Bitcoin Forum
August 04, 2026, 10:07:22 PM *
News: COLDCARD users only: critical vulnerability risks funds stored on COLDCARD devices; immediate action required
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 [16] 17 »  All
  Print  
Author Topic: Large-scale Coldcard compromise (1360.23 BTC stolen so far)  (Read 4875 times)
LoyceV
Legendary
*
Offline

Activity: 4116
Merit: 22411


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
Today at 01:03:42 PM
Merited by vapourminer (1)
 #301

The community in general is still "lucky" that the stupidity came from the ColdCard developers.
This is one of the reasons I'm always careful paranoid when a new wallet (be it hardware or software) is released. It took me years to trust Ledger (until they broke that trust), and now I only have Trezor left on my personal preferred list of hardware wallets.
The fact that this Coldcard flaw was around for 5 years makes it only harder to trust anything.

Personally I don't consider saving cost is important when I buy a hardware wallet because I understand its importance and there are free open source software wallets to use. If I spend money to buy a hardware wallet, I buy a best one and don't mind to save cost that possibly puts my fund at risk if I buy a bad hardware wallet.
Paying more doesn't guarantee a better hardware wallet, Coldcard wasn't cheap.



Verify, don't trust. Easier said than done.

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
EstherBtc
Jr. Member
*
Offline

Activity: 63
Merit: 8


View Profile
Today at 01:09:12 PM
 #302


Got this from X https://x.com/COLDCARDwallet/status/2084596971268956161

Someone's comment on this post made me sad, he said "Thank you cold card and coinkite for destroying trust in hardware device manufacturers for an entire class of Bitcoiners. Your lesson will be taught for decades to come".

Coldcard should just refund those affected. Unfortunately, some users who are not online don't even know that their bitcoin is under attack and has been wiped or about to be.

asUHWEceyc
Full Member
***
Offline

Activity: 167
Merit: 194

dekleptocraticizationismist


View Profile WWW
Today at 01:18:16 PM
 #303

This certainly appears to be an exit scam with good plausible deniability when you look back at JWWeatherman_ badgering coldcard to add external entropy via dice rolls to their quick start guide in the 2020-2021 period, which they refused to do.

It also casts a shadow on their podcast promoters, who were most likely mere useful idiots.

The company is obviously done, through reputational damage and/or lawsuits, but someone has the coins
Cookdata
Legendary
*
Offline

Activity: 1750
Merit: 1412


Not Your Keys, Not Your Bitcoin


View Profile
Today at 01:49:35 PM
Merited by LoyceV (2), vapourminer (1)
 #304

I have seen some creepy tweets of old posts from Coldcard but I don't think this company is worth defending.



https://x.com/coldcardwallet/status/1447213375398846473

I don't think I'm overreacting right!

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits..REWARDING, BEYOND LIMITS...
█████████████████████████
█████████████████████████
███████████▀▀░░▀█▄░░▀████
████████▀░░░░░░░░▀█▄░████
███████░░░░▄▄░░▄░░░▀█████
██████░░░░░▀▀▄██▀░░░░████
█████░░░██░▄██▀▄▄░░░█████
████░░░░░▄██▀░░▀▀░░██████
█████▄░░▀█▀░██░░░░███████
████░▀█▄░░░░░░░░▄████████
████▄░░▀█▄░░▄▄███████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████▀░░▀░███████████
████████░░░▄░█░██████████
███████████▌▐██░█████████
███████████░███▌▐████████
██████████░█████░████████
██████▀░▄░▀███▀░▄░▀█████
█████░▄▀░░░░█░▄▀░░░░█████
█████░░░░░░░█░░░░░░░█████
██████▄░░░▄███▄░░░▄██████
█████████████████████████
█████████████████████████


























  PLAY NOW  
[/center
Lucius
Legendary
*
Offline

Activity: 4046
Merit: 7684



View Profile WWW
Today at 01:51:55 PM
Merited by vapourminer (1), F2b (1)
 #305

What's wrong with a laminated paper wallet rolled up in a sealed PVC pipe filled with rice and buried in backyard?

It's okay if you don't have a dog that likes to dig, and you haven't dug deep enough - or if you have a neighbor who watches you just for fun and decides to dig around your yard when you're not home. In addition, in some countries there are laws that say that the owner of the land is the owner of what is found up to a certain depth, and everything else is owned by the state. This is how they protect oil and gas deposits from ordinary people.

The ground settles over time, so if you bury something to a depth of, say, half a meter, it will slowly sink over time, especially if the soil is moist and there is a lot of rainfall.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits..REWARDING, BEYOND LIMITS...
█████████████████████████
█████████████████████████
███████████▀▀░░▀█▄░░▀████
████████▀░░░░░░░░▀█▄░████
███████░░░░▄▄░░▄░░░▀█████
██████░░░░░▀▀▄██▀░░░░████
█████░░░██░▄██▀▄▄░░░█████
████░░░░░▄██▀░░▀▀░░██████
█████▄░░▀█▀░██░░░░███████
████░▀█▄░░░░░░░░▄████████
████▄░░▀█▄░░▄▄███████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████▀░░▀░███████████
████████░░░▄░█░██████████
███████████▌▐██░█████████
███████████░███▌▐████████
██████████░█████░████████
██████▀░▄░▀███▀░▄░▀█████
█████░▄▀░░░░█░▄▀░░░░█████
█████░░░░░░░█░░░░░░░█████
██████▄░░░▄███▄░░░▄██████
█████████████████████████
█████████████████████████


























  PLAY NOW  
philipma1957
Legendary
*
Offline

Activity: 4928
Merit: 12318


'The right to privacy matters'


View Profile WWW
Today at 02:47:28 PM
Merited by abaeze (2)
 #306

This certainly appears to be an exit scam with good plausible deniability when you look back at JWWeatherman_ badgering coldcard to add external entropy via dice rolls to their quick start guide in the 2020-2021 period, which they refused to do.

It also casts a shadow on their podcast promoters, who were most likely mere useful idiots.

The company is obviously done, through reputational damage and/or lawsuits, but someone has the coins

lets say inside job.

the issue is any other wallet company can do the same.

firmware 2027 for ledger makes a bug
and in 2028 ledger hacked.

right down the road.

so  back to core only?

since if core is bad it is all dead.

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|..BTC......XMR...
..USDT.....LTC...
....Fees  0.8%.....
abaeze
Full Member
***
Offline

Activity: 490
Merit: 172



View Profile
Today at 03:39:59 PM
 #307

This certainly appears to be an exit scam with good plausible deniability when you look back at JWWeatherman_ badgering coldcard to add external entropy via dice rolls to their quick start guide in the 2020-2021 period, which they refused to do.

It also casts a shadow on their podcast promoters, who were most likely mere useful idiots.

The company is obviously done, through reputational damage and/or lawsuits, but someone has the coins

lets say inside job.

the issue is any other wallet company can do the same.

firmware 2027 for ledger makes a bug
and in 2028 ledger hacked.

right down the road.

so  back to core only?

since if core is bad it is all dead.
The Coldcard hacking incident is actually challenging the entire Bitcoin ecosystem, no one can say exactly what will happen in the future, but self-custody, which was people's last resort to keep their digital assets Bitcoin safe, is now distrusted. You are right that there is no guarantee that other companies will not do the same in the near future. Without people's trust and confidence, no security system is effectively secure, no matter how much companies say "your assets are 100% safe through our products", the public and companies must understand these things.

Danish Ali
Newbie
*
Offline

Activity: 3
Merit: 0


View Profile
Today at 04:29:39 PM
 #308

Seedsigner looks good by passing 10 tests there.
https://walletscrutiny.com/hardware/seedsigner/

It is recommended by Jameson Lopp in his list of recommended wallets but honestly I don't know and I am unsure because he recommended Coldcard and has yet removed this terrible hardware wallet from the list.

In this What are best Bitcoin wallets, there is no recommendation for SeedSigner.

Personally I don't consider saving cost is important when I buy a hardware wallet because I understand its importance and there are free open source software wallets to use. If I spend money to buy a hardware wallet, I buy a best one and don't mind to save cost that possibly puts my fund at risk if I buy a bad hardware wallet.
That recommendation list on Lopp's is losing trust is fair concern. However, SeedSigner trust model is quite different from that of Coldcard. Risk of Coldcard was centralized decision of a company owned maker. SeedSigner does not have maker, it's made out of everyday parts, so that type of failure is not relevant.
Price factor plays a different role here as well. It is not about cost of the product you are buying, it is about removing risk from your shipping and parts supply. That is different type of benefit.
It is still on Lopp's list and WalletScrutiny passes it, that is pretty good starting point for open source hardware.
asUHWEceyc
Full Member
***
Offline

Activity: 167
Merit: 194

dekleptocraticizationismist


View Profile WWW
Today at 04:53:22 PM
 #309

This certainly appears to be an exit scam with good plausible deniability when you look back at JWWeatherman_ badgering coldcard to add external entropy via dice rolls to their quick start guide in the 2020-2021 period, which they refused to do.

It also casts a shadow on their podcast promoters, who were most likely mere useful idiots.

The company is obviously done, through reputational damage and/or lawsuits, but someone has the coins

lets say inside job.

the issue is any other wallet company can do the same.

firmware 2027 for ledger makes a bug
and in 2028 ledger hacked.

right down the road.

so  back to core only?

since if core is bad it is all dead.

I can only recommend storing coins safely at MtGox, BTC-e or FTX at this time

All wallets are hardware wallets; some consist of electronic, analog and/or auditable components. Bitcoin has been more or less "working" for a long time and is highly scrutinized, with fewer LOC and less stuff bolted on the farther you go back. Intel CPUs commonly relied on, on the other hand, are implicitly un-examinable.

If someone's selling a cheap turnkey solution it might be too good to be true. It seems reasonable that a company marketing such a product in the future may need to insure every device sold with an implementation loss warranty up to some nominal fiat amount.
vapourminer
Legendary
*
Offline

Activity: 5110
Merit: 6621


what is this "brake pedal" you speak of?


View Profile
Today at 05:28:10 PM
 #310

I can only recommend storing coins safely at MtGox, BTC-e or FTX at this time


you jest but at least mtgox people got ~20% of their btc/bcash back

LoyceV
Legendary
*
Offline

Activity: 4116
Merit: 22411


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
Today at 05:41:33 PM
 #311

Hypothetical: it just occurred to me that even if Coldcard knew about this vulnerability, they couldn't have warned users about it. The moment they issue a warning, potential attackers would know about it too, and their warning would have been the catalyst to losing funds.
So once the bug was out there, all they could reasonably do was offer updated firmware and remove the vulnerability from newly sold devices.

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
negotiation4
Newbie
*
Offline

Activity: 14
Merit: 15


View Profile
Today at 06:32:28 PM
 #312

Hypothetical: it just occurred to me that even if Coldcard knew about this vulnerability, they couldn't have warned users about it. The moment they issue a warning, potential attackers would know about it too, and their warning would have been the catalyst to losing funds.
So once the bug was out there, all they could reasonably do was offer updated firmware and remove the vulnerability from newly sold devices.
Not true, they could have advised moving funds without disclosing the vulnerability up front.
BlackHatCoiner
Legendary
*
Offline

Activity: 2100
Merit: 10005


Cross Chain Crypto Swap


View Profile
Today at 06:51:25 PM
 #313

Hypothetical: it just occurred to me that even if Coldcard knew about this vulnerability, they couldn't have warned users about it. The moment they issue a warning, potential attackers would know about it too, and their warning would have been the catalyst to losing funds.
So once the bug was out there, all they could reasonably do was offer updated firmware and remove the vulnerability from newly sold devices.
They could have taken most of the coins though, and give it back to the soon-to-be-victims though. Regardless, however, I agree that either way their business would be completely over.

And yes, they could have warned the user of a vulnerability, but that should be worded in a way that it does not reveal your cold storage is at risk, or attackers would have got sooner than the victims by just scanning the codebase.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
tvbcof
Legendary
*
Online Online

Activity: 5278
Merit: 1314


View Profile
Today at 07:01:07 PM
 #314

Hypothetical: it just occurred to me that even if Coldcard knew about this vulnerability, they couldn't have warned users about it. The moment they issue a warning, potential attackers would know about it too, and their warning would have been the catalyst to losing funds.
So once the bug was out there, all they could reasonably do was offer updated firmware and remove the vulnerability from newly sold devices.
Not true, they could have advised moving funds without disclosing the vulnerability up front.

The only feasible way to 'get the word out' would be via an 'emergency' such as we are seeing now.

Of course I am very interested in whether these guys are crooks or not, so I try to look at things from all angles.  What if there was an even better reason (e.g., and even bigger back-door.)  The 'responsible' thing to do would be to scare the shit out of people with a relatively bogus defect and a dose of social media engineering.  In that way, everyone would hear it pretty soon, and would take the desired action of draining their Coldcard-based wallets ASAP while in the scheme of things the userbase would not actually lose all that much.  I'm pleasantly surprised that none of my stuff was hit.

Anyway, that's a charitable hypothetical excuse for Coinkite's activities and proclivities.

---

As for keeping this particular vulnerability undisclosed, it's not real practical.  The problem was really a pretty basic one which happens all the time.  [There may be some code running in space built against header files inappropriate for the Linux kernel installed due to problems much like this one.  Who knows?]

I don't do almost any coding any more, but my friends who do are ga-ga over AI.  All I can say is that if AI missed a very common pre-processor issue like this, it's not very good at code checking.  Did they forget to teach the model that RNG was extra critical?  Do they even need to?  Not impressed!


sig spam anywhere and self-moderated threads on the pol&soc board are for losers.
ryzaadit
Legendary
*
Offline

Activity: 3276
Merit: 1380



View Profile
Today at 07:16:08 PM
 #315

Seeing the response from a bug on the newest firmware from Coinkite Support Specialist is funny.


For instance, giving a response from a solution aspect to the firmware bugs. They respond to the bug on the latest firmware by giving a new device COLDCARD. Man, you own COLDCARD.... these what you should do on COLDCARD.



▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
Forsyth Jones
Legendary
*
Offline

Activity: 1974
Merit: 2178


I love Bitcoin!


View Profile WWW
Today at 07:49:23 PM
 #316

I have seen some creepy tweets of old posts from Coldcard but I don't think this company is worth defending.



https://x.com/coldcardwallet/status/1447213375398846473

I don't think I'm overreacting right!
He is very arrogant, which makes it harder not to think it was intentional, because when dealing with a data security device, the first thing a expert cryptography/dev must know is how to generate sensitive data with a good source of entropy. Coldcard is a hardware wallet, which has all the security features we can imagine, but they failed in the most critical aspect: the entropy used to generate wallets. Only those who used a strong passphrase were safe.

Owners of hardware wallets should know what passphrase is, this also makes me have the following question: and other devices from other brands, how can we guarantee that such devices do not have some other flaw that could cause potential losses, we are in the age of AI guys, while there are millions of pcs using AI to search for hardware/software failures out there and they are evolving every day, we cannot do what the arrogant Nvk from coldcard did, which was ignore all the warnings from 2021 (like this tweet on the image for example).

Ledger, its competitor that also did a lot of shit (like Recover), has a team of white hat who scour their competitors' devices in search of bugs, and mainly, very serious vulnerabilities, while nvk didn't review its own code, and if it did, it probably used vibe coding that did a lousy analysis, at the very least, as a developer, he should have a team responsible for reviewing the all code.

I just haven't bought a coldcard yet, besides its price, I would have to pay between 60% - 300% in customs fees (yes, I live in a country that outrageously abuses taxing its own citizens).

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits..REWARDING, BEYOND LIMITS...
█████████████████████████
█████████████████████████
███████████▀▀░░▀█▄░░▀████
████████▀░░░░░░░░▀█▄░████
███████░░░░▄▄░░▄░░░▀█████
██████░░░░░▀▀▄██▀░░░░████
█████░░░██░▄██▀▄▄░░░█████
████░░░░░▄██▀░░▀▀░░██████
█████▄░░▀█▀░██░░░░███████
████░▀█▄░░░░░░░░▄████████
████▄░░▀█▄░░▄▄███████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████▀░░▀░███████████
████████░░░▄░█░██████████
███████████▌▐██░█████████
███████████░███▌▐████████
██████████░█████░████████
██████▀░▄░▀███▀░▄░▀█████
█████░▄▀░░░░█░▄▀░░░░█████
█████░░░░░░░█░░░░░░░█████
██████▄░░░▄███▄░░░▄██████
█████████████████████████
█████████████████████████


























  PLAY NOW  
Alone055
Hero Member
*****
Online Online

Activity: 1862
Merit: 720


Catalog Websites


View Profile WWW
Today at 08:16:12 PM
 #317

Hypothetical: it just occurred to me that even if Coldcard knew about this vulnerability, they couldn't have warned users about it. The moment they issue a warning, potential attackers would know about it too, and their warning would have been the catalyst to losing funds.
So once the bug was out there, all they could reasonably do was offer updated firmware and remove the vulnerability from newly sold devices.
They could have taken most of the coins though, and give it back to the soon-to-be-victims though. Regardless, however, I agree that either way their business would be completely over.

And yes, they could have warned the user of a vulnerability, but that should be worded in a way that it does not reveal your cold storage is at risk, or attackers would have got sooner than the victims by just scanning the codebase.

Would it be illogical to think that this might not be just a random attack but a preplanned one? For which the bug or vulnerability was planted years ago, and was never found or patched on purpose to keep collecting information for a major attack, but doing it in a way that shouldn't make it suspicious for those in control of everything? Because there are cases unfolding where users reported similar problems years ago, but the developers or their support never took them seriously or looked into it. Maybe those few people who got their funds stolen back then were just victims of a few test tries if it actually works or not?  Roll Eyes

█████████████████████████
████████▀▀████▀▀█▀▀██████
█████▀████▄▄▄▄████████
███▀███▄███████████████
██▀█████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
██▄███████████████▀▀▄▄███
███▄███▀████████▀███▄████
█████▄████▀▀▀▀████▄██████
████████▄▄████▄▄█████████
█████████████████████████
 
 BitList 
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
Bitcointalk Archive 📚
Visualization ' Search

.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
CryptoCrookz
Jr. Member
*
Offline

Activity: 63
Merit: 2


View Profile WWW
Today at 08:25:31 PM
 #318

Seems diversification is the only real answer, with a preselection of suppliers based on some code aspects like rng characteristics - though let's see what the next 'hack of the month' will be. Including custodial options in the approach is also not bad idea, 'not your keys not your coins' is not the answer to everything.
shahzadafzal
Copper Member
Legendary
*
Offline

Activity: 2254
Merit: 3487



View Profile
Today at 09:12:58 PM
 #319

We've run AI-assisted review against our critical codebases, including in the weeks before the exploit. It did not catch this vulnerability. Since the incident, we've also tested our code against frontier models, including Kimi K3, Claude Fable, and Codex 5.6. None of them caught it.

Now that’s a straight lie.

Coinkite’s latest post claims they performed AI-assisted code reviews weeks before the vulnerability was discovered. Yet people have shown that Claude can identify the bug in just a 8 minutes.

Yes, it depends on the prompt too, but I’d expect the entropy generation logic to be one of the first areas reviewed. Instead of prompts like “Find a security issue in this code” or “find a bug in this code” will never expose the issue.

Of course, I’m only speculating about the prompts they actually used before the vulnerability was discovered.

You can read the full post here https://x.com/coldcardwallet/status/2084731768632991801?s=46&t=EYlgQnpcCaCtcz2k1MwkNg

░░░░▄▄████████████▄
▄████████████████▀
▄████████████████▀▄█▄
▄██████▀▀░░▄███▀▄████▄
▄██████▀░░░▄███▀▀██████▄
██████▀░░▄████▄░░░▀██████
██████░░▀▀▀▀▄▄▄▄░░██████
██████▄░░░▀████▀░░▄██████
▀██████▄▄███▀░░░▄██████▀
▀████▀▄████░░▄▄███████▀
▀█▀▄████████████████▀
▄████████████████▀
▀████████████▀▀░░░░
 
 CCECASH 
Meuserna
Sr. Member
****
Offline

Activity: 335
Merit: 555


View Profile WWW
Today at 09:47:19 PM
 #320

We've run AI-assisted review against our critical codebases, including in the weeks before the exploit. It did not catch this vulnerability. Since the incident, we've also tested our code against frontier models, including Kimi K3, Claude Fable, and Codex 5.6. None of them caught it.

Now that’s a straight lie.

Coinkite’s latest post claims they performed AI-assisted code reviews weeks before the vulnerability was discovered. Yet people have shown that Claude can identify the bug in just a 8 minutes.

Yes, it depends on the prompt too, but I’d expect the entropy generation logic to be one of the first areas reviewed. Instead of prompts like “Find a security issue in this code” or “find a bug in this code” will never expose the issue.

Of course, I’m only speculating about the prompts they actually used before the vulnerability was discovered.

You can read the full post here https://x.com/coldcardwallet/status/2084731768632991801?s=46&t=EYlgQnpcCaCtcz2k1MwkNg

Coinkite also downplayed the attack. Their initial warning, published July 30, 2026, specifically said:

Quote
“Out of an abundance of caution, Coinkite is warning all users who generated a seed using a Mk3 on version 4.0.1 (March 2021) or any subsequent version that their funds may be at risk.”

“Mk4, Q and Mk5 are not affected based on our early analysis of the issue.”

Coinkite told users their Mk4, Mk5, and Q devices were safe before Coinkite established that was true.

It was not true.

Coinkite's attempt to downplay the severity of the attack gave owners of MK4, MK5, and Q devices false assurance their coins were safe while also giving thieves more time to work on finding and draining those users' wallets.

Every step of the way, Coinkite's handling of the catastrophe has been inexcusable.

Meanwhile, @NVK has been on Xwitter for days. He's been doing lots of reposting, but saying nothing.

Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 [16] 17 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!