Bitcoin Forum
August 06, 2026, 12:55:50 PM *
News: COLDCARD users only: critical vulnerability risks funds stored on COLDCARD devices; immediate action required
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 [18] 19 »  All
  Print  
Author Topic: Large-scale Coldcard compromise (1485.77 BTC stolen so far)  (Read 5933 times)
bitmover
Legendary
*
Offline

Activity: 3122
Merit: 7654


Trêvoid █ No KYC-AML Crypto Swaps


View Profile WWW
August 05, 2026, 02:08:22 PM
Merited by JayJuanGee (1)
 #341

My advice is have a few setups and add strong passphrases
This is basically mandatory now..
I have a second wallet without a passphrase. I will move the funds to a new wallet with passphrase during this week.

But I have many coins, many addresses, many derivation paths. It will take some time...

In your case, I imagine that you are talking about a wallet that is not a cold card.

I recall several years ago, I had a wallet that seemed to have allowed the creation of several accounts, so over the years, I had created more than 50 accounts, and half of them still had some coins on them. 

I recall that in a haste (or maybe out of expediency), I ended up combining accounts, which I later regretted.  At the time, I did not realize the implications of combining accounts and/or combining addresses

If we are not in a rush, then it may well be better to keep some (or even all) of the derivation paths separate.

If I were to be able to do that again, I would send each account to a separate address and if I had sub addresses within some of the accounts, each of those subaddresses would have gone to separate addresses too... so maybe I would have had ended up with more than 30 receiving addresses rather than the 1 or 2 that I ended up creating.

Actually, it is a hardware wallet with 2 wallets inside (one with a passphrase and 1 without).

Each of them has about 40-50 addresses distributed along 2-3 derivation paths... I have more than 60 addresses with balance and used more than 100 (including the ones without balance)

And I still have ethereum and some tokens such as PAXG/XAUT. It will take some time to move all those coins which are in the wallet without a passphrase. But I think this is very important. I already set up a new hardware wallet and added a passphrase. I will move the funds soon.

You are right about being careful with consolidations. I will try not to spend too many addresses together, for privacy reasons

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|  BTC     XMR  
  DAI     LTC  
   Fees  0.8%    
Catenaccio
Sr. Member
****
Offline

Activity: 1218
Merit: 359



View Profile
August 05, 2026, 02:32:43 PM
Merited by vapourminer (1)
 #342

My advice is have a few setups and add strong passphrases
I know the importance of wallet passphrase but honestly I don't know what are strong passphrases, could you help me with information about that or any resources for learning about that?

It's easy to find resources to learn about passwords, how to create a strong password, but with passphrases I see very limited resources to learn and apply for my practice.

Like how many words are considered as strong enough for a wallet passphrase?
No recommendation about that in Mastering Bitcoin book.
https://github.com/bitcoinbook/bitcoinbook/blob/develop/ch05_wallets.adoc#optional-passphrase-in-bip39

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT|
4,000+ GAMES
███████████████████
██████████▀▄▀▀▀████
████████▀▄▀██░░░███
██████▀▄███▄▀█▄▄▄██
███▀▀▀▀▀▀█▀▀▀▀▀▀███
██░░░░░░░░█░░░░░░██
██▄░░░░░░░█░░░░░▄██
███▄░░░░▄█▄▄▄▄▄████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
█████████
▀████████
░░▀██████
░░░░▀████
░░░░░░███
▄░░░░░███
▀█▄▄▄████
░░▀▀█████
▀▀▀▀▀▀▀▀▀
█████████
░░░▀▀████
██▄▄▀░███
█░░█▄░░██
░████▀▀██
█░░█▀░░██
██▀▀▄░███
░░░▄▄████
▀▀▀▀▀▀▀▀▀
|||
▄▄████▄▄
▀█▀
▄▀▀▄▀█▀
▄░░▄█░██░█▄░░▄
█░▄█░▀█▄▄█▀░█▄░█
▀▄░███▄▄▄▄███░▄▀
▀▀█░░░▄▄▄▄░░░█▀▀
░░██████░░█
█░░░░▀▀░░░░█
▀▄▀▄▀▄▀▄▀▄
▄░█████▀▀█████░▄
▄███████░██░███████▄
▀▀██████▄▄██████▀▀
▀▀████████▀▀
.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
░▀▄░▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄░▄▀
███▀▄▀█████████████████▀▄▀
█████▀▄░▄▄▄▄▄███░▄▄▄▄▄▄▀
███████▀▄▀██████░█▄▄▄▄▄▄▄▄
█████████▀▄▄░███▄▄▄▄▄▄░▄▀
███████████░███████▀▄▀
███████████░██▀▄▄▄▄▀
███████████░▀▄▀
████████████▄▀
███████████
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▀▄███░░░▀████░███▄▀██▄
███░████░░░░░▀██░████░███
███░████░█▄░░░░▀░████░███
███░████░███▄░░░░████░███
▀██▄▀███░█████▄░░███▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
OFFICIAL PARTNERSHIP
SOUTHAMPTON FC
FAZE CLAN
SSC NAPOLI
Comeacross
Full Member
***
Offline

Activity: 230
Merit: 112


View Profile
August 05, 2026, 02:40:48 PM
 #343

Be aware of fake Telegram groups, where they "help" with "wallet migration".

Scam telegram groups:

Code:
https://t.me/coldcardREAL
https://t.me/coldcardMigration

These groups are swaming with scammers that want victims to use their malicious links:
Code:
https://swiftprotocolresolvers.web.app/
http://migrate.coldcardfirmware.com
https://m-coldcard.web.app
https://dashboards.protocolsdata.workers.dev
https://coldcard-en.web.app
https://coldcard-devicenode.net/en/
https://coldcard-audit.com
https://dapplogin-connect.com
https://t.me/AiCustomerSupport247_bot
https://onchains-hub.vercel.app

Do not enter seed words there! Do not send funds there! Do not download any software from there!

Edit. Added new scams


If any of the victim fall for this again, they probably should not have any business with Bitcoin.

Scammers have no conscience indeed. If you can not sympathise with the victims, you should not attempt to steal more from them. Taking advantage of the hack to scam again is too devilish.

These people don't deserve this. Their only mistake was using the device that aim to protect them now they are being punished for silly mistakes by devs.
jayhex
Newbie
*
Offline

Activity: 3
Merit: 0


View Profile
August 05, 2026, 03:36:14 PM
 #344



you jest but at least mtgox people got ~20% of their btc/bcash back


[/quote]

Yep and a long solid hodl so good they made nice money in fiat terms.
[/quote]
incorrect
i think just like FTX they got 20% of the price at the time of theft. so no hodl, just 20% of what u lost at that time 5-6 or more years ago
FP91G
Legendary
*
Offline

Activity: 2450
Merit: 1667


#kycfree 🗽


View Profile
August 05, 2026, 03:51:06 PM
Merited by vapourminer (1), JayJuanGee (1)
 #345

MARA opens Slipstream to public as a free, permissionless Bitcoin transaction tool
link
MARA Holdings has made its Slipstream transaction service free and open to the public, letting any Bitcoin user submit transactions directly through the company’s mining pool without touching the public mempool. The move turns a formerly restricted infrastructure tool into something any Bitcoin holder can use from a browser.

The service is live at slipstream.mara.com, requires no client software, and carries no additional fees beyond standard Bitcoin network transaction costs.


Quote
For users using multi-signature configurations—common among Coldcard holders who share control of their funds across multiple devices—the slipstream process itself is fraught with risk. Publicly broadcasting a transaction reveals wallet keys and the spending details. An attacker with a corresponding vulnerable private key could detect this transaction, create a competing transaction with a higher fee, and exploit the Bitcoin network's "Replace-by-Fee" (RBF) feature to bypass the queue and steal funds before the original transaction is confirmed.

MARA's Slipstream feature eliminates this window of vulnerability. Because the transaction never reaches the public mempool, the attacker sees neither the keys nor the spending details until MARA mines the coins in a confirmed block.

▄███████████████████████▄
███████████████████████
████████████▀▀██████████
████████████████████████
██████████▄▄██████████
█████████████████████
███████████████████████
█████████████████████
██████████▀▀██████████
████████████████████████
██████████▄▄████████████
███████████████████████
▀███████████████████████▀
 
 MoBit 
████
██
██
██
██
██
██
██
██
██
██
██
████
 NO   LOGS
 
 LOW  FEES
 
 PGP  GUARANTEE
████
██
██
██
██
██
██
██
██
██
██
██
████
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
hosemary
Legendary
*
Offline

Activity: 3220
Merit: 7155



View Profile
August 05, 2026, 03:55:15 PM
Last edit: August 05, 2026, 04:11:41 PM by hosemary
Merited by JayJuanGee (1)
 #346

It's easy to find resources to learn about passwords, how to create a strong password, but with passphrases I see very limited resources to learn and apply for my practice.
When it comes to the amount of entropy and the probability of being cracked, I don't see any difference between a passphrase and a password.
It's simple. The more random characters you add to your passphrase, the higher entropy it provides.

Assuming all the characters you used in your passphrase are completely random and have been drawn from the full set of printable ASCII characters, there are 95 possibilities for each character.
For example, if your passphrase contains 10 random printable ASCII characters, there are 9510 possible combinations, which provide around 65.7 bits of entropy.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits..REWARDING, BEYOND LIMITS...
█████████████████████████
█████████████████████████
███████████▀▀░░▀█▄░░▀████
████████▀░░░░░░░░▀█▄░████
███████░░░░▄▄░░▄░░░▀█████
██████░░░░░▀▀▄██▀░░░░████
█████░░░██░▄██▀▄▄░░░█████
████░░░░░▄██▀░░▀▀░░██████
█████▄░░▀█▀░██░░░░███████
████░▀█▄░░░░░░░░▄████████
████▄░░▀█▄░░▄▄███████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████▀░░▀░███████████
████████░░░▄░█░██████████
███████████▌▐██░█████████
███████████░███▌▐████████
██████████░█████░████████
██████▀░▄░▀███▀░▄░▀█████
█████░▄▀░░░░█░▄▀░░░░█████
█████░░░░░░░█░░░░░░░█████
██████▄░░░▄███▄░░░▄██████
█████████████████████████
█████████████████████████


























  PLAY NOW  
Cookdata
Legendary
*
Offline

Activity: 1764
Merit: 1433


Not Your Keys, Not Your Bitcoin


View Profile
August 05, 2026, 04:10:09 PM
Merited by JayJuanGee (1)
 #347

My advice is have a few setups and add strong passphrases
I know the importance of wallet passphrase but honestly I don't know what are strong passphrases, could you help me with information about that or any resources for learning about that?

If a scammer get access to your seed phrase and scan the wallet and see nothing on the wallet, they are not going to walk away immediately, they will try to guess right some common possible words which they know you might use as extension of your seed phrase. They are going to test words like your name, your child name or common strings you use for password, all of these are weak passphrase that scammer can guess right especially if the person knows much about you in detail. You should learn to use words that are uncommon that you can remember any time.

Quote
It's easy to find resources to learn about passwords, how to create a strong password, but with passphrases I see very limited resources to learn and apply for my practice.

I think that's because seed phrase that is generated with a secured entropy is safe for your Bitcoin that's why emphasis are not given to passphrase and some recommendations but it's something you can do. If not for Coldcard negligence, most people don't use passphrase unless they want to use it. Look at numbers of wallet that were swept, it shows most didn't use passphrase else the attacker wouldn't be able to access them.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits..REWARDING, BEYOND LIMITS...
█████████████████████████
█████████████████████████
███████████▀▀░░▀█▄░░▀████
████████▀░░░░░░░░▀█▄░████
███████░░░░▄▄░░▄░░░▀█████
██████░░░░░▀▀▄██▀░░░░████
█████░░░██░▄██▀▄▄░░░█████
████░░░░░▄██▀░░▀▀░░██████
█████▄░░▀█▀░██░░░░███████
████░▀█▄░░░░░░░░▄████████
████▄░░▀█▄░░▄▄███████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████▀░░▀░███████████
████████░░░▄░█░██████████
███████████▌▐██░█████████
███████████░███▌▐████████
██████████░█████░████████
██████▀░▄░▀███▀░▄░▀█████
█████░▄▀░░░░█░▄▀░░░░█████
█████░░░░░░░█░░░░░░░█████
██████▄░░░▄███▄░░░▄██████
█████████████████████████
█████████████████████████


























  PLAY NOW  
[/center
Princess Leah
Sr. Member
****
Offline

Activity: 910
Merit: 323


Recognized among the best crypto casino options.


View Profile
August 05, 2026, 04:53:08 PM
Merited by JayJuanGee (1)
 #348

I know the importance of wallet passphrase but honestly I don't know what are strong passphrases, could you help me with information about that or any resources for learning about that?

If a scammer get access to your seed phrase and scan the wallet and see nothing on the wallet, they are not going to walk away immediately, they will try to guess right some common possible words which they know you might use as extension of your seed phrase. They are going to test words like your name, your child name or common strings you use for password, all of these are weak passphrase that scammer can guess right especially if the person knows much about you in detail. You should learn to use words that are uncommon that you can remember any time.

Quote
It's easy to find resources to learn about passwords, how to create a strong password, but with passphrases I see very limited resources to learn and apply for my practice.

I think that's because seed phrase that is generated with a secured entropy is safe for your Bitcoin that's why emphasis are not given to passphrase and some recommendations but it's something you can do. If not for Coldcard negligence, most people don't use passphrase unless they want to use it. Look at numbers of wallet that were swept, it shows most didn't use passphrase else the attacker wouldn't be able to access them.

A combination of aphabets, numbers and symbols is more better  for instance a common name like Grace or Paul Smith can be guessed correctly but a combination of a nickname number and symbols would be so tough to guess and it should be from 12 to 32 characters something like PsmithY@&80566@.

 Noticed how the characters contains upper and lowercase alphabets, that's to add extra strength to it and make it tough to decoded. People would begin to see the importance of adding extra security to their wallets by including a passphrase, those who did that to their wallets and also used multi sig wallets would be secured from hack.

philipma1957
Legendary
*
Online Online

Activity: 4942
Merit: 12324


'The right to privacy matters'


View Profile WWW
August 05, 2026, 06:05:01 PM
Merited by joker_josue (2), JayJuanGee (1)
 #349

My advice is have a few setups and add strong passphrases
I know the importance of wallet passphrase but honestly I don't know what are strong passphrases, could you help me with information about that or any resources for learning about that?

It's easy to find resources to learn about passwords, how to create a strong password, but with passphrases I see very limited resources to learn and apply for my practice.

Like how many words are considered as strong enough for a wallet passphrase?
No recommendation about that in Mastering Bitcoin book.
https://github.com/bitcoinbook/bitcoinbook/blob/develop/ch05_wallets.adoc#optional-passphrase-in-bip39

I can talk to you about trezor as that is what I use.

you can use up to 50 character length but don't lost it or you lose your funds.

easy ways to make a good one.

https://www.amazon.com/Abrrow-Scrabble-Symbols-Great-Pendants-Scrapbooking/dp/B077SDLMLL/ref=sr_1_36?

above has
0
1
2
3
4
5
6
7
8
9
-
+
 /
 =                       that is 14 different characters


put them in a bag all 14 shake pick 1 out write it on paper put it back
shake bag  pick 1 out write it on paper put it back do this at least 16 times


so 1/14 for each pick

a single pick is 14 combos = shit
2 picks is 14x14=196 combos =shit
3 picks is 14x14x14=2,744  = shit
4 pick is   14x14x14x14=38,416 =shit
5 picks is 14x14x14x14x14=537,824 =shit
6 picks is  14x14x14x14x14x14=7,529,536 =shit
7 picks is  14x14x14x14x14x14x14=105,413,504 = meh yeah 105mill is meh
8 picks is 14x14x14x14x14x14x14x14=1,475,789,056 = meh  yep 1.4bill is meh
9 picks is  14x14x14x14x14x14x14x14x14= 20,661,046,784 = meh yep 20.6 billion is also meh
10 picks is  289,254,654,,976              still meh yep 289 bill = so so
11 picks is 4,049,565,169,664            this may give you enough time to move the coins out as you would not be the first wave of victims
12 picks is 56,693,912,375,296          same here you would likely be a bit longer that the first wave.
13 picks is             793,714,773,254,144         I still would want more then a 793 trillion set of protection
14 picks is        11,112,006,825,558,016
15 picks is   2,177,953,337,809,371,136
16 picks is 30,491,346,729,331,195,904      this is 30 million times 1 trillion the weak hacked set on cold card was 1.1 trillion

so this would be 30 million times harder to hit than the hack and you also have a seed in front of of it.


▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|..BTC......XMR...
..USDT.....LTC...
....Fees  0.8%.....
Meuserna
Sr. Member
****
Offline

Activity: 339
Merit: 558


View Profile WWW
August 05, 2026, 06:17:30 PM
Merited by JayJuanGee (1)
 #350

My advice is have a few setups and add strong passphrases
I know the importance of wallet passphrase but honestly I don't know what are strong passphrases, could you help me with information about that or any resources for learning about that?

It's easy to find resources to learn about passwords, how to create a strong password, but with passphrases I see very limited resources to learn and apply for my practice.

Like how many words are considered as strong enough for a wallet passphrase?
No recommendation about that in Mastering Bitcoin book.
https://github.com/bitcoinbook/bitcoinbook/blob/develop/ch05_wallets.adoc#optional-passphrase-in-bip39

Picking a Good BIP39 Passphrase or avoiding a bad one.

A guide by the ultimate white-hat Bitcoiner, Crypto-Guide:

https://www.youtube.com/watch?v=nhjq_1J0EbU&t=583s

His youtube channel is one of the best. No fluff, no hype. Just serious security, well explained.

suzanne5223
Hero Member
*****
Online Online

Activity: 3388
Merit: 751


Want top-notch marketing for your brand, Hire me


View Profile WWW
August 05, 2026, 06:28:12 PM
Merited by JayJuanGee (1)
 #351

This certainly appears to be an exit scam with good plausible deniability when you look back at JWWeatherman_ badgering coldcard to add external entropy via dice rolls to their quick start guide in the 2020-2021 period, which they refused to do.

It also casts a shadow on their podcast promoters, who were most likely mere useful idiots.

The company is obviously done, through reputational damage and/or lawsuits, but someone has the coins

lets say inside job.

the issue is any other wallet company can do the same.

firmware 2027 for ledger makes a bug
and in 2028 ledger hacked.

right down the road.

so  back to core only?

since if core is bad it is all dead.
The Coldcard hacking incident is actually challenging the entire Bitcoin ecosystem
No, it actually challenges the hardware wallet ecosystem.

no one can say exactly what will happen in the future, but self-custody, which was people's last resort to keep their digital assets Bitcoin safe, is now distrusted.
This is exactly why it is a challenge for the hardware sector to focus more on their product security and have more concern about every security flaw that's raised.


I can only recommend storing coins safely at MtGox, BTC-e or FTX at this time
you jest but at least mtgox people got ~20% of their btc/bcash back
Not everyone, though, because the final repayment deadline for Mt. Gox was postponed to October 31, 2026

What's wrong with a laminated paper wallet rolled up in a sealed PVC pipe filled with rice and buried in backyard?

It's okay if you don't have a dog that likes to dig, and you haven't dug deep enough - or if you have a neighbor who watches you just for fun and decides to dig around your yard when you're not home. In addition, in some countries there are laws that say that the owner of the land is the owner of what is found up to a certain depth, and everything else is owned by the state. This is how they protect oil and gas deposits from ordinary people.

The ground settles over time, so if you bury something to a depth of, say, half a meter, it will slowly sink over time, especially if the soil is moist and there is a lot of rainfall.
I believe the major problem will be the neighbor who likes to watch for fun.
According to my research, the country with the lowest owner legal depth is 32 feet / 10 meters, which is Japan, while the max depth a dog can dig is roughly 3-7 feet.
Any depth thats dip to 15 feet deep is far below every active topsoil layer where earthworms and roots can cause slowly sink unless the object buried is something immensely heavy.

▄▄███████████████████▄▄
▄███████████████████████▄
███████████████████████
████████▀▀▀▀██▀█▄▀███████
███▀▀██▄▄██▄██▌▄▄▄▄▄██
████▄█████▐██▀▄█▀▀█████
█████▌██▀▀▄█▀██▄██▄███
██▄▄▄▄███████████▐███████
████████▐█████████▀▀█████
███████▄██████▀█▄▄▄▄▄████
███████████████████████

▀███████████████████████▀
▀▀███████████████████▀▀

 Kings Game  
 
 🎰   🎲   ⚽ 
████
██
██
██
██
██
██
██
██
██
██
██
████
████████████████████████████


RAKEBACK
..UP TO 30%..
████████████████████████████
████
██
██
██
██
██
██
██
██
██
██
██
████
████
██
██
██
██
██
██
██
██
██
██
██
████
████████████████████████████
 
..500%..
WELCOME BONUS
+ 250 FREE SPINS
████████████████████████████
████
██
██
██
██
██
██
██
██
██
██
██
████

   WIN NOW     
pawel7777
Legendary
*
Offline

Activity: 3262
Merit: 1832


Ora et labora


View Profile WWW
August 05, 2026, 07:54:42 PM
 #352

Due to holiday, I'm a bit behind with all recent news including the coldcard vulnerability thing. But if I understand this correctly:
- nobody "hacked" anything per se
- the "hacker(s)" didn't have any contact with coldcard hardware
- it's all a result of open source code flaw that nobody noticed for like 5 years.

I read on social media that this type of flaw was almost impossible to notice for an untrained eye, so unless you're an expert, any self-inspection of the code would unlikely work.

I guess there's a sad lesson to be learned here. Even an open source software that has been around for years cannot be trusted blindly.

▄▄████████████████████▄▄
████████████████████████
██████████████████████████
██████████████████████████
███▄▄▀▀▀▀▀▀▀▀▀▀▄▄██
██████████▐████▐██████
███▀██████▀▀████▀▀███████
██████████████████████
████▄▄██▄▄▄▄███▄▄▄███████
██████▀▀▀▀▀▀▀▀▀▀▀▀██████
██████████████████████████

████████████████████████
▀▀████████████████████▀▀

.1win.com.
█████████████████████████
█████████████████████████
████████████▀░░░▀▀▀▀█████
█████████▀▀▀█▄░░░░░░░████
████▀▀░░░░░░░█▄░▄░░░▐████
████▌░░░░▄░░░▐████░░▐███
█████░░░▄██▄░░██▀░░░█████
█████▌░░▀██▀░░▐▌░░░▐█████
██████░░░░▀░░░░█░░░▐█████
██████▌░░░░░░░░▐█▄▄██████
███████▄░░▄▄▄████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████▀▀▀███████████
███████▀▀░░▄▄▄░░▀▀███████
██████▄░░░░███░░░░▄██████
█████░▀▀█▄▄░░░▄▄█▀▀░█████
█████░██░░▀▀█▀▀░░██░█████
█████░░░░░░░█░██░▄▄░█████
█████▄░░░▄▄░█░▄▄░▀▀▄█████
███████▄▄▀▀░█░▀▀▄▄██████
███████████▄█▄███████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
████████▀▀░░░░░▀▀████████
██████░░▄██▄░▄██▄░░██████
█████░░████▀░▀████░░█████
████░░░░▀▀░░░░░▀▀░░░░████
████░░▄██░░░░░░░██▄░░████
████░░████░░░░░████░░████
█████░░▀▀░▄███▄░▀▀░░████
██████░░░░▀███▀░░░░██████
████████▄▄░░░░░▄▄████████
█████████████████████████
█████████████████████████
NotATether
Legendary
*
Offline

Activity: 2422
Merit: 10095


┻┻ ︵㇏(°□°㇏)


View Profile WWW
August 05, 2026, 08:05:22 PM
 #353


How would this work exactly? the KYC information are going to be cross checked against what exactly?

A signed message is not going to work either. Someone who can access your funds, would also have the ability to sign a message...

I understand the intention may be good but with no clear and straightforward way to know the rightful owners of those funds, whoever is going to do this will probably end up in legal trouble, or am I missing something here?

It seems they don't care, their only idea it seems is to involve law enforcement and inshallah

https://x.com/i/status/2084949932289765633

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
Ambatman
Legendary
*
Offline

Activity: 1092
Merit: 1392


Don't tell anyone


View Profile WWW
August 05, 2026, 08:32:57 PM
 #354


I guess there's a sad lesson to be learned here. Even an open source software that has been around for years cannot be trusted blindly.
It wasn't necessarily an open source but a verifiable source code.
And yeah open source doesn't mean it's bug free
Even bugs were noticed in bitcoin years ago.
And this would set a precedence for more to come.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits PREDICT..
█████████████████████████
█████████████████████████
███████████▀▀░░░░▀▀██████
██████████░░▄████▄░░████
█████████░░████████░░████
█████████░░████████░░████
█████████▄▀██████▀▄████
████████▀▀░░░▀▀▀▀░░▄█████
██████▀░░░░██▄▄▄▄████████
████▀░░░░▄███████████████
█████▄▄█████████████████
█████████████████████████
█████████████████████████
.
.WHERE EVERYTHING IS A MARKET..
█████
██
██







██
██
██████
Will Bitcoin hit $200,000
before January 1st 2027?

    No @1.15         Yes @6.00    
█████
██
██







██
██
██████

  CHECK MORE > 
cAPSLOCK
Legendary
*
Offline

Activity: 4466
Merit: 8046


Rock is DEAD


View Profile
August 05, 2026, 11:28:36 PM
 #355

This situation also demonstrates the need to have a second hadeware wallet, a different model (or, better yet, from a different manufacturer).

I'm wondering if this situation demonstrates the need for more than what you've suggested--what that is I don't know, but I've been seeing a lot of vulnerabilities exploited/pointed out by hackers using AI, which includes HW wallets, altcoin blockchains (if I'm not mistaken), and other miscellaneous things that were once thought to be safe but turned out weren't.

I've always liked the concept of DIY HW wallets but haven't ever given one a shot.  Has there been any code written to make any for BTC?  Would one of those not potentially be safer overall?

Shit's scary out there right now.

Look into the Seedsigner.  I am a fan.
kTimesG
Sr. Member
****
Offline

Activity: 924
Merit: 263


View Profile
Today at 01:49:26 AM
 #356

the following new website lists 'honeypot' wallets on the mainnet that are vulnerable to this specific ColdCard exploit – some wallets are protected by additional dice rolls or a passphrase.
this site tracks which of these an attacker is draining and how quickly. this makes it possible to determine which coins are currently being seized...

https://cktripwire.com/

The attack estimated time is around 352 times less than what is stipulated on that website. It's just that the "trivial" address is generated very naively as it's using impossible conditions for actually ever be created on a compromised device (unless one uses telepathy to force some hardware to start executing code, instead of using physics). I would only expect the rest of the honeypots to have the same problem (besides basically missing from the 5 years worth of historical blockchain indexed data - so probably skipped during lookup), which means that the entire process says nothing about how actual real hacked seeds were computed.

215c78739714754ba7a21269416165b194f5b5136bcd4766d58a7bb2ce8500d8 (a very naive seed, one of 16777216, found in 4.2 seconds using.a RTX 4090, not 88 minutes)

gmaxwell
Staff
Legendary
*
Offline

Activity: 4830
Merit: 11349



View Profile WWW
Today at 01:59:15 AM
Merited by vapourminer (1), stwenhao (1)
 #357

It would be prudent to remind people here that there are still a lot of vulnerable funds that could be saved and that it would be anti-social to explain how to reduce the search space of coldcard devices just to brag about how smart you are, or show that some rando was wrong on the internet.

Plenty of other people could be posting about the exact search space needed to enumerate vulnerable seeds and are kindly refraining from doing so. Just because you could figure out that doesn't mean that every would be coin-thief is going to figure it out before the owners sweep their coins.

[I'm not picking on anyone here, this is in fact a repost of a comment I just wrote on reddit.]
tvbcof
Legendary
*
Offline

Activity: 5292
Merit: 1321


View Profile
Today at 02:44:38 AM
Last edit: Today at 05:19:55 AM by tvbcof
Merited by NotATether (2), vapourminer (1), joker_josue (1)
 #358

It would be prudent to remind people here that there are still a lot of vulnerable funds that could be saved and that it would be anti-social to explain how to reduce the search space of coldcard devices just to brag about how smart you are, or show that some rando was wrong on the internet.

Plenty of other people could be posting about the exact search space needed to enumerate vulnerable seeds and are kindly refraining from doing so. Just because you could figure out that doesn't mean that every would be coin-thief is going to figure it out before the owners sweep their coins.

[I'm not picking on anyone here, this is in fact a repost of a comment I just wrote on reddit.]


Not so sure, Greg.

I found out about the 'bug', and the initial details of it, when I had about 3 days left in a foreign land.  I had to decide whether to get an emergency ticket home.  My own musings about such optimizations and growth rates had a lot to do with my catching the next plane home rather than waiting.  I'm very glad I did.

I would question the potential for someone who didn't think of some of the optimizations to implement them triggered by general chatter.  Even if they did, they would likely be highly out-competed by sharper minds or groups of minds.  No pun on 'mines' intended.

At the end of the day, I almost always tend to lean toward full, accurate, and truthful information availability as a general principle.  Not always, but usually all else being marginally close to equal.

Actually one could be mildly suspicious about sources which circulate information that drastically overstates some of the metrics such as search space.


sig spam anywhere and self-moderated threads on the pol&soc board are for losers.
Dave1
Hero Member
*****
Offline

Activity: 2128
Merit: 643



View Profile
Today at 06:13:09 AM
 #359

Not sure if this is true or not,



https://x.com/News_crypto/status/2084558130239664431

Or this is just for the clickbait and clout about the current incident. But this could be bad crypto media. And if confirmed, this is really a sad story and tragic. The thing is that the one that is going to suffer the most here is that family that is going to be left behind.


███████▄▄███▄███▄
███▄▄████████▌██
▄█████████████▐██▌
██▄███████████▌█▌
███████▀██████▐▌█
██████████████▌▌▐
████████▄███████▐▐
█████████████████
███████████████▄██▄
██████████████▀▀▀
█████▀███▀▀▀

▄▄▄██████▄▄▄███████▄▄▄
███████████████████████████
███▌█████▀███▌█████▀▀███████████▄▄▄▄▄▄▄▄
███▌█████▄███▌█████▄███▐███████████████████▄
▐████████████▀███████▄██████████▀▀▀▀▀▀▀▀████▀
▐████████████▄██▄███████████▌█████████▄████▀
▐█████████▀█████████▌█████████████▄▄████▀
██████████▄███████████▐███▌██▄██████▀
██████████████▀███▐███▌██████████████████████
████▀██████▀▀█████████▌███▀▀▀▀███▀▀▀▀▀▀▀████▌
 
      P R E M I E R   B I T C O I N   C A S I N O   &   S P O R T S B O O K      

█▀▀









▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

  98%  
RTP

 
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█









▀▀▀

█▀▀









▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

 HIGH 
ODDS

 
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█









▀▀▀
 
..PLAY NOW..
Somegory
Full Member
***
Offline

Activity: 378
Merit: 186



View Profile
Today at 06:24:17 AM
 #360

My advice is have a few setups and add strong passphrases
I know the importance of wallet passphrase but honestly I don't know what are strong passphrases, could you help me with information about that or any resources for learning about that?

If a scammer get access to your seed phrase and scan the wallet and see nothing on the wallet, they are not going to walk away immediately, they will try to guess right some common possible words which they know you might use as extension of your seed phrase. They are going to test words like your name, your child name or common strings you use for password, all of these are weak passphrase that scammer can guess right especially if the person knows much about you in detail. You should learn to use words that are uncommon that you can remember any time.

Quote
It's easy to find resources to learn about passwords, how to create a strong password, but with passphrases I see very limited resources to learn and apply for my practice.

I think that's because seed phrase that is generated with a secured entropy is safe for your Bitcoin that's why emphasis are not given to passphrase and some recommendations but it's something you can do. If not for Coldcard negligence, most people don't use passphrase unless they want to use it. Look at numbers of wallet that were swept, it shows most didn't use passphrase else the attacker wouldn't be able to access them.

Are you saying that someone can stumble on my seed phrase online, maybe through leaking or maybe I use my hands to insert it online and the next is they will know my child's name or my mother's name?

Good luck with that on their end, also who would be stupid enough to use just name? Why not osamabinladen#£+()!//@;*£;@;'snhagunna? Good luck on their end, there is no way they will have access to a passphrase unless they found it through the keeper.

Maybe the owner store them carelessness, in the same way that caused the seed phrases to get exposed in the first place, even a single - can make a huge difference.

Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 [18] 19 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!