Bitcoin Forum
August 05, 2026, 10:30:13 PM *
News: COLDCARD users only: critical vulnerability risks funds stored on COLDCARD devices; immediate action required
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 [17] 18 »  All
  Print  
Author Topic: Large-scale Coldcard compromise (1485.77 BTC stolen so far)  (Read 5618 times)
ovcijisir
Legendary
*
Offline

Activity: 2338
Merit: 1351


#kycfree 🗽


View Profile WWW
August 04, 2026, 10:02:19 PM
Last edit: Today at 10:47:48 AM by ovcijisir
Merited by cygan (3), examplens (1), ABCbits (1), decodx (1), jahead (1)
 #321

Be aware of fake Telegram groups, where they "help" with "wallet migration".

Scam telegram groups:

Code:
https://t.me/coldcardREAL
https://t.me/coldcardMigration

These groups are swaming with scammers that want victims to use their malicious links:
Code:
https://swiftprotocolresolvers.web.app/
http://migrate.coldcardfirmware.com
https://m-coldcard.web.app
https://dashboards.protocolsdata.workers.dev
https://coldcard-en.web.app
https://coldcard-devicenode.net/en/
https://coldcard-audit.com
https://dapplogin-connect.com
https://t.me/AiCustomerSupport247_bot
https://onchains-hub.vercel.app

Do not enter seed words there! Do not send funds there! Do not download any software from there!

Edit. Added new scams

▄███████████████████████▄
███████████████████████
████████████▀▀██████████
████████████████████████
██████████▄▄██████████
█████████████████████
███████████████████████
█████████████████████
██████████▀▀██████████
████████████████████████
██████████▄▄████████████
███████████████████████
▀███████████████████████▀
 
 MoBit 
████
██
██
██
██
██
██
██
██
██
██
██
████
 NO   LOGS
 
 LOW  FEES
 
 PGP  GUARANTEE
████
██
██
██
██
██
██
██
██
██
██
██
████
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
NUCLEAR7.1
Jr. Member
*
Online Online

Activity: 55
Merit: 2

Hmm...


View Profile
August 04, 2026, 10:13:31 PM
Last edit: August 04, 2026, 10:37:08 PM by NUCLEAR7.1
 #322

We've run AI-assisted review against our critical codebases, including in the weeks before the exploit. It did not catch this vulnerability. Since the incident, we've also tested our code against frontier models, including Kimi K3, Claude Fable, and Codex 5.6. None of them caught it.

Now that’s a straight lie.

Coinkite’s latest post claims they performed AI-assisted code reviews weeks before the vulnerability was discovered. Yet people have shown that Claude can identify the bug in just a 8 minutes.

Yes, it depends on the prompt too, but I’d expect the entropy generation logic to be one of the first areas reviewed. Instead of prompts like “Find a security issue in this code” or “find a bug in this code” will never expose the issue.

Of course, I’m only speculating about the prompts they actually used before the vulnerability was discovered.

You can read the full post here https://x.com/coldcardwallet/status/2084731768632991801?s=46&t=EYlgQnpcCaCtcz2k1MwkNg


Calling this a "straight lie" is jumping the gun a bit.

AI review results are heavily prompt-dependent. Running "find a bug in this code" against an entire firmware codebase is a very different task than pointing a model directly at the RNG function once you already know it's an entropy issue. Nobody outside Coinkite knows what prompts or scope they actually used pre-disclosure — that's the missing piece in this whole argument.

Hindsight also does a lot of heavy lifting here. Once the bug is public and everyone knows to look at seed/entropy generation, of course a model (or a human researcher) zeroes in on it fast. That's not really comparable to a blind review of the full codebase before anyone knew where the problem was.

That said, the underlying question is fair. If Coinkite actually ran targeted reviews of the RNG logic specifically, with well-crafted prompts, across multiple frontier models, and still came back empty — that would be a real red flag worth pressing them on. But without knowing exactly what they tested, how, and against what scope, there's no way to call this a "lie" with any confidence. It's either a genuine limitation of AI-assisted review under generic prompting, or a case of "we didn't look hard enough in the right place" — and those are two very different admissions.

Would be good to see Coinkite actually publish the prompts and methodology they used for both the pre- and post-incident reviews. That's the only way this gets resolved instead of argued about.
philipma1957
Legendary
*
Online Online

Activity: 4942
Merit: 12323


'The right to privacy matters'


View Profile WWW
August 04, 2026, 11:43:50 PM
 #323

I can only recommend storing coins safely at MtGox, BTC-e or FTX at this time


you jest but at least mtgox people got ~20% of their btc/bcash back



Yep and a long solid hodl so good they made nice money in fiat terms.

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|..BTC......XMR...
..USDT.....LTC...
....Fees  0.8%.....
DanWalker
Hero Member
*****
Offline

Activity: 2674
Merit: 580


Leading Crypto Sports Betting & Casino Platform


View Profile
Today at 12:34:00 AM
 #324

I have seen some creepy tweets of old posts from Coldcard but I don't think this company is worth defending.



https://x.com/coldcardwallet/status/1447213375398846473

I don't think I'm overreacting right!

wtf, it seems a retirement attack? Huh
is it when a developer intentionally inserts a bug into the entropy generation process so that it can later be used to steal user's wallet?

Ironically, that old tweet almost exactly describes the type of vulnerability that now appeared in ColdCard's firmware, so sad.
It seems they know everything, and made us fools.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
NotFuzzyWarm
Legendary
*
Offline

Activity: 4438
Merit: 3515


Evil beware: We have waffles!


View Profile
Today at 12:46:18 AM
Last edit: Today at 04:43:22 PM by NotFuzzyWarm
Merited by vapourminer (1)
 #325

.....
Gmaxwell detailed exactly what the ColdCard programmer(s) did wrong
Letting such an amateur bug slip through into production software is beyond inexcusable. So they wrote a critical function selection process but never added a followup state check flag? When debugging the software they made no allowances to actually see what RNG was being used? They should be and probably will be massively sued.

When I used to write CNC code that used #define and #ifdef/#ifndef to setup key functions I always followed it with 2 lines of code to act as a handshake to verify what I intended to run actually has been the one chosen and is the one running, if it wasn't it would throw a error about it. It just was common sense to do that and I'm not even a 'real' programmer as writing code was just part of what I did designing the systems we used to build. For someone who writes code for a living, not checking the state of critical functions is pure slop.

Worse, others have pointed out that Coinkite was aware of something wrong long ago. They buried the reports. They also have a history of not paying any bug bounties which of course discourages knowledgeable folks from reviewing their code. Their code maybe 'Open View' but they made no effort to respond to any possible issues reported by anyone They never paid any 3rd party security org to certify their code & hardware. The list goes on and on for the probable grounds of lawsuits.

- For bitcoin to succeed the community must police itself -    My info useful? Donations welcome!  3NtFuzyWREGoDHWeMczeJzxFZpiLAFJXYr
 -Sole remaining active Primary developer of cgminer, Kano's repo is here  Discord support invite at https://kano.is/
-Support Sidehacks miner development. Donations to:   1BURGERAXHH6Yi6LRybRJK7ybEm5m5HwTr
JayJuanGee
Legendary
*
Offline

Activity: 4522
Merit: 14831


Self-Custody is a right. Say no to "non-custodial"


View Profile
Today at 04:59:37 AM
Merited by vapourminer (1), Lucius (1), bitmover (1)
 #326

also if you have a trezor

you can add five passphrase wallets

With Trezor, you can add an unlimited number of passphrase wallets.

Trezor refers to the wallet that is generated from the seedphrase by itself as the standard wallet, and the wallet that is generated from the addition of the passphrase is referred to as a hidden wallet.

well if you have a trezor adding a 24 passphrase means
a lot of safety

Of course, I do not know the accuracy of the math (like you had shown in your earlier post), and surely your random 24 passphrase from 94 characters leads to quite a bit of difficulty, which may well be quite a bit more than enough... even 12 characters with randomness would be quite a lot of difficulty in breaking.

There are surely some folks who had used the passphrase with a lot less difficulty (randomness), and something like 12 characters, even if not random, would seem like a minimum preference level.

That's why they're now in trouble. They either weren't aware of what was happening (the first wave and the vulnerability) or ignored the possibility of a repeat theft.
Or they were aware, but could not get access to their wallets. The purpose of a cold storage is to not be accessible at any point and time. It's August, people are in vacations. It's entirely possible that they saw the news and were in a foreign country, far away from their homes, or wherever they keep their seed phrases.

I am a bit reluctant to create my own "watch only" wallets, yet for sure there are times in which I am in places in which I don't have access to my hardware, yet there could sometimes be abilities to access the seedwords even though the device might be in another location - and some of the ability to access could be coincidence depending on where a person is at and what kind of information he has at the tip of his fingers (or within reasonable reach).

The ColdCard situation showed the community that Bitcoin still has a very long journey before it actually reaches mass adoption.
But TODAY, we lost some users. We can't blame those people. You would probably have the same viewpoint if you lost your entire life-savings held in Bitcoin.
 Cry
Quote
8 years of stacking, gone. I think it's time to move on.
I believed in Bitcoin. Holding it gave me peace of mind because my country has faced several FATF sanctions. I was glad to find a kind of money that cannot be censored or debased because I just want to protect myself from the money printing and my country's weak and inflated currency comapred to the dollar.

I’m 39, and I was hoping to have a good financial cushion before 50. But today, my 2 BTC were drained.
Losing my Bitcoin has changed my mindset. It’s no longer about finishing the race first. At this point, I just want to finish it. But losing my BTC feels like I’m back at the starting line. I lost years of hard work and time.

I thought I was secure because Cold Card was always praised as one of the best and most secure wallets. It’s open source, so anyone can verify.
I’m done with Bitcoin. I’m not even sure if I still believe in it. I don’t know what the future holds for it anymore. I could have stayed with traditional investments and lived a normal life. Maybe I should have just moved everything into a Bitcoin ETF when they launched. But I don't know. It's too late to do it.

To everyone who has lost their BTC, I wish you the best and good health. I hope you find the strength to start again.
https://www.reddit.com/r/Bitcoin/comments/1vclm91/8_years_of_stacking_gone_i_think_its_time_to_move/

For sure people can end up feeling disgruntled based on a large loss (or large losses), and yeah, if we take the guy at his word that he lost everything related to his bitcoin stash, then that is a pretty BIG set back. I measure 8 years of stacking to have had been about $33.5k invested at about $80 per week, in order to get to that stack size in 8 years.

It seems to me that 39 years old is not too young to start again with the bitcoin stash, even if maybe the stacking rate might be less and even the ability to recover the coins that had already been lost is not possible, but there still could be a possibility to stack somewhere in the ballpark of $80 per week or even more - even though surely confidence may well could have had been shattered.. yet I have difficulties imagining other places to put value that is as good as bitcoin - even though for sure we know that the future of bitcoin and/or its price is not guaranteed, yet it seems if anyone already spent around 8 years stacking bitcoin at $80-ish per week, then from my perspective, a total loss at 39 years old, is still not automatically a reason to stop stacking...even though I can understand the current sentiment is negative.  

Surely.  Opinions are going to vary, and guys who are much older than 39 years old would love to be 39 years old again... so there still can be ways to attempt to figure out positive things in terms of learning that might not necessarily involve abandoning bitcoin.

My advice is have a few setups and add strong passphrases
This is basically mandatory now..
I have a second wallet without a passphrase. I will move the funds to a new wallet with passphrase during this week.

But I have many coins, many addresses, many derivation paths. It will take some time...

In your case, I imagine that you are talking about a wallet that is not a cold card.

I recall several years ago, I had a wallet that seemed to have allowed the creation of several accounts, so over the years, I had created more than 50 accounts, and half of them still had some coins on them.  

I recall that in a haste (or maybe out of expediency), I ended up combining accounts, which I later regretted.  At the time, I did not realize the implications of combining accounts and/or combining addresses

If we are not in a rush, then it may well be better to keep some (or even all) of the derivation paths separate.

If I were to be able to do that again, I would send each account to a separate address and if I had sub addresses within some of the accounts, each of those subaddresses would have gone to separate addresses too... so maybe I would have had ended up with more than 30 receiving addresses rather than the 1 or 2 that I ended up creating.

What's wrong with a laminated paper wallet rolled up in a sealed PVC pipe filled with rice and buried in backyard?

My first thought was:  cooked rice or raw?  hahahaha.. but that is a dumb joke since I understand the rice is meant to absorb  moisture, so it would be raw.

We know that the paper wallet does not solve your problem if it was created by a cold card wallet or if the random number generator was lacking in randomness.  

For the kind of attack against cold card wallets, burying it does not help, either.

1) Self-Custody is a right.  Resist being labelled as: "non-custodial" or "un-hosted."  2) ESG, KYC & AML are attack-vectors on Bitcoin to be avoided or minimized.  3) How much alt (shit)coin diversification is necessary? if you are into Bitcoin, then 0%......if you cannot control your gambling, then perhaps limit your alt(shit)coin exposure to less than 10% of your bitcoin size...Put BTC here: bc1q49wt0ddnj07wzzp6z7affw9ven7fztyhevqu9k
cygan
Legendary
*
Offline

Activity: 3962
Merit: 13018


icarus-cards.eu


View Profile WWW
Today at 05:55:06 AM
Merited by vapourminer (1)
 #327

the following new website lists 'honeypot' wallets on the mainnet that are vulnerable to this specific ColdCard exploit – some wallets are protected by additional dice rolls or a passphrase.
this site tracks which of these an attacker is draining and how quickly. this makes it possible to determine which coins are currently being seized...

https://cktripwire.com/


█████████████████████████
██████████████▀▄▄▄▀██████
████████▀▀▄▄████▄▄▀███
██████████████
████▀▄▄████████████
██▀██▀▀▀▀██
███▄▀▀███████
█▀███████████▄█
█▄▀▄██▀███▄████▄██
███▄█████▄▄▄████
█████▄████▄▄▄▀▀▄▄██████
███████▄▀▀▀▀▄▄▄██████████
█████████████████████████
.
 Jackpot ter .....  COMMUNITY POWERED CRYPTO CASINO  
▄███████████████████████▄
█████████████████████████
█████████████████████████
██████▄░▄▄▀██████▀▄██████
███████▄░█▄░███▀▄████████
█████████▄▀█░▀▄██████████
██████████▄▀█▄▀██████████
██████████▀▄░█▄▀█████████
████████▀▄███░██░▀███████
██████▀▄██████░▀▀░▀██████
█████████████████████████
█████████████████████████
▀███████████████████████▀
▄███████████████████████▄
█████████████████████████
█████████████████████████
███████████████▀▀░░▐█████
███████████▀▀░░░░░░██████
███████▀▀░░░▄▄▀░░░░██████
████▀░░░░░▄█▀░░░░░▐██████
██████▄▄██▀░░░░░░░▐██████
███████████▄░░░░░░███████
██████████████▄░░▄███████
█████████████████████████
█████████████████████████
▀███████████████████████▀
▄███████████████████████▄
█████████████████████████
█████████████████████████
██████▀░░░▀▀▀▀▀░░░▀██████
█████▀░░░░░░░░░░░░░▀█████
████▀░░░░░░░░░░░░░░░▀████
████░░░░▄█▄░░░▄█▄░░░░████
███▌░░░░▀█▀░░░▀█▀░░░░▐███
███▌░░░░▄░░░░░░░▄░░░░▐███
█████▄▄░▄█▄▄▄▄▄█▄░▄▄█████
█████████████████████████
█████████████████████████
▀███████████████████████▀
 
  PLAY NOW  
stompix
Legendary
*
Offline

Activity: 3696
Merit: 7276



View Profile WWW
Today at 06:27:59 AM
Merited by vapourminer (1)
 #328

What's wrong with a laminated paper wallet rolled up in a sealed PVC pipe filled with rice and buried in backyard?

It's okay if you don't have a dog that likes to dig, and you haven't dug deep enough - or if you have a neighbor who watches you just for fun and decides to dig around your yard when you're not home.

Flood, earthquakes, some company coming out of nowhere and digging in your yard for an emergency gas/electric line repair and many others.
Also, about the rice thing, just grab a pair of new sneakers and use the silica gel from them, rice that absorbs humidity will be a problem itself.

There is no perfect solution for anything, there is always a risk.

Hypothetical: it just occurred to me that even if Coldcard knew about this vulnerability, they couldn't have warned users about it. The moment they issue a warning, potential attackers would know about it too, and their warning would have been the catalyst to losing funds.
So once the bug was out there, all they could reasonably do was offer updated firmware and remove the vulnerability from newly sold devices.
They could have taken most of the coins though, and give it back to the soon-to-be-victims though. Regardless, however, I agree that either way their business would be completely over.

And nobody would have believed them when they said they were giving all the coins back to the owners, everyone would have said they are preying on people who can't prove they are the owners of those coins.
A cold wallet manufacturer taking your money without your knowledge would have been the end of any company.



▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|  BTC     XMR  
  DAI     LTC  
   Fees  0.8%    
JayJuanGee
Legendary
*
Offline

Activity: 4522
Merit: 14831


Self-Custody is a right. Say no to "non-custodial"


View Profile
Today at 06:31:21 AM
Merited by LoyceV (4), jahead (1)
 #329

[edited out]
Yeah kyc helps in this case.
Say I have kyc at kraken. And by  Buying 0.001 btc a week to be like jjg and dca

 deposit it every week to the cold card.

Since my name was dropped, I would like to clarify what I would do if I were DCA'ing anywhere between $40 to $100 worth of bitcoin every week on an exchange. 

Most likely I would let the value of BTC on the exchange get up to anywhere between $500 and $1k before I would transfer the amount to my hardware wallet.  I would not transfer relatively small UTXOs that are anywhere between $40 and $100, and I probably would not even transfer any below $500 since I would not want to have a bunch of small UTXOs to deal with, either in the present or in the future (even though we don't exactly know what is going to happen in the future in relation to bitcoin and/or transaction fees).

Plus you have the bank statements for the cash you added to kraken
And the actual cold card

 lastly the paper work for buying the cold card.
If you did this you can show all the withdrawals you made from kraken and the deposits to the cold card.
The ones to be fucked are all gray buys of coins.

If you have a bunch of UTXOs in one wallet, it is most likely that you would be able to show that all of those UTXOs are yours, as long as you were able to show one or more of them were yours.  There should not be any obligation to show from where all of the UTXOs came from as long as at least one of them (or maybe more than one) can be traced to your identity, such as the Kraken purchases, as you mentioned.  There might even be several sub accounts within a same wallet that has hundreds of bitcoin addresses (UTXOs), and it does not matter, since they are all controlled by the same wallet, so once you show that you are owner of the wallet, then all of the UTXOs o not need to be shown to be ones that you can (or even need to) identify, unless there is some state actor that is requiring such, and then you would have to get an attorney to sue the government for lack of due process (trying to take your property) and/or lack of a rational basis for requiring you to show anything beyond your ownership of the wallet.

1) Self-Custody is a right.  Resist being labelled as: "non-custodial" or "un-hosted."  2) ESG, KYC & AML are attack-vectors on Bitcoin to be avoided or minimized.  3) How much alt (shit)coin diversification is necessary? if you are into Bitcoin, then 0%......if you cannot control your gambling, then perhaps limit your alt(shit)coin exposure to less than 10% of your bitcoin size...Put BTC here: bc1q49wt0ddnj07wzzp6z7affw9ven7fztyhevqu9k
Wind_FURY
Legendary
*
Offline

Activity: 3724
Merit: 2211



View Profile
Today at 06:40:55 AM
 #330


The community in general is still "lucky" that the stupidity came from the ColdCard developers.


This is one of the reasons I'm always careful paranoid when a new wallet (be it hardware or software) is released. It took me years to trust Ledger (until they broke that trust), and now I only have Trezor left on my personal preferred list of hardware wallets.
The fact that this Coldcard flaw was around for 5 years makes it only harder to trust anything.


But for the truly paranoid, install Bitcoin Core/Electrum in a computer that will NEVER connect to the internet FOREVER, and generate your keys/seed phrase there. Write it down, then keep it in a safe place. The same for the computer, keep it locked in a vault.

Keep sending Bitcoin to that address.

NotATether
Legendary
*
Offline

Activity: 2422
Merit: 10087


┻┻ ︵㇏(°□°㇏)


View Profile WWW
Today at 06:44:16 AM
Merited by vapourminer (1), LoyceV (1)
 #331

What's wrong with a laminated paper wallet rolled up in a sealed PVC pipe filled with rice and buried in backyard?

That only works if you have a backyard.

I'd get in trouble if I drilled through the patio concrete for this purpose.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
decodx
Hero Member
*****
Offline

Activity: 1484
Merit: 963


#kycfree 🗽


View Profile
Today at 06:56:46 AM
 #332


The community in general is still "lucky" that the stupidity came from the ColdCard developers.


This is one of the reasons I'm always careful paranoid when a new wallet (be it hardware or software) is released. It took me years to trust Ledger (until they broke that trust), and now I only have Trezor left on my personal preferred list of hardware wallets.
The fact that this Coldcard flaw was around for 5 years makes it only harder to trust anything.


But for the truly paranoid, install Bitcoin Core/Electrum in a computer that will NEVER connect to the internet FOREVER, and generate your keys/seed phrase there. Write it down, then keep it in a safe place. The same for the computer, keep it locked in a vault.

Keep sending Bitcoin to that address.

To be honest, I don't think this is a good solution for the truly paranoid (or even for the mildly paranoid).   You've just switched from using hardware wallets over to Electrum as your preferred solution.

What if there was some vulnerability exposed within the Electrum development? It really wouldn't make that much difference to the final outcome.

▄███████████████████████▄
███████████████████████
████████████▀▀██████████
████████████████████████
██████████▄▄██████████
█████████████████████
███████████████████████
█████████████████████
██████████▀▀██████████
████████████████████████
██████████▄▄████████████
███████████████████████
▀███████████████████████▀
 
 MoBit 
████
██
██
██
██
██
██
██
██
██
██
██
████
 NO   LOGS
 
 LOW  FEES
 
 PGP  GUARANTEE
████
██
██
██
██
██
██
██
██
██
██
██
████
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
flatfly (OP)
Legendary
*
Offline

Activity: 1288
Merit: 1356

Joined: 2012


View Profile
Today at 07:46:43 AM
Last edit: Today at 08:14:16 AM by flatfly
Merited by shahzadafzal (1)
 #333

Maybe time to revisit this very simple Python script I made 13 years ago (with support for dice rolls!)  

https://bitcointalk.org/index.php?topic=308972.msg3512786#msg3512786

(Not saying this is a good solution - DYOR)

Did you know? Counterparty is still alive! It's the Bitcoin-native DEX with a fascinating history, running with zero downtime since 2014.
Danish Ali
Newbie
*
Offline

Activity: 5
Merit: 1


View Profile
Today at 08:17:57 AM
Merited by vapourminer (1)
 #334

I can only recommend storing coins safely at MtGox, BTC-e or FTX at this time
you jest but at least mtgox people got ~20% of their btc/bcash back
Getting 20% back after a decade of waiting, truly the gold standard of customer service.
hedgeh0g
Hero Member
*****
Offline

Activity: 1540
Merit: 942



View Profile
Today at 08:24:31 AM
 #335

The community in general is still "lucky" that the stupidity came from the ColdCard developers.
This is one of the reasons I'm always careful paranoid when a new wallet (be it hardware or software) is released. It took me years to trust Ledger (until they broke that trust), and now I only have Trezor left on my personal preferred list of hardware wallets.
The fact that this Coldcard flaw was around for 5 years makes it only harder to trust anything.

Unfortunately, there is a misconception in our psychology that if something has worked for a long time before us, then we consider it proven, although it may not be so. Every new incoming user thinks, "if everyone is using it so calmly, then someone has checked everything for sure." But it turns out that the system has not been properly tested in five years. And in the age of AI, we will hear more than once about the secrets of systems that were in plain sight, but only the latest AI model will be able to find it.

 
█▄
R


▀▀██████▄▄
████████████████
▀█████▀▀▀█████
████████▌███▐████
▄█████▄▄▄█████
████████████████
▄▄██████▀▀
LLBIT▀█ 
  TH#1 SOLANA CASINO  
████████████▄
▀▀██████▀▀███
██▄▄▀▀▄▄████
████████████
██████████
███▀████████
▄▄█████████
████████████
████████████
████████████
████████████
█████████████
████████████▀
████████████▄
▀▀▀▀▀▀▀██████
████████████
███████████
██▄█████████
████▄███████
████████████
█░▀▀████████
▀▀██████████
█████▄█████
████▀▄▀████
▄▄▄▄▄▄▄██████
████████████▀
........5,000+........
GAMES
 
......INSTANT......
WITHDRAWALS
..........HUGE..........
REWARDS
 
............VIP............
PROGRAM
 .
   PLAY NOW    
LoyceV
Legendary
*
Offline

Activity: 4116
Merit: 22417


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
Today at 09:05:29 AM
Last edit: Today at 10:53:30 AM by LoyceV
Merited by vapourminer (1)
 #336

But for the truly paranoid, install Bitcoin Core/Electrum in a computer that will NEVER connect to the internet FOREVER, and generate your keys/seed phrase there. Write it down, then keep it in a safe place. The same for the computer, keep it locked in a vault.
Keep sending Bitcoin to that address.
First, using only one address is terrible for privacy, but also requires exposing all funds if you want to send a transaciton in the future.
But worse, this setup is not easy. I can only encourage everyone to try and get familiar with it, but doing it correctly will be a challenge even for many people who consider themselves experienced Bitcoin users.
You mentioned writing down keys. That's prone to making mistakes, and with descriptor wallets it's even harder to do. If you use Electrum, you're going to have to update your offline version at some point. I've seen old (offline) versions that couldn't sign a transaction created with a newer (online) version of Electrum. It's time-consuming to do correct, and one small mistake is enough to undo all your efforts to keep your keys offline.



The generation of random numbers is too important to be left to chance.
— Robert R. Coveyou, 1970

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
Dave1
Hero Member
*****
Offline

Activity: 2114
Merit: 642



View Profile
Today at 09:31:41 AM
Merited by vapourminer (1)
 #337

Let the games begin,



https://x.com/CertiKAlert/status/2084920866526114183

As one of the biggest blockchain security firm has seen some movement already. So it's going to be a cat and mouse game moving forward and trail where it will go.


███████▄▄███▄███▄
███▄▄████████▌██
▄█████████████▐██▌
██▄███████████▌█▌
███████▀██████▐▌█
██████████████▌▌▐
████████▄███████▐▐
█████████████████
███████████████▄██▄
██████████████▀▀▀
█████▀███▀▀▀

▄▄▄██████▄▄▄███████▄▄▄
███████████████████████████
███▌█████▀███▌█████▀▀███████████▄▄▄▄▄▄▄▄
███▌█████▄███▌█████▄███▐███████████████████▄
▐████████████▀███████▄██████████▀▀▀▀▀▀▀▀████▀
▐████████████▄██▄███████████▌█████████▄████▀
▐█████████▀█████████▌█████████████▄▄████▀
██████████▄███████████▐███▌██▄██████▀
██████████████▀███▐███▌██████████████████████
████▀██████▀▀█████████▌███▀▀▀▀███▀▀▀▀▀▀▀████▌
 
      P R E M I E R   B I T C O I N   C A S I N O   &   S P O R T S B O O K      

█▀▀









▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

  98%  
RTP

 
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█









▀▀▀

█▀▀









▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

 HIGH 
ODDS

 
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█









▀▀▀
 
..PLAY NOW..
examplens
Legendary
*
Offline

Activity: 4088
Merit: 4872



View Profile WWW
Today at 10:49:36 AM
Merited by bitmover (5), vapourminer (1)
 #338

Let the games begin,
Here are the first Bitcoin transfers from the address bc1q0rvn88w08j75k4h48lf9fvhan7unjp7vjf5q6m, 64 BTC was sent. According to the further flow of transactions, it seems that it is a matter of mixing through the coinjoin method

https://mempool.space/tx/e3274a1b87096938d014e1edaa01b06c3dd16e72a48f66ead95c79f83f2b3ddf
https://mempool.space/tx/f3ee6e61129b90b4746275a2ea17b08ac53769556d61994c94f03db9bcc37b24
https://mempool.space/tx/3bdac8ed822fc4cb123bc78689da3179ea8321d6daa5034c2170100399cdf935
https://mempool.space/tx/80f11c778a2f486ffc55b4e8665a94971ae9c350ac53969e9efcbf90478cbf90

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
tvbcof
Legendary
*
Online Online

Activity: 5278
Merit: 1316


View Profile
Today at 12:32:46 PM
Merited by vapourminer (1)
 #339

I have seen some creepy tweets of old posts from Coldcard but I don't think this company is worth defending.



https://x.com/coldcardwallet/status/1447213375398846473

I don't think I'm overreacting right!

wtf, it seems a retirement attack? Huh
is it when a developer intentionally inserts a bug into the entropy generation process so that it can later be used to steal user's wallet?

Ironically, that old tweet almost exactly describes the type of vulnerability that now appeared in ColdCard's firmware, so sad.
It seems they know everything, and made us fools.

Remember the 'hack' associated with the ridiculously simple on-line wallet which used only URL's?  What was the name...ah; Instawallet.

The hack was to sell it off to a couple of French guys of questionable repute.  They shut it down, but in fact did refund BTC to anyone who asked nice.  The 'hack' was that a lot of people had forgotten about Bitcoin generally.  To someone with only a few BTC (~$30) it simply wasn't worth the hassle to bother with.

Did the perps actually steal value from anyone?  It's questionable.  Was it a crime?  Debatable, but actually probably not.  Did they do well financially?  I wouldn't be surprised if they mainly travel in a Gulfstream these days.  They basically picked up what other people had dropped.

---

As I understand, the RNG used by Coinkite gained entropy from the device state.  It's a relatively simple device running at low clockrates.  Still, enough of a challenge to add some need for work (time).  If one designed and built the hardware, however, they could arrange to be more efficient at 'mining' for the right device states than their competition (e.g., common opertunists/criminals.)  They might actually have the private key to any BTC backed by their hardware almost in real time.

On my flight back to save some of my BTC I figured that what would probably form would be something like 'mining pools' looking for Coinkite BTC where the organizers keep track of productive device state data and thus optimize efforts for it.  Also, methods for identifying 'Coinkite-backed' BTC addresses in the blockchain would develop.  e.g., coins associated with other known Coinkite-backed ones would be more likely as users transfer funds around.

If Coinkite gave themselves an advantage among a population of criminals, they could pretty much sit on their hands and let the thief population stir up a lot of dust, then periodically pick up a juicy pay-off batch as needed.  Nice retirement.

Some tribes have a general understanding that it is ethically OK for their tribe to 'pick up what other people have dropped'.  I'm no Talmudic scholar, but I do wonder what the consensus is about how much helping people drop something in the first place is acceptable?


sig spam anywhere and self-moderated threads on the pol&soc board are for losers.
asUHWEceyc
Full Member
***
Offline

Activity: 168
Merit: 194

dekleptocraticizationismist


View Profile WWW
Today at 01:17:31 PM
 #340

I can only recommend storing coins safely at MtGox, BTC-e or FTX at this time


you jest but at least mtgox people got ~20% of their btc/bcash back


Yeah let's say Quadriga instead...for pants pooping consistency's sake
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 [17] 18 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!