|
|
Forsyth Jones
Legendary

Activity: 1974
Merit: 2178
I love Bitcoin!
|
The attack is not ended, maybe another one hackers or hack team is on work to drain more BTC in people addresses. At this point, we can safely say that Coldcard can be flushed down the toilet and we can move on to something else. I don’t think they wil regain the trust of their current and future customers. Projected BTC drained count tell about: [img height=400]https://talkimg.com/images/2026/08/03/UoI5wT.png[/img] I'm in favor of bad companies going bankrupt, especially those that were negligent and had the chance to avoid this disaster (bug bounty, reverting to the GPL license). Let's see what happens. Compromised entropy = all derived wallet addresses are also compromised. So it is impossible to prove ownership when all the seeds are publicly known.
This is not necessarily true. As eaLiTy already said: The attacker (or whoever has the private keys of those addresses) cannot forge your entire historical transaction trail. Unless I'm mistaken, technically you can prove you own the drained funds, as the seed was generated from the coldcard ID. https://x.com/narcelio/status/2084303965202657304https://x.com/BTCsessions/status/2084024733511921691The attackers have started draining wallets on Coldcard devices WITH passphrase. As per the tweet, it was a pretty simple passphrase (two extra words), but this shows the attack is active and they are searching everything. If you personally know any Coldcard user who feels safe with his "strong passphrase", it's best to reach them out as soon as possible. cutthroat, even those who used passphrases used weak and predictable ones. People should use common sense before using advanced features and understand them masterfully. Below is a table showing the strength of each passphrase extension:  It's one crook trying to outsmart another crook. Guys, don't leave your houses while all tricksters are among each other. 
|
| . .Duelbits..REWARDING, BEYOND LIMITS... | █████████████████████████ █████████████████████████ ███████████▀▀░░▀█▄░░▀████ ████████▀░░░░░░░░▀█▄░████ ███████░░░░▄▄░░▄░░░▀█████ ██████░░░░░▀▀▄██▀░░░░████ █████░░░██░▄██▀▄▄░░░█████ ████░░░░░▄██▀░░▀▀░░██████ █████▄░░▀█▀░██░░░░███████ ████░▀█▄░░░░░░░░▄████████ ████▄░░▀█▄░░▄▄███████████ █████████████████████████ █████████████████████████ | █████████████████████████ █████████████████████████ █████████▀░░▀░███████████ ████████░░░▄░█░██████████ ███████████▌▐██░█████████ ███████████░███▌▐████████ ██████████░█████░████████ ██████▀░▄░▀███▀░▄░▀██████ █████░▄▀░░░░█░▄▀░░░░█████ █████░░░░░░░█░░░░░░░█████ ██████▄░░░▄███▄░░░▄██████ █████████████████████████ █████████████████████████ | █ █ █ █ █ █ █ █ █ █ █ █ █ | |
| | █ █ █ █ █ █ █ █ █ █ █ █ █ | PLAY NOW |
|
|
|
tvbcof
Legendary

Activity: 5278
Merit: 1314
|
 |
Today at 12:29:11 AM Last edit: Today at 12:54:30 AM by tvbcof Merited by vapourminer (1) |
|
I see no reason to create a new topic about this but it looks like ColdCard is just one crappy hardware wallet company over all. They can't even fixed a firmware right for their devices. The picture below is what users are currently getting after updated to the latest firmware.  I think this is one of those reasons why you don't want to install latest firmware instantly as they are available. Always give it time because you can never tell what will happen, atleast let some other people lead the way first.  Sorry to say but ColdCard just sucks big time. I usually try to go through a thread before commenting, but I cannot help it in this case. I just got done doing an emergency international flight and taking care of business of a type which might be obvious to the readers of this thread. (No losses yet that I can determine just fwiw.) I've got a number of Coldcard Q's. More than half have serious operational flaws (e.g., won't turn off so I use the battery as an off switch). I suspect that the Coinkite crew are to busy with new features and devices which are much more fun and interesting than code review, QA, and going over boring documentation like how different chips and libraries (and pre-processor macros) actually work. I have always considered the Coinkite developers to be potential enemies and only one time reached out to them for support. Support was at best unhelpful and I retain a rather serious and costly issue with one of the devices. Never worth my time to dig into the problem/solution, and I figured that as the months (or years) drag on, it will become more clear if I should interact with them as a serious and honest vendor, or as relatively clever and patient group of thieves. Entropy issues have always been at the core of my concerns about any coin handling solution, and Coinkite in particular (because, to their credit, they addressed other concerns better than anyone else when I was researching things.) Actually, the same basic issue bothers me most about Bitcoin itself. The BTC I lost to Coldcard Q defects (and my own lack of proper system testing) were not stolen. They sit right where they are. If they moved, I would have known for sure that Coinkite were crooks...well...unless some defect like the one we are discussing came along...
|
sig spam anywhere and self-moderated threads on the pol&soc board are for losers.
|
|
|
philipma1957
Legendary
Online
Activity: 4928
Merit: 12318
'The right to privacy matters'
|
 |
Today at 12:48:22 AM |
|
Does this mean the stolen bitcoins can't be recovered and refunded?
No if you own the wallet and have proof of purchase it helps. If you purchased BTC at a real kyc exchange and can show that along with moves of coin to the wallet it helps. Let’s consider a hypothetical situation in which they manage to recover those stolen BTC One way to prove that the BTC was yours could be through the addresses that may have been linked to the stolen wallets For example, I withdrew from Binance to a wallet that was drained If I have the transaction from Binance to my address, I can prove that I requested a withdrawal during a specific time frame Or conversely, if I used the drained wallet to send BTC, I could prove that the recipient’s wallet is also in my possession It’s not that easy, since there might be some bad-faith users, but if it’s well thought out and planned, it would be possible to link some addresses to specific users Yeah kyc helps in this case. Say I have kyc at kraken. And by Buying 0.001 btc a week to be like jjg and dca deposit it every week to the cold card. Plus you have the bank statements for the cash you added to kraken And the actual cold card lastly the paper work for buying the cold card. If you did this you can show all the withdrawals you made from kraken and the deposits to the cold card. The ones to be fucked are all gray buys of coins.
|
| DΞX.fo | | | | | | ▄▄██████ █████████ ██████████ ██████████ ██████████ █████████ ▀▀██████
▄███████ ▄██████████ ████████████ █████████████ █████████████ | | | | ▄▄█ ▄████▀ ▄███▀█▄ ▄██▀█▄██ █████▀▀█ ████████ ████████ ▀██▄████ ▄████▄▄█ ▄█████▀███ ▄█████▀████▀ █████▀███████ ▀██▀█████████ | | | | | ..BTC......XMR... ..USDT.....LTC... ....Fees 0.8%..... |
|
|
|
|
suhadi88
|
 |
Today at 01:10:37 AM |
|
Why didn't policymakers take precautions earlier, even though the vulnerability had already been detected—say, detected in 2021—and why are they only now realizing it? They were busy, while people's wallets, already full of accumulated BTC, were being lost. Fortunately, they were quick to detect it and immediately moved it, even though 50% of the BTC had already been lost. Otherwise, everything would have been wiped without a trace. I think it's simple: Only we know our own performance, and so does the device itself.
|
|
|
|
|
BlackBoss_
|
Why didn't policymakers take precautions earlier, even though the vulnerability had already been detected—say, detected in 2021—and why are they only now realizing it?
They realized it since the community reported that security problem but they just irresponsibly ignored all warnings. They were busy
Busy? Their main job as a wallet manufacturer is to create a secure wallet for customers. Even customers, developers, security experts in community generously and proactively mentioned about the security weakness and loss to Coldcard, they ignored all these things. What are more important things for Coldcard so that they were busy with such and ignored fixing their wallet? while people's wallets, already full of accumulated BTC, were being lost. Fortunately, they were quick to detect it and immediately moved it, even though 50% of the BTC had already been lost.
With people who already lost bitcoin to hackers, they were unlucky and deeply sorry for their losses but as always, losses of some people are luckiness of the others. I am not talking about hackers, but Bitcoin holders from hardware wallet users to users of other wallets. This technical problems and exploitation on Coldcard raise an alarm and need of using passphrase (custom words) for wallets from now.
|
|
|
|
|
|
| R |
▀▀▀▀▀▀▀██████▄▄ ████████████████ ▀▀▀▀█████▀▀▀█████ ████████▌███▐████ ▄▄▄▄█████▄▄▄█████ ████████████████ ▄▄▄▄▄▄▄██████▀▀ | LLBIT | | | 4,000+ GAMES███████████████████ ██████████▀▄▀▀▀████ ████████▀▄▀██░░░███ ██████▀▄███▄▀█▄▄▄██ ███▀▀▀▀▀▀█▀▀▀▀▀▀███ ██░░░░░░░░█░░░░░░██ ██▄░░░░░░░█░░░░░▄██ ███▄░░░░▄█▄▄▄▄▄████ ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀ | █████████ ▀████████ ░░▀██████ ░░░░▀████ ░░░░░░███ ▄░░░░░███ ▀█▄▄▄████ ░░▀▀█████ ▀▀▀▀▀▀▀▀▀ | █████████ ░░░▀▀████ ██▄▄▀░███ █░░█▄░░██ ░████▀▀██ █░░█▀░░██ ██▀▀▄░███ ░░░▄▄████ ▀▀▀▀▀▀▀▀▀ |
| | | | | | .
| | | ▄▄████▄▄ ▀█▀▄▀▀▄▀█▀ ▄▄░░▄█░██░█▄░░▄▄ ▄▄█░▄▀█░▀█▄▄█▀░█▀▄░█▄▄ ▀▄█░███▄█▄▄█▄███░█▄▀ ▀▀█░░░▄▄▄▄░░░█▀▀ █░░██████░░█ █░░░░▀▀░░░░█ █▀▄▀▄▀▄▀▄▀▄█ ▄░█████▀▀█████░▄ ▄███████░██░███████▄ ▀▀██████▄▄██████▀▀ ▀▀████████▀▀ | . ▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄ ░▀▄░▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄░▄▀ ███▀▄▀█████████████████▀▄▀ █████▀▄░▄▄▄▄▄███░▄▄▄▄▄▄▀ ███████▀▄▀██████░█▄▄▄▄▄▄▄▄ █████████▀▄▄░███▄▄▄▄▄▄░▄▀ ████████████░███████▀▄▀ ████████████░██▀▄▄▄▄▀ ████████████░▀▄▀ ████████████▄▀ ███████████▀ | ▄▄███████▄▄ ▄████▀▀▀▀▀▀▀████▄ ▄███▀▄▄███████▄▄▀███▄ ▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄ ▄██▀▄███░░░▀████░███▄▀██▄ ███░████░░░░░▀██░████░███ ███░████░█▄░░░░▀░████░███ ███░████░███▄░░░░████░███ ▀██▄▀███░█████▄░░███▀▄██▀ ▀██▄▀█▄▄▄██████▄██▀▄██▀ ▀███▄▀▀███████▀▀▄███▀ ▀████▄▄▄▄▄▄▄████▀ ▀▀███████▀▀ | | OFFICIAL PARTNERSHIP SOUTHAMPTON FC FAZE CLAN SSC NAPOLI |
|
|
|
jayhex
Newbie

Activity: 2
Merit: 0
|
 |
Today at 02:37:22 AM |
|
why did my opendimes question get deleted? cant a guy ask a question? isnt that coldcard too? jeez
|
|
|
|
|
|
Alone055
|
 |
Today at 05:59:23 AM |
|
Some of them are actually funny. Look at this one:  Lol 
Anyway, since it was because of a security breach from their devices that caused people such big losses, shouldn't the owners, creators, developers, and all those involved in this be arrested and put through trials just like how SBF (Sam Bankman Fried) of FTX was arrested for fraud? And, let me just throw this thought out there, and I'm not blaming anyone or anything like that, but what are the chances that there is actually no external hacker or anything but it's all done from the inside? Just saying. 
|
█████████████████████████ ████████▀▀████▀▀█▀▀██████ █████▀████▄▄▄▄██████▀████ ███▀███▄████████▄████▀███ ██▀███████████████████▀██ █████████████████████████ █████████████████████████ █████████████████████████ ██▄███████████████▀▀▄▄███ ███▄███▀████████▀███▄████ █████▄████▀▀▀▀████▄██████ ████████▄▄████▄▄█████████ █████████████████████████ | BitList | | | █▀▀▀▀ █ █ █ █ █ █ █ █ █ █ █ █▄▄▄▄ | ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀.Bitcointalk Archive 📚 Visualization ' Search.▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄ | ▀▀▀▀█ █ █ █ █ █ █ █ █ █ █ █ ▄▄▄▄█ | | |
|
|
|
EstherBtc
Jr. Member

Activity: 63
Merit: 8
|
 |
Today at 07:24:35 AM |
|
Some of them are actually funny. Look at this one:  Lol 
Anyway, since it was because of a security breach from their devices that caused people such big losses, shouldn't the owners, creators, developers, and all those involved in this be arrested and put through trials just like how SBF (Sam Bankman Fried) of FTX was arrested for fraud? And, let me just throw this thought out there, and I'm not blaming anyone or anything like that, but what are the chances that there is actually no external hacker or anything but it's all done from the inside? Just saying.  I also thought about this whole thing as being an inside job. Because, why would a company neglect security alert that they know is a threat to their reputation. They knew their security was weak yet they neglected the warnings and didn't even come out publicly to warn their users. Also, they have been quiet on how to recover the coins that has been stolen, they are not providing solutions. lastly, why is it only Coldcard that is being attacked?
|
|
|
|
|
LoyceV
Legendary

Activity: 4116
Merit: 22411
Thick-Skinned Gang Leader and Golden Feather 2021
|
Two extra words from the 2048 standard seed dictionary yields 23 bits of entropy, 10 million possibilities for every wallet. I think that is beyond the realm of where this attack becomes economically feasible. My guess is it was a very simple two word combo that may be in the 10000 most common passwords or something. I assume this only happened to a wallet that already had a "decoy" amount stored on an address without additional passphrase. So out of about 1 trillion potentional seed phrases with 40 bit entropy, the attacker finds thousands of funded wallets. For those thousands, 10 million possibilities per wallet is not that far fetched. The victim does bear some responsibility here. There is no denying that, no matter how much people dislike hearing it. When a passphrase is optional and users choose not to use it, they significantly increase the risk of becoming victims sooner or later. Unfortunately, that's the direction it almost inevitably leads. It was also optional to keep the hardware device with a seed phrase created from 256 manual coin tosses offline, and sign only transactions manually entered on the keyboard. My point is: there's always more "the victims could have done". By your logic, it's always at least partially the victim's fault. I disagree. This is basic functionaly for a hardware wallet they sold for hundreds of dollars. The only reason to pay that much for such a simple piece of hardware is that it should be absolutely secure.
|
¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
|
|
|
flatt
Newbie

Activity: 11
Merit: 0
|
 |
Today at 08:05:11 AM Last edit: Today at 09:01:24 AM by Mr. Big |
|
I also thought about this whole thing as being an inside job. Because, why would a company neglect security alert that they know is a threat to their reputation. They knew their security was weak yet they neglected the warnings and didn't even come out publicly to warn their users. Also, they have been quiet on how to recover the coins that has been stolen, they are not providing solutions. lastly, why is it only Coldcard that is being attacked?
I believe the attacker also wish other 'self-custody wallet' have the same vulnerability like Coldcard did. And there will be no solutions to stop the hacker on this attack, because the generated seed is already made and there's no way to revert it. The only solution is moving the vulnerable fund to new seed. One more thing to deny "an inside job": people outside the job also able to make an automation script to brute-force all the vulnerable seeds. It was just a poor mistake made by their team.
The question on my mind is will white hat be able to recover the stolen bitcoin? and if they do. It would be better to just send the recovered bitcoins to their original address. Instead asking for verifications from the victims and refusing to return the recoup coins if they can't verify.
1. The tasks isn't to recover the stolen bitcoin, the tasks is to secure the bitcoin available on the "seed" that has not been stolen yet. 2. Sending the recovered bitcoins to their original address with a vulnerable seed isn't a better option at all. It is the MOST worse option.
|
|
|
|
|
|
decodx
|
 |
Today at 08:34:51 AM |
|
Anyway, since it was because of a security breach from their devices that caused people such big losses, shouldn't the owners, creators, developers, and all those involved in this be arrested and put through trials just like how SBF (Sam Bankman Fried) of FTX was arrested for fraud? And, let me just throw this thought out there, and I'm not blaming anyone or anything like that, but what are the chances that there is actually no external hacker or anything but it's all done from the inside? Just saying.  They should be held responsible. And face consequences, of course. But technically coldcard and SBF are quite different. SBF was a classic case of fraud and embezzlement. Nevertheless, whether this was deliberate theft or just incompetence, there needs to be a thorough investigation into what happened and who should be held accountable.
|
| MoBit | | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | | NO LOGS LOW FEES PGP GUARANTEE | | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | | | ▄██████▄▄▄ █████████████▄▄ ███████████████ ███████████████ ███████████████ ███████████████ ███░░█████████ ███▌▐█████████ █████████████ ███████████▀ ██████████▀ ████████▀ ░▀▀██▀▀ |
|
|
|
tvbcof
Legendary

Activity: 5278
Merit: 1314
|
 |
Today at 09:18:59 AM |
|
What's wrong with a laminated paper wallet rolled up in a sealed PVC pipe filled with rice and buried in backyard?
Basically this is in-line with my preferred set of solutions, or at least a key element of one. It remains the case, however, that you have to have enduring confidence in the entropy used to create the wallet. Same as any other solution including Coinkite wares. Some of the reasons I chose Coldcard Q included that the ~nvk dude had been around a while and I didn't see strong evidence of his being involved in crooked undertakings. Of course it would be difficult to vet his employees and contractors. They also used seemingly good hardware rng's. Sadly, it/they were not used for the most critical cryptographic work as we would later learn. I've a distaste for anything which uses electromagnetic radiation for comms (or dicking with uSD cards is a hassle with it's own security and usability issues.) When I was shopping, Coldcard Q was the only device which made use of two-way QR-code interactions, and as a bonus, one could physically cut the radio options. Mostly the device was powerful and usable for more complex work given it's form-factor, but I only appreciated that _fully_ after using it. In my initial research I actually did find and note at least one report of Coldcard funds vanishing, and it did give me pause. Not seeing a huge number of them I decided, with reluctance, to chalk them up to probable user-error, competitor FUD, or some such. Now it looks more like proof-of-concept and getting a little spending money by someone somewhere. If Coinkite really did ignore and bury the complaints, that is not at all a good look. I am hopeful that in order to make amends to the community, Coinkite donates the whole Coldcard Q effort, including supply chain info, to the community. Code development _INCLUDING TESTING_, profiling, distribution, etc might then be able to be done by people who have a wider range of skills and interests. It would be great if such firmware would be distributed with a bootstrapped environment (compilers, test harnesses, etc) which may foster more interest among users to undertake more complex tasks.
|
sig spam anywhere and self-moderated threads on the pol&soc board are for losers.
|
|
|
vapourminer
Legendary

Activity: 5110
Merit: 6621
what is this "brake pedal" you speak of?
|
 |
Today at 10:34:44 AM |
|
The victim does bear some responsibility here. There is no denying that, no matter how much people dislike hearing it. When a passphrase is optional and users choose not to use it, they significantly increase the risk of becoming victims sooner or later. Unfortunately, that's the direction it almost inevitably leads. some people have a non passphrase wallet as a decoy with passphrases behind it. but that doesnt mean they want to lose those coins, even as warning.
|
|
|
|
|
Wind_FURY
Legendary

Activity: 3724
Merit: 2210
|
 |
Today at 10:58:59 AM |
|
Seeing some of the responses to this makes my blood boil a bit on behalf of the victims.
"Oh they should have added passphrase, should have used dice, etc."
Sure - in hindsight, obviously, that would have protected them from this attack. But this is not correlated with whether this is something they should have done. In my mind - this is not what a passphrase is meant to protect against. It is for the case where your exact seed gets exposed, if your backup gets stolen, if it's accidentally uploaded to the internet, etc.
An equivalent bug could have seen the initial seed be perfectly fine, and then adding a passphrase through some bug eliminates a lot of that initial seed entropy. Or that the dice roll entries delete the initial entropy. Then what would people say? "Oh you should have verified the code and trusted the hardware RNG." It's easy to be wise after the fact.
It's just a mixture of bad luck and negligence on the part of the developer(s).
What scares me about this is that it just feels so random, so unavoidable on the part of the users. It feels like how when you get on a plane you're hoping it doesn't crash, but one in a few million will go down just out of sheer bad luck, through no fault of your own.
I think my biggest taking from this is just that spreading across 2-4 different technologies is probably worthwhile. Other than that I'm not sure there is much of a lesson here for the end user. It just sucks.
I'm sorry.
The Silver Lining - At least ColdCard didn't sell as much hardware devices as Trezor or Ledger. If ColdCard was the most successful hardware wallet that sold devices to millions of users, I'm very confident that the current situation would be more like the FTX crash or the Terra Luna crash. The community in general is still "lucky" that the stupidity came from the ColdCard developers.
|
|
|
|
|
suzanne5223
|
 |
Today at 11:17:45 AM |
|
The victim does bear some responsibility here. There is no denying that, no matter how much people dislike hearing it. When a passphrase is optional and users choose not to use it, they significantly increase the risk of becoming victims sooner or later. Unfortunately, that's the direction it almost inevitably leads. some people have a non passphrase wallet as a decoy with passphrases behind it. but that doesnt mean they want to lose those coins, even as warning. While some people dont use a passphrase due to their level of understanding (newbie) and the trust they have in the wallet based on their security claim, with the inclusion of influencer marketing hype on YouTube, etc. Therefore, the people who should be responsible the most are the wallet manufacturing company. 1. An alarm was raised about the issue years ago, but they ignore 2. They used the entropy bits that are not advisable for security One of the thing i believe this incident demonstrates is that every security flaw alarm raised shouldn't be ignore; wallet manufacturers should always work with white hackers in doing security check on their devices because technology is always dvncing, wllet mnufacturer should lways consider the newbie level of understanding when they are creating their device, nd we as a community should also reconsider some hardware wallets to sure there's no hardware people are currently using that will be next Coldcard because nothing is totally perfect.
|
| Kings Game | 🎰 🎲 ⚽ | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | ████████████████████████████
████████████████████████████ | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | ████████████████████████████
| ..500%.. | WELCOME BONUS + 250 FREE SPINS |
████████████████████████████ | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | WIN NOW |
|
|
|
Pmalek
Legendary

Activity: 3570
Merit: 9412
|
 |
Today at 11:27:28 AM |
|
The Bitcoin Policy Institute created a visual overview of the Coldcard vulnerability, comparing seed phrases to atoms. In their video they describe a properly generated seed as an atom hidden somewhere across two billion galaxies, impossible to find by any computer/AI. Compared to that huge space, Coldcard's seed generation is presented as one atom in a virus. A computer could find it in a few hours. It's an interesting watch, so take a look: https://www.youtube.com/watch?v=IwrKWdxt0YMOne person found a new use case for his Coldcard Q. He created a game, The Bitcoin Dungeon. You run around the different levels, collecting bitcoin and staying away from bankers. It's not meant to make fun of the victims that lost their coins. It just shows what's possible. https://x.com/pastorcoin/status/2084438312803090648
|
| EARNBET | | | ⚽ 🏀 🏈 🏓 🎯 🥊 |
| ⚾ 🎾 ⛳ 🏐 🏏 🏎️ | | |
███████▄▄███████████ ████▄██████████████████ ██▄▀▀███████████████▀▀███ █▄████████████████████████ ▄▄████████▀▀▀▀▀████████▄▄██ ███████████████████████████ █████████▌████▀████████████ ███████████████████████████ ▀▀███████▄▄▄▄▄█████████▀▀██ █▀█████████████████████▀██ ██▀▄▄███████████████▄▄███ ████▀██████████████████ ███████▀▀███████████ | ....HIGHEST.... VIP REWARDS ✔ G U A R A N T E E D
| | | 🜲 | KING OF THE CASTLE $200K in prizes | | | ..PLAY NOW.. |
|
|
|
Cookdata
Legendary
Online
Activity: 1750
Merit: 1412
Not Your Keys, Not Your Bitcoin
|
 |
Today at 11:43:48 AM |
|
well guys if you own the keys you own the coins if you are trusting someone to safeuard your assest the whole point of btc is lost make your own wallet dont let someone make it for you or their software before investing try to understand a bit about what the technology is and if you dont understand it then its just simply isnt for you. I heard about bitcoin in 2025 for the first time and people from 2015 0r 2020 dosent seem to understad what bitcoin is. What are you saying? The coldcard mistake is a bug(deliberately or not, nobody can confirm if it was intentional), this does not makes other hardware trash or other random number generators invalid, there are plenty of wallet with good entropy. Hardware wallet are still the safest way to keep coins from scammers like this. You can actually generate a good entropy of seed phrase if you don't trust the wallet to do it for you, do it yourself with a dice or let a secure device does it for you. However, you still need a hardware wallet to keep your keys from the internet. the coldcard company is to blame but no one was force to use thier wallet always do your own due deligence to make sure what you own is secure and safe .
This is bullshit though, do you think people that bought the hardware wallet had the intention of losing their Bitcoin. I myself once fancy cold card, it was a matter of time before I get one until this incident. You know why your comment is funny? What happened to Coldcard can happen to any device, this is not the first time a device with bad entropy is been reported, it just happen that we are in AI era where things are made easy for scammers. I'm not sure if you have a hardware wallet the what you wrote up there.
|
| . .Duelbits..REWARDING, BEYOND LIMITS... | █████████████████████████ █████████████████████████ ███████████▀▀░░▀█▄░░▀████ ████████▀░░░░░░░░▀█▄░████ ███████░░░░▄▄░░▄░░░▀█████ ██████░░░░░▀▀▄██▀░░░░████ █████░░░██░▄██▀▄▄░░░█████ ████░░░░░▄██▀░░▀▀░░██████ █████▄░░▀█▀░██░░░░███████ ████░▀█▄░░░░░░░░▄████████ ████▄░░▀█▄░░▄▄███████████ █████████████████████████ █████████████████████████ | █████████████████████████ █████████████████████████ █████████▀░░▀░███████████ ████████░░░▄░█░██████████ ███████████▌▐██░█████████ ███████████░███▌▐████████ ██████████░█████░████████ ██████▀░▄░▀███▀░▄░▀██████ █████░▄▀░░░░█░▄▀░░░░█████ █████░░░░░░░█░░░░░░░█████ ██████▄░░░▄███▄░░░▄██████ █████████████████████████ █████████████████████████ | █ █ █ █ █ █ █ █ █ █ █ █ █ | |
| | █ █ █ █ █ █ █ █ █ █ █ █ █ | PLAY NOW |
[/center
|
|
|
Danish Ali
Newbie

Activity: 3
Merit: 0
|
 |
Today at 12:15:38 PM |
|
I'm wondering if this situation demonstrates the need for more than what you've suggested--what that is I don't know, but I've been seeing a lot of vulnerabilities exploited/pointed out by hackers using AI, which includes HW wallets, altcoin blockchains (if I'm not mistaken), and other miscellaneous things that were once thought to be safe but turned out weren't.
I've always liked the concept of DIY HW wallets but haven't ever given one a shot. Has there been any code written to make any for BTC? Would one of those not potentially be safer overall?
Shit's scary out there right now.
Honestly the concern is justified, attack area has grown by leaps and bounds and what was once considered safe two years ago is no longer safe. SeedSigner is good option for Bitcoin in particular. Open source, air gapped, parts cost around $50, and community guides are good enough that technically curious person could make one without too much trouble. With no company owned software, there is no need to blindly trust maker code. You should be able to follow build process easily, as you have some experience with it. Could be a good time to finally take that shot.
|
|
|
|
|
|
Catenaccio
|
 |
Today at 12:44:35 PM |
|
SeedSigner is good option for Bitcoin in particular. Open source, air gapped, parts cost around $50, and community guides are good enough that technically curious person could make one without too much trouble.
Seedsigner looks good by passing 10 tests there. https://walletscrutiny.com/hardware/seedsigner/It is recommended by Jameson Lopp in his list of recommended wallets but honestly I don't know and I am unsure because he recommended Coldcard and has yet removed this terrible hardware wallet from the list. In this What are best Bitcoin wallets, there is no recommendation for SeedSigner. Personally I don't consider saving cost is important when I buy a hardware wallet because I understand its importance and there are free open source software wallets to use. If I spend money to buy a hardware wallet, I buy a best one and don't mind to save cost that possibly puts my fund at risk if I buy a bad hardware wallet.
|
|
|
|
|
|
| R |
▀▀▀▀▀▀▀██████▄▄ ████████████████ ▀▀▀▀█████▀▀▀█████ ████████▌███▐████ ▄▄▄▄█████▄▄▄█████ ████████████████ ▄▄▄▄▄▄▄██████▀▀ | LLBIT | | | 4,000+ GAMES███████████████████ ██████████▀▄▀▀▀████ ████████▀▄▀██░░░███ ██████▀▄███▄▀█▄▄▄██ ███▀▀▀▀▀▀█▀▀▀▀▀▀███ ██░░░░░░░░█░░░░░░██ ██▄░░░░░░░█░░░░░▄██ ███▄░░░░▄█▄▄▄▄▄████ ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀ | █████████ ▀████████ ░░▀██████ ░░░░▀████ ░░░░░░███ ▄░░░░░███ ▀█▄▄▄████ ░░▀▀█████ ▀▀▀▀▀▀▀▀▀ | █████████ ░░░▀▀████ ██▄▄▀░███ █░░█▄░░██ ░████▀▀██ █░░█▀░░██ ██▀▀▄░███ ░░░▄▄████ ▀▀▀▀▀▀▀▀▀ |
| | | | | | | | | ▄▄████▄▄ ▀█▀▄▀▀▄▀█▀ ▄▄░░▄█░██░█▄░░▄▄ ▄▄█░▄▀█░▀█▄▄█▀░█▀▄░█▄▄ ▀▄█░███▄█▄▄█▄███░█▄▀ ▀▀█░░░▄▄▄▄░░░█▀▀ █░░██████░░█ █░░░░▀▀░░░░█ █▀▄▀▄▀▄▀▄▀▄█ ▄░█████▀▀█████░▄ ▄███████░██░███████▄ ▀▀██████▄▄██████▀▀ ▀▀████████▀▀ | . ▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄ ░▀▄░▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄░▄▀ ███▀▄▀█████████████████▀▄▀ █████▀▄░▄▄▄▄▄███░▄▄▄▄▄▄▀ ███████▀▄▀██████░█▄▄▄▄▄▄▄▄ █████████▀▄▄░███▄▄▄▄▄▄░▄▀ ████████████░███████▀▄▀ ████████████░██▀▄▄▄▄▀ ████████████░▀▄▀ ████████████▄▀ ███████████▀ | ▄▄███████▄▄ ▄████▀▀▀▀▀▀▀████▄ ▄███▀▄▄███████▄▄▀███▄ ▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄ ▄██▀▄███░░░▀████░███▄▀██▄ ███░████░░░░░▀██░████░███ ███░████░█▄░░░░▀░████░███ ███░████░███▄░░░░████░███ ▀██▄▀███░█████▄░░███▀▄██▀ ▀██▄▀█▄▄▄██████▄██▀▄██▀ ▀███▄▀▀███████▀▀▄███▀ ▀████▄▄▄▄▄▄▄████▀ ▀▀███████▀▀ | | OFFICIAL PARTNERSHIP SOUTHAMPTON FC FAZE CLAN SSC NAPOLI |
|
|
|
|