JayJuanGee
Legendary
Online
Activity: 4536
Merit: 14847
Self-Custody is a right. Say no to "non-custodial"
|
My advice is have a few setups and add strong passphrases
I know the importance of wallet passphrase but honestly I don't know what are strong passphrases, could you help me with information about that or any resources for learning about that? It's easy to find resources to learn about passwords, how to create a strong password, but with passphrases I see very limited resources to learn and apply for my practice. Like how many words are considered as strong enough for a wallet passphrase? No recommendation about that in Mastering Bitcoin book. https://github.com/bitcoinbook/bitcoinbook/blob/develop/ch05_wallets.adoc#optional-passphrase-in-bip39Personally, I think that the earlier table that was posted by Forsyth Jones is a good guideline for at least shooting for at least minimal levels of safety, especially if we want to shoot to have our levels to at least be in the orange, and probably better to be in the lighter orange rather than the darker orange, just to be safer, yet even if we land in the darker orange, we should not need to panic, even though we might want to consider if we might want to create a wee bit stronger variation and then move our coins to that stronger variation. Below is a table showing the strength of each passphrase extension:  you jest but at least mtgox people got ~20% of their btc/bcash back
Yep and a long solid hodl so good they made nice money in fiat terms.
incorrect i think just like FTX they got 20% of the price at the time of theft. so no hodl, just 20% of what u lost at that time 5-6 or more years ago You are guessing, and you are providing skewedly wrong information because you guess wrong and you act like you know what you are talking about, when you don't. MTGOX got around 20% of the number of coins that they had at the time of the shutdown (which is "in-kind" redemption), and I think around 75% of the claims (or the total value had been paid so far) - yeah 10 years later, which is a bit of an injustice in itself. FTX got something around 20% of the cash value at the time of the filing, when the BTC price was then around $19.5k... So they were not the same, and the FTX folks got reimbursed even worse since their bitcoin claims were liquidated into dollars and they got 20% of the dollar value and the BTC price was up around 3x (close to $60k) when they got paid those dollars. Maybe you could argue that FTX is more just because the claims were paid out more promptly, and so I am not going to dispute that the forced HODL situation of MTGOX likely created a lot of injustices for those who did not have something like a 10-ish to 13-ish year timeline, to the extent that they had already been paid (maybe around 75% paid), and I am not sure if the still fucking around to pay more claims will end up getting paid, since there is some strangeness in how long it is taking with potential distributions at the end of this year, perhaps? so yeah, delays are injust, too.
|
1) Self-Custody is a right. Resist being labelled as: "non-custodial" or "un-hosted." 2) ESG, KYC & AML are attack-vectors on Bitcoin to be avoided or minimized. 3) How much alt (shit)coin diversification is necessary? if you are into Bitcoin, then 0%......if you cannot control your gambling, then perhaps limit your alt(shit)coin exposure to less than 10% of your bitcoin size...Put BTC here: bc1q49wt0ddnj07wzzp6z7affw9ven7fztyhevqu9k
|
|
|
joker_josue
Legendary

Activity: 2478
Merit: 7336
**In BTC since 2013**
|
 |
August 06, 2026, 06:42:59 AM |
|
I found out about the 'bug', and the initial details of it, when I had about 3 days left in a foreign land. I had to decide whether to get an emergency ticket home. My own musings about such optimizations and growth rates had a lot to do with my catching the next plane home rather than waiting. I'm very glad I did.
It's vacation time in most countries in the Northern Hemisphere. I believe there are still many people in a similar situation. Some people tend to take a few days to be 100% offline, so they may not even be aware of this whole problem yet. They may have already run out of coins and not even know it. I think that in a week, when many people return from vacation, they will have a sad surprise. More reports will emerge and the numbers will increase. Fortunately for you, you were aware of the situation and had the ability to return in time (I hope). Many probably weren't so lucky.
|
|
|
|
NotATether
Legendary

Activity: 2422
Merit: 10111
┻┻ ︵㇏(°□°㇏)
|
 |
August 06, 2026, 07:06:59 AM |
|
Or this is just for the clickbait and clout about the current incident. But this could be bad crypto media. And if confirmed, this is really a sad story and tragic. The thing is that the one that is going to suffer the most here is that family that is going to be left behind.
CLICKBAIT until confirmed true by authorities. The account on X posting this is just taking screenshots and fabricating news pieces based on his imagination. Very shameful conduct by a so-called "news" account. Already requested Community Note for that post so that it doesn't mislead anyone.
|
|
|
|
Danish Ali
Newbie

Activity: 12
Merit: 1
|
 |
August 06, 2026, 08:44:38 AM |
|
It's vacation time in most countries in the Northern Hemisphere. I believe there are still many people in a similar situation.
Some people tend to take a few days to be 100% offline, so they may not even be aware of this whole problem yet. They may have already run out of coins and not even know it.
I think that in a week, when many people return from vacation, they will have a sad surprise. More reports will emerge and the numbers will increase.
Fortunately for you, you were aware of the situation and had the ability to return in time (I hope). Many probably weren't so lucky.
It is very serious statement. Losses are well over $130 million and the attack continues, people coming back from vacation are not just walking into bad news, they could be walking into active losses. Probably the most important thing offline users need to know first is that wallets created using the dice-roll option are safe. All else can wait.
|
|
|
|
|
ryzaadit
Legendary

Activity: 3290
Merit: 1395
|
 |
August 06, 2026, 09:03:03 AM |
|
Crazy to see the sweeps just need 10 seconds after the deposit. https://x.com/we_satoshis/status/2085034468935450918Some social experiment being made by Wesatoshis, who provides a Bitcoin hardware terminal for moving transaction with @Pathfinder to fill his Coldcard MK3 with 10,000 sat for the atacker to take the baits. And indeed..... just need 10 second after the deposit for the atacker trying to take those fund Their device detected the sweeps and both of them are in the race for RBF transaction. The hacker lose the race. They ended with paying fees 9,000 sat and receiving 1,000 sat losing 90% of the fund on miners fees.
|
| EARNBET | | | ⚽ 🏀 🏈 🏓 🎯 🥊 |
| ⚾ 🎾 ⛳ 🏐 🏏 🏎️ | | |
███████▄▄███████████ ████▄██████████████████ ██▄▀▀███████████████▀▀███ █▄████████████████████████ ▄▄████████▀▀▀▀▀████████▄▄██ ███████████████████████████ █████████▌████▀████████████ ███████████████████████████ ▀▀███████▄▄▄▄▄█████████▀▀██ █▀█████████████████████▀██ ██▀▄▄███████████████▄▄███ ████▀██████████████████ ███████▀▀███████████ | ....HIGHEST.... VIP REWARDS ✔ G U A R A N T E E D
| | | 🜲 | KING OF THE CASTLE $200K in prizes | | | ..PLAY NOW.. |
|
|
|
|
kTimesG
|
 |
August 06, 2026, 10:23:55 AM |
|
It would be prudent to remind people here that there are still a lot of vulnerable funds that could be saved and that it would be anti-social to explain how to reduce the search space of coldcard devices just to brag about how smart you are, or show that some rando was wrong on the internet. My intention was to simply point out that the specific honeypot doesn't reflect real-life conditions. It's not a security breach to use the number "42" which was pretended to be some sort of a honey pot of all wallets between 1 and 100 (out of which none was actually ever created)., when in reality there's a jigsaw puzzle hidden in a maze with a billion doors.
|
|
|
|
Cookdata
Legendary

Activity: 1764
Merit: 1438
Not Your Keys, Not Your Bitcoin
|
Their device detected the sweeps and both of them are in the race for RBF transaction. The hacker lose the race. They ended with paying fees 9,000 sat and receiving 1,000 sat losing 90% of the fund on miners fees.
There is a similar experimental video about Mk3 but with different objectives, the person created 5 different wallets using Mk3 Coldcard, the first wallet was generated using the insecure random number generator, the same seed phrase was used to generate 3 wallets with different passphrases and the last wallet which is the 5th was generated using the same seed phrase from a random account. http://x.com/ColeTU/status/2085090397223637049He funded the 5 generated addresses from each wallet with 10800 sats each https://mempool.space/tx/f6a0e25dfa9b03f4a45c65cddeebafb0ea50c9b2732febbafd9a7f40ecf7b7da to see which of the wallet is getting sweep first and it turns out that the insecured RNG which is the first wallet was swept immediately, he could have overide it with a new transaction and pay more fees too but his objective is to see how the scammers are moving the coins and if passphrase 1 word, 2 words or 3 are secured enough with an insucure RNG seed phrase. So far, the first wallet is swept, and the sats are sitting in this address: https://mempool.space/address/bc1qunqajps4elc78m8fq7s7nglc6x80j49exheq78The rest of the wallets with the same seed phrase and passphrases are intact, the same wallet with the same seed phrase but a random account is also intact. That means the scammers focus is on default accounts created from Mk3, they don't search all account derivations.
|
| . .Duelbits..REWARDING, BEYOND LIMITS... | █████████████████████████ █████████████████████████ ███████████▀▀░░▀█▄░░▀████ ████████▀░░░░░░░░▀█▄░████ ███████░░░░▄▄░░▄░░░▀█████ ██████░░░░░▀▀▄██▀░░░░████ █████░░░██░▄██▀▄▄░░░█████ ████░░░░░▄██▀░░▀▀░░██████ █████▄░░▀█▀░██░░░░███████ ████░▀█▄░░░░░░░░▄████████ ████▄░░▀█▄░░▄▄███████████ █████████████████████████ █████████████████████████ | █████████████████████████ █████████████████████████ █████████▀░░▀░███████████ ████████░░░▄░█░██████████ ███████████▌▐██░█████████ ███████████░███▌▐████████ ██████████░█████░████████ ██████▀░▄░▀███▀░▄░▀██████ █████░▄▀░░░░█░▄▀░░░░█████ █████░░░░░░░█░░░░░░░█████ ██████▄░░░▄███▄░░░▄██████ █████████████████████████ █████████████████████████ | █ █ █ █ █ █ █ █ █ █ █ █ █ | |
| | █ █ █ █ █ █ █ █ █ █ █ █ █ | PLAY NOW |
[/center
|
|
|
|
Bullethead21
|
 |
August 06, 2026, 10:32:39 AM |
|
I have a TREZOR? I am still save?
|
|
|
|
|
vapourminer
Legendary

Activity: 5124
Merit: 6635
what is this "brake pedal" you speak of?
|
 |
August 06, 2026, 10:56:46 AM |
|
I have a TREZOR? I am still save?
if you used a seed generated on a coldcard, no you are not safe. you need to move funds out. otherwise depends on how you generated the seed, but so far other wallets are not affected by the coldcard bug
|
|
|
|
|
Filicius
Sr. Member
  

Activity: 714
Merit: 361
ENG>SPA translator
|
 |
August 06, 2026, 11:07:53 AM |
|
It's incredible: although I didn't see it, apparently yesterday in the local news they commented on this issue, but when a friend of mine who was able to see it told me about this news it seems that they confused it with a Bitcoin base problem and not with something related to a specific device.
I am reluctant to think that a serious news program is capable of making a mistake of such magnitude, and, most likely, the person who has told me about it misunderstood what they said. But, if so, there are many more people who know less about the subject that my friend and who saw the news that must be thinking that something is wrong with Bitcoin.
|
| Kings Game | | | │ │ | 🎰 | │ │ | 🎲 | │ │ | ⚽ | | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | ████████████████████████████
████████████████████████████ | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | ████████████████████████████
| 500% | WELCOME BONUS + 250 FREE SPINS |
████████████████████████████ | ████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ████ | ██████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██████ | WIN NOW | ██████ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██████ |
|
|
|
stompix
Legendary

Activity: 3710
Merit: 7282
|
Not sure if this is true or not, https://x.com/News_crypto/status/2084558130239664431Or this is just for the clickbait and clout about the current incident. But this could be bad crypto media. And if confirmed, this is really a sad story and tragic. The thing is that the one that is going to suffer the most here is that family that is going to be left behind. One guy sends a message and claims to commit suicide, and we already write him dead? Also, who uses a tumbler to split move funds 4 times before sending that message to reimburse him to an address with no activity? Seriously, lately the ratio of noise to actual info is going down the drain. It's vacation time in most countries in the Northern Hemisphere. I believe there are still many people in a similar situation. Some people tend to take a few days to be 100% offline, so they may not even be aware of this whole problem yet. They may have already run out of coins and not even know it.
I doubt they have planned it this way all along but indeed, it came at one of the worst times possible, at least for Christmas or some other holiday a lot of people are home with family, in summer, things are different. I'm sure there are plenty who don't even know what has happened yet.
|
| DΞX.fo | | | | | | ▄▄██████ █████████ ██████████ ██████████ ██████████ █████████ ▀▀██████
▄███████ ▄██████████ ████████████ █████████████ █████████████ | | | | ▄▄█ ▄████▀ ▄███▀█▄ ▄██▀█▄██ █████▀▀█ ████████ ████████ ▀██▄████ ▄████▄▄█ ▄█████▀███ ▄█████▀████▀ █████▀███████ ▀██▀█████████ | | | | | BTC XMR DAI LTC Fees 0.8% |
|
|
|
Wind_FURY
Legendary

Activity: 3738
Merit: 2213
|
 |
August 06, 2026, 11:22:11 AM |
|
The community in general is still "lucky" that the stupidity came from the ColdCard developers.
This is one of the reasons I'm always careful paranoid when a new wallet (be it hardware or software) is released. It took me years to trust Ledger (until they broke that trust), and now I only have Trezor left on my personal preferred list of hardware wallets. The fact that this Coldcard flaw was around for 5 years makes it only harder to trust anything. But for the truly paranoid, install Bitcoin Core/Electrum in a computer that will NEVER connect to the internet FOREVER, and generate your keys/seed phrase there. Write it down, then keep it in a safe place. The same for the computer, keep it locked in a vault. Keep sending Bitcoin to that address. To be honest, I don't think this is a good solution for the truly paranoid (or even for the mildly paranoid). You've just switched from using hardware wallets over to Electrum as your preferred solution. What if there was some vulnerability exposed within the Electrum development? It really wouldn't make that much difference to the final outcome. Read my post again. I believe you didn't understand that it's one of the original solutions for cold-storage before hardware wallets were invented. PLUS Electrum is one of the truly tested wallets in the Bitcoin ecosystem. It's not a debate. It's a FACT.  Shower thought. The ColdCard situation might be an inside job.
|
|
|
|
ultrloa
Legendary

Activity: 3472
Merit: 1471
|
 |
August 06, 2026, 11:27:59 AM |
|
I have a TREZOR? I am still save?
if you used a seed generated on a coldcard, no you are not safe. you need to move funds out. otherwise depends on how you generated the seed, but so far other wallets are not affected by the coldcard bug Right, because those vulnerability on happens on created seeds on those compromised old coldcard firmware and this is not affect the seeds of other devices. But I think there's no way for Trezor user to generate seed on Coldcard. So generally he's safe from this exploit. So those seed generated by like Ledger, Seedsigner and other wallets is not affected on the exploit happened on Coldcard.
|
|
|
|
|
|
| R |
▀▀▀▀▀▀▀██████▄▄ ████████████████ ▀▀▀▀█████▀▀▀█████ ████████▌███▐████ ▄▄▄▄█████▄▄▄█████ ████████████████ ▄▄▄▄▄▄▄██████▀▀ | LLBIT | | | 4,000+ GAMES███████████████████ ██████████▀▄▀▀▀████ ████████▀▄▀██░░░███ ██████▀▄███▄▀█▄▄▄██ ███▀▀▀▀▀▀█▀▀▀▀▀▀███ ██░░░░░░░░█░░░░░░██ ██▄░░░░░░░█░░░░░▄██ ███▄░░░░▄█▄▄▄▄▄████ ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀ | █████████ ▀████████ ░░▀██████ ░░░░▀████ ░░░░░░███ ▄░░░░░███ ▀█▄▄▄████ ░░▀▀█████ ▀▀▀▀▀▀▀▀▀ | █████████ ░░░▀▀████ ██▄▄▀░███ █░░█▄░░██ ░████▀▀██ █░░█▀░░██ ██▀▀▄░███ ░░░▄▄████ ▀▀▀▀▀▀▀▀▀ |
| | | | | | .
| | | ▄▄████▄▄ ▀█▀▄▀▀▄▀█▀ ▄▄░░▄█░██░█▄░░▄▄ ▄▄█░▄▀█░▀█▄▄█▀░█▀▄░█▄▄ ▀▄█░███▄█▄▄█▄███░█▄▀ ▀▀█░░░▄▄▄▄░░░█▀▀ █░░██████░░█ █░░░░▀▀░░░░█ █▀▄▀▄▀▄▀▄▀▄█ ▄░█████▀▀█████░▄ ▄███████░██░███████▄ ▀▀██████▄▄██████▀▀ ▀▀████████▀▀ | . ▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄ ░▀▄░▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄░▄▀ ███▀▄▀█████████████████▀▄▀ █████▀▄░▄▄▄▄▄███░▄▄▄▄▄▄▀ ███████▀▄▀██████░█▄▄▄▄▄▄▄▄ █████████▀▄▄░███▄▄▄▄▄▄░▄▀ ████████████░███████▀▄▀ ████████████░██▀▄▄▄▄▀ ████████████░▀▄▀ ████████████▄▀ ███████████▀ | ▄▄███████▄▄ ▄████▀▀▀▀▀▀▀████▄ ▄███▀▄▄███████▄▄▀███▄ ▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄ ▄██▀▄███░░░▀████░███▄▀██▄ ███░████░░░░░▀██░████░███ ███░████░█▄░░░░▀░████░███ ███░████░███▄░░░░████░███ ▀██▄▀███░█████▄░░███▀▄██▀ ▀██▄▀█▄▄▄██████▄██▀▄██▀ ▀███▄▀▀███████▀▀▄███▀ ▀████▄▄▄▄▄▄▄████▀ ▀▀███████▀▀ | | OFFICIAL PARTNERSHIP SOUTHAMPTON FC FAZE CLAN SSC NAPOLI |
|
|
|
|
RoxxR
|
 |
August 06, 2026, 11:36:09 AM |
|
Lol now there's a Counterparty asset about this story. https://xcp.io/asset/NOTSOCOLD Seems that it didn't get much coverage in mainstream media, though?
|
|
|
|
|
Danish Ali
Newbie

Activity: 12
Merit: 1
|
 |
August 06, 2026, 01:37:45 PM |
|
I have a TREZOR? I am still save?
if you used a seed generated on a coldcard, no you are not safe. you need to move funds out. otherwise depends on how you generated the seed, but so far other wallets are not affected by the coldcard bug Exactly, the device brand does not matter here, the seed origin does. Any wallet holding Coldcard generated seed is equally at risk regardless of what hardware it is running on now.
|
|
|
|
|
Stalker22
Legendary

Activity: 2324
Merit: 1617
|
I doubt they have planned it this way all along but indeed, it came at one of the worst times possible, ~ I think someone DID plan this carefully. The first few batched transactions were executed almost simultaneously. This means someone had to crack all the private keys, find the wallets with the largest balances, prepare and sign all the transactions, and just wait for the right time to execute. I'm sure there are plenty who don't even know what has happened yet.
Unfortunately, yes. Mainstream coverage of this incident has been practically nonexistent, keeping the story confined strictly to the crypto space.
|
|
|
|
vapourminer
Legendary

Activity: 5124
Merit: 6635
what is this "brake pedal" you speak of?
|
Mainstream coverage of this incident has been practically nonexistent, keeping the story confined strictly to the crypto space.
just as well; the public would think its a bitcoin-the-protocol is hacked and create panic. its just one hardware wallets manufacturers idiot programming. not a big deal in the general bitcoin space as a whole. not to minimize the absolute suck this whole thing is for victims and thats what they were, victims. not their fault they trusted this thing it was recommended by many here and elsewhere.
|
|
|
|
|
LoyceV
Legendary

Activity: 4130
Merit: 22422
Thick-Skinned Gang Leader and Golden Feather 2021
|
 |
August 06, 2026, 02:29:00 PM |
|
Crazy to see the sweeps just need 10 seconds after the deposit. Was that a new hardware wallet with a newly created seed phrase, or a seed phrase that was compromised before? If it's the former, that means someone (or multiple entities) are now racing through all ~trillion possible seed phrases to detect any new incoming funds. losing 90% of the fund on miners fees. RBF is a bitch for thiefs: Things will get quite interesting once full RBF becomes commonplace. Any such transaction stealing coins from a brain wallet or leaked private key could be replaced by another transaction, regardless of whether or not is opted in to RBF or not. We could end up seeing different bots broadcasting more and more replacements, each paying a higher and higher fee, trying to steal the coins for themselves. Since there is no incentive for any one such bot to surrender and let another bot win, then such transactions could just escalate until the entire value (or close to it) is paid in fees. I was curious about that scenario too. That would mean that (eventually) only miners profit from funds sent to addresses with leaked private keys.
|
¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
|
|
|
hd49728
Legendary

Activity: 2912
Merit: 1364
|
 |
August 06, 2026, 02:41:05 PM |
|
Crazy to see the sweeps just need 10 seconds after the deposit.
Some social experiment being made by Wesatoshis, who provides a Bitcoin hardware terminal for moving transaction with @Pathfinder to fill his Coldcard MK3 with 10,000 sat for the atacker to take the baits. And indeed..... just need 10 second after the deposit for the atacker trying to take those fund
Their device detected the sweeps and both of them are in the race for RBF transaction. The hacker lose the race. They ended with paying fees 9,000 sat and receiving 1,000 sat losing 90% of the fund on miners fees.
It's interesting information to see how attackers do their jobs but I don't see attackers losing anything here. They already stole a lot of money with about 1,500 bitcoins so far, and even in this sweep transaction, they did not lose 9,000 satoshi but actually got 1,000 satoshi. Because every satoshi is worth something now and will be worth more in the future. https://charts.bitbo.io/satoshi-per-dollar/With this test, it shows the attackers use bots to do their jobs but it's not strange because attackers will not move funds manually. They need to sweep fund immediately and as fastest as possible while manual processing it is not helpful.
|
|
|
|
pawanjain
Legendary

Activity: 3500
Merit: 1004
Nothing lasts forever
|
 |
August 06, 2026, 02:44:08 PM |
|
At this point, I have stopped trusting these hardware wallets. Are there even any option left for really good hardware wallets? What's the point of having one if they can have such bugs which can sweep out millions of funds in such a short time. I know it's not the users fault here but the company has to take the responsibility here for the mess up and ensure their users get their funds back. Who knows, it can even be an insider job. That's always the first thought I get when such hacks happen.
|
|
|
|
|