins out.
Yeah, cold wallets can be used for trading but lots of people dont touch them for months. Some people might be traveling and without access to the wallet. This happens to me a lot. This is a very sad and desperate situation for so many people... I wonder what will the hacker do with all those coins. Are they north Korean? Why would someone want so much money? He could have drained just a few hundread btc if it is just a small group. Lots of what or whom the hacker could be. If it is one guy he should have done 1 wallet with 2 or 3 coins. Then practiced mixing the heck out of it. He likely would not have been detected and could have grabbed a few btc every 4 or 5 months. Not so sure that it was a loner. Time will unfold and we may get more details in the next few months. Here is hoping it is not a big crew looking to hit a second company soon. Many fear ledger and its recovery program. My advice is have a few setups and add strong passphrases
|
| DΞX.fo | | | | | | ▄▄██████ █████████ ██████████ ██████████ ██████████ █████████ ▀▀██████
▄███████ ▄██████████ ████████████ █████████████ █████████████ | | | | ▄▄█ ▄████▀ ▄███▀█▄ ▄██▀█▄██ █████▀▀█ ████████ ████████ ▀██▄████ ▄████▄▄█ ▄█████▀███ ▄█████▀████▀ █████▀███████ ▀██▀█████████ | | | | | ..BTC......XMR... ..USDT.....LTC... ....Fees 0.8%..... |
|
|
|
bitmover
Legendary

Activity: 3108
Merit: 7652
Trêvoid █ No KYC-AML Crypto Swaps
|
 |
August 03, 2026, 05:02:19 PM |
|
My advice is have a few setups and add strong passphrases
This is basically mandatory now.. I have a second wallet without a passphrase. I will move the funds to a new wallet with passphrase during this week. But I have many coins, many addresses, many derivation paths. It will take some time...
|
| DΞX.fo | | | | | | ▄▄██████ █████████ ██████████ ██████████ ██████████ █████████ ▀▀██████
▄███████ ▄██████████ ████████████ █████████████ █████████████ | | | | ▄▄█ ▄████▀ ▄███▀█▄ ▄██▀█▄██ █████▀▀█ ████████ ████████ ▀██▄████ ▄████▄▄█ ▄█████▀███ ▄█████▀████▀ █████▀███████ ▀██▀█████████ | | | | | BTC XMR DAI LTC Fees 0.8% |
|
|
|
MicroGuy
Legendary

Activity: 2562
Merit: 1030
x.com/realmicroguy
|
 |
August 03, 2026, 05:24:21 PM |
|
What's wrong with a laminated paper wallet rolled up in a sealed PVC pipe filled with rice and buried in backyard?
|
|
|
|
|
jayhex
Newbie

Activity: 1
Merit: 0
|
 |
August 03, 2026, 06:06:55 PM |
|
also; you know they're just going to sell all this stolen btc on the 7th or whenever bip110 activates. mfers
|
|
|
|
|
EstherBtc
Jr. Member

Activity: 61
Merit: 7
|
 |
August 03, 2026, 06:31:45 PM Last edit: August 03, 2026, 09:10:21 PM by EstherBtc |
|
 Found this on https://x.com/BitcoinNewsCom/status/2084273394229362780 The question on my mind is will white hat be able to recover the stolen bitcoin? and if they do. It would be better to just send the recovered bitcoins to their original address. Instead asking for verifications from the victims and refusing to return the recoup coins if they can't verify.
|
|
|
|
|
FinneysTrueVision
Legendary

Activity: 2464
Merit: 1177
|
 |
August 03, 2026, 07:49:53 PM |
|
Coldcard has just announced that it is sending emails to Coldcard users https://x.com/COLDCARDwallet/status/2083741922070352247The saddest part is that most people who receive one of these emails and aren't aware of the attacks will think it's just another one of those phishing emails I would think so, it looks exactly like those emails we constantly get from “Ledger” I got one of those emails even though I have never bought one of their products. I think I might have signed up for email alerts to notify me when the Coldcard Q became available for pre-order some years ago when I considered buying one. Like many people I was confused and thought it might be a phishing attempt because they claim to delete customer information after a period of time. They use this as a selling point whenever a competitor suffers a data breach. Apparently, there is some fine print saying that they actually do retain some information about customers.
|
| EARNBET | ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ | ███████▄▄███████████ ████▄██████████████████ ██▄▀▀███████████████▀▀███ █▄████████████████████████ ▄▄████████▀▀▀▀▀████████▄▄██ ███████████████████████████ █████████▌████▀████████████ ███████████████████████████ ▀▀███████▄▄▄▄▄█████████▀▀██ █▀█████████████████████▀██ ██▀▄▄███████████████▄▄███ ████▀██████████████████ ███████▀▀███████████ | | ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ |
▄▄▄ ▄▄▄███████▐███▌███████▄▄▄ █████████████████████████ ▀████▄▄▄███████▄▄▄████▀ █████████████████████ ▐███████████████████▌ ███████████████████ ███████████████████ ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
| King of The Castle $200,000 in prizes | ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ | 62.5% | RAKEBACK BONUS |
|
|
|
OmegaStarScream
Staff
Legendary

Activity: 4284
Merit: 7510
|
 |
August 03, 2026, 07:54:52 PM Last edit: August 03, 2026, 08:17:02 PM by OmegaStarScream |
|
How would this work exactly? the KYC information are going to be cross checked against what exactly? A signed message is not going to work either. Someone who can access your funds, would also have the ability to sign a message... I understand the intention may be good but with no clear and straightforward way to know the rightful owners of those funds, whoever is going to do this will probably end up in legal trouble, or am I missing something here?
|
|
|
|
EstherBtc
Jr. Member

Activity: 61
Merit: 7
|
 |
August 03, 2026, 09:17:22 PM |
|
How would this work exactly? the KYC information are going to be cross checked against what exactly? A signed message is not going to work either. Someone who can access your funds, would also have the ability to sign a message... I understand the intention may be good but with no clear and straightforward way to know the rightful owners of those funds, whoever is going to do this will probably end up in legal trouble, or am I missing something here? When i saw this on X, i was skeptical about it because, why do they need kyc and since they have the address where these coins was stolen from is better to just send it back there. That is if they are able to recover the bitcoins. I just hope those affected will be careful and not expose themselves to further theft in a bid to recover what they lost. Caution is needed.
|
|
|
|
|
|
5W-KILO
|
 |
August 03, 2026, 09:18:11 PM |
|
Since this is the latest bitcoin wallet and security discussion thread on the forum I think it will be a good time to ask this question, some members on here have advice that 12 seed phrases aren't that much different from 24 seed phrases. Some even said that they prefer to have 12 seed phrase rather than the rest but it seems that 12 seed phrases is 128bits while 24 seed phrases is 256Bits... If this is true then 24 seed phrases are more secured. Because of that bit, I came across this picture of Twitter today and it just backed it up so I believe sharing it on here will be educational.  I'm open to correction if you believe that I am wrong in any way.
|
|
|
|
|
|
kTimesG
|
 |
August 03, 2026, 09:20:59 PM |
|
When i saw this on X, i was skeptical about it because, why do they need kyc and since they have the address where these coins was stolen from is better to just send it back there. That is if they are able to recover the bitcoins. Compromised entropy = all derived wallet addresses are also compromised. So it is impossible to prove ownership when all the seeds are publicly known.
|
|
|
|
EstherBtc
Jr. Member

Activity: 61
Merit: 7
|
 |
August 03, 2026, 09:38:14 PM |
|
When i saw this on X, i was skeptical about it because, why do they need kyc and since they have the address where these coins was stolen from is better to just send it back there. That is if they are able to recover the bitcoins. Compromised entropy = all derived wallet addresses are also compromised. So it is impossible to prove ownership when all the seeds are publicly known. Does this mean the stolen bitcoins can't be recovered and refunded?
|
|
|
|
|
hosemary
Legendary

Activity: 3206
Merit: 7145
|
 |
August 03, 2026, 09:46:29 PM |
|
Some even said that they prefer to have 12 seed phrase rather than the rest but it seems that 12 seed phrases is 128bits while 24 seed phrases is 256Bits...
What happened with Coldcard wallets doesn't mean a 12 word seed phrase isn't secure enough. A 12 word BIP39 seed phrase provides 128 bits of entropy, if generated correctly. Coldcard didn't generate the seed phrases in the correct way, and it provided much lower entropy.
|
| . .Duelbits..REWARDING, BEYOND LIMITS... | █████████████████████████ █████████████████████████ ███████████▀▀░░▀█▄░░▀████ ████████▀░░░░░░░░▀█▄░████ ███████░░░░▄▄░░▄░░░▀█████ ██████░░░░░▀▀▄██▀░░░░████ █████░░░██░▄██▀▄▄░░░█████ ████░░░░░▄██▀░░▀▀░░██████ █████▄░░▀█▀░██░░░░███████ ████░▀█▄░░░░░░░░▄████████ ████▄░░▀█▄░░▄▄███████████ █████████████████████████ █████████████████████████ | █████████████████████████ █████████████████████████ █████████▀░░▀░███████████ ████████░░░▄░█░██████████ ███████████▌▐██░█████████ ███████████░███▌▐████████ ██████████░█████░████████ ██████▀░▄░▀███▀░▄░▀██████ █████░▄▀░░░░█░▄▀░░░░█████ █████░░░░░░░█░░░░░░░█████ ██████▄░░░▄███▄░░░▄██████ █████████████████████████ █████████████████████████ | █ █ █ █ █ █ █ █ █ █ █ █ █ | |
| | █ █ █ █ █ █ █ █ █ █ █ █ █ | PLAY NOW |
|
|
|
|
suzanne5223
|
 |
August 03, 2026, 09:54:08 PM |
|
After so many years, the issue was reported to the Coldcard team did not address it and left it unresolved? That's an act of irresponsibility.
As far as I know, in the case of the Coldcard breach which drained users of millions of dollars/thousands of lost Bitcoins, due to the theft incident that occurred, as far as I know, Coinkite has already released a warning to the victims, although at this time there is no clear solution for compensation or recovering stolen Bitcoins, what I know is that the company cannot be held responsible for this disaster, they say Bitcoin assets are completely in the hands of self-custody users. They know that this decision is indeed difficult and many of the victims are emotional and upset, but what else can I say, for that reason, none of the parties or Coinkite employees can make a decision or take responsibility in this case, They are aware that this decision could make it doubtful for users to use their Bitcoin Wallet in the future, because of the theft incident against Coldcard, they not only suffered losses, but their reputation was also at stake, it was indeed a bitter decision that Coldcard had to swallow. I have never read or see anything related to Coldcard team warning their users about a certain vulnerability of their wallet before the hack. What I see is the post from a Bitcoiner warning people about the wallet (Coldcard) which they choose to ignore. Although, no information about the compensation for the lost Bitcoins is provide at the moment but the whole attack is entirely the fault of the wallet team. I could remember people are advised to use atleast 128 bits of entropy for security purpose, why would the Coldcard team use something lower for their wallet and never expect security vulnerabilities in the future. Apart from the wallet team losing their reputation, I feel sad that some people may use it to promote custodial holding and newbie will easily adopt the idea while some antiBTC may also use it as a topic to create fud.
|
| Kings Game | 🎰 🎲 ⚽ | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | ████████████████████████████
████████████████████████████ | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | ████████████████████████████
| ..500%.. | WELCOME BONUS + 250 FREE SPINS |
████████████████████████████ | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | WIN NOW |
|
|
|
philipma1957
Legendary
Online
Activity: 4928
Merit: 12315
'The right to privacy matters'
|
 |
August 03, 2026, 10:02:43 PM |
|
When i saw this on X, i was skeptical about it because, why do they need kyc and since they have the address where these coins was stolen from is better to just send it back there. That is if they are able to recover the bitcoins. Compromised entropy = all derived wallet addresses are also compromised. So it is impossible to prove ownership when all the seeds are publicly known. Does this mean the stolen bitcoins can't be recovered and refunded? No if you own the wallet and have proof of purchase it helps. If you purchased BTC at a real kyc exchange and can show that along with moves of coin to the wallet it helps.
|
| DΞX.fo | | | | | | ▄▄██████ █████████ ██████████ ██████████ ██████████ █████████ ▀▀██████
▄███████ ▄██████████ ████████████ █████████████ █████████████ | | | | ▄▄█ ▄████▀ ▄███▀█▄ ▄██▀█▄██ █████▀▀█ ████████ ████████ ▀██▄████ ▄████▄▄█ ▄█████▀███ ▄█████▀████▀ █████▀███████ ▀██▀█████████ | | | | | ..BTC......XMR... ..USDT.....LTC... ....Fees 0.8%..... |
|
|
|
rdluffy
Legendary
Online
Activity: 3038
Merit: 2034
|
 |
August 03, 2026, 10:13:24 PM |
|
Does this mean the stolen bitcoins can't be recovered and refunded?
No if you own the wallet and have proof of purchase it helps. If you purchased BTC at a real kyc exchange and can show that along with moves of coin to the wallet it helps. Let’s consider a hypothetical situation in which they manage to recover those stolen BTC One way to prove that the BTC was yours could be through the addresses that may have been linked to the stolen wallets For example, I withdrew from Binance to a wallet that was drained If I have the transaction from Binance to my address, I can prove that I requested a withdrawal during a specific time frame Or conversely, if I used the drained wallet to send BTC, I could prove that the recipient’s wallet is also in my possession It’s not that easy, since there might be some bad-faith users, but if it’s well thought out and planned, it would be possible to link some addresses to specific users
|
| | .1win.com. | █████████████████████████ █████████████████████████ ████████████▀░░░▀▀▀▀█████ █████████▀▀▀█▄░░░░░░░████ ████▀▀░░░░░░░█▄░▄░░░▐████ ████▌░░░░▄░░░▐████░░▐████ █████░░░▄██▄░░██▀░░░█████ █████▌░░▀██▀░░▐▌░░░▐█████ ██████░░░░▀░░░░█░░░▐█████ ██████▌░░░░░░░░▐█▄▄██████ ███████▄░░▄▄▄████████████ █████████████████████████ █████████████████████████ | | █████████████████████████ █████████████████████████ ███████████▀▀▀███████████ ███████▀▀░░▄▄▄░░▀▀███████ ██████▄░░░░███░░░░▄██████ █████░▀▀█▄▄░░░▄▄█▀▀░█████ █████░██░░▀▀█▀▀░░██░█████ █████░░░░░░░█░██░▄▄░█████ █████▄░░░▄▄░█░▄▄░▀▀▄█████ ███████▄▄▀▀░█░▀▀▄▄███████ ███████████▄█▄███████████ █████████████████████████ █████████████████████████ | | █████████████████████████ █████████████████████████ ████████▀▀░░░░░▀▀████████ ██████░░▄██▄░▄██▄░░██████ █████░░████▀░▀████░░█████ ████░░░░▀▀░░░░░▀▀░░░░████ ████░░▄██░░░░░░░██▄░░████ ████░░████░░░░░████░░████ █████░░▀▀░▄███▄░▀▀░░█████ ██████░░░░▀███▀░░░░██████ ████████▄▄░░░░░▄▄████████ █████████████████████████ █████████████████████████ | | |
|
|
|
Stalker22
Legendary

Activity: 2310
Merit: 1612
|
 |
August 03, 2026, 10:13:39 PM |
|
Compromised entropy = all derived wallet addresses are also compromised. So it is impossible to prove ownership when all the seeds are publicly known.
This is not necessarily true. As eaLiTy already said: The attacker (or whoever has the private keys of those addresses) cannot forge your entire historical transaction trail.
|
|
|
|
|