Bitcoin Forum
August 07, 2026, 09:34:07 PM *
News: COLDCARD users only: critical vulnerability risks funds stored on COLDCARD devices; immediate action required
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 [20] 21 »  All
  Print  
Author Topic: Large-scale Coldcard compromise (1485.77 BTC stolen so far)  (Read 6742 times)
oll
Full Member
***
Offline

Activity: 327
Merit: 151


old oll


View Profile
August 06, 2026, 03:09:11 PM
 #381

Mainstream coverage of this incident has been practically nonexistent, keeping the story confined strictly to the crypto space.

just as well; the public would think its a bitcoin-the-protocol is hacked and create panic. its just one hardware wallets manufacturers idiot programming. not a big deal in the general bitcoin space as a whole.

not to minimize the absolute suck this whole thing is for victims and thats what they were, victims. not their fault they trusted this thing it was recommended by many here and elsewhere.

That's right, because for the general public, bitcoin and blockchain are not amazing technologies, but a "speculative asset" that some of them bought for 120k in euphoria, someone got burned earlier, and someone regrets that he did not buy 100 bucks and carries this fomo through the years. And all this mass of people will happily leave toxic comments without even delving into the topic of the ColdCard issue. This is how the mass psychology of people works: they need to justify their greed and laziness by preserving their own picture of the world. Which is distorted, and so does not want to change. And over the years, this static only increases. And it would seem that a crypto enthusiast can easily help this person, but in the end it will be he who will be the first to be blamed for the investment troubles of such people.
Pmalek
Legendary
*
Offline

Activity: 3584
Merit: 9427



View Profile
August 06, 2026, 03:35:05 PM
Merited by vapourminer (1), JayJuanGee (1), ABCbits (1), hosemary (1)
 #382

Bitcoin Red Team consists of 16 people who are working around the clock now and running security audits on Bitcoin code bases. According to their report, they have already made close to 5,000 findings and discovered what they believe are 85 critical and 635 high severity issues. They report these issues back to project owners and companies, and I think that's a great thing that has come out of this terrible situation. Whitehats and industry experts joining forces to help secure the wider Bitcoin ecosystem.

https://xcancel.com/callebtc/status/2085024458012586286

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
ryzaadit
Legendary
*
Offline

Activity: 3290
Merit: 1395



View Profile
August 06, 2026, 05:38:04 PM
 #383

I have a TREZOR? I am still save?


Best thing to do, add your own entropy my friend. Learn about entropy.

Was that a new hardware wallet with a newly created seed phrase, or a seed phrase that was compromised before?
If it's the former, that means someone (or multiple entities) are now racing through all ~trillion possible seed phrases to detect any new incoming funds.
Unfortunately, it's new.

At this point, I have stopped trusting these hardware wallets. Are there even any option left for really good hardware wallets?
Just because of one stupid manufacturer mistake, don't lose your belief in hardware wallets. There are so many good hardware wallets out there.

People forget some important things, mostly new people. They think that owning a hardware wallet their fund 100% secure, and this is the reason by using hardware wallet removes the feeling of safety, especially for anyone who has not learned more about safety risk.

Hardware wallets are just one key element; you can add more security risks to your stored system.
- Learn entropy
- Make your own key
- Create a multi-signature transaction
- Store your funds not just in one single bucket

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
Meuserna
Sr. Member
****
Offline

Activity: 340
Merit: 559


View Profile WWW
August 06, 2026, 05:49:25 PM
Last edit: August 06, 2026, 07:19:11 PM by Meuserna
Merited by NotFuzzyWarm (1)
 #384

I think there's no way for Trezor user to generate seed on Coldcard. So generally he's safe from this exploit.

Sure there is.

Generate a seed on a ColdCard. Enter the seed on a Trezor to restore the wallet. The wallet is still in danger because the seed was generated on a ColdCard.

Edited to add a specific example: Let's say somebody has been using a ColdCard since 2022. They heard about ColdCard users getting robbed, so they ran to Best Buy and bought a Trezor. They restored their seed on their new Trezor. "Whew! No more ColdCard. I'm safe!" Nope. Their wallet is still in danger because the seed was originally generated on a ColdCard with borked code that was generating seeds with only limited randomness.

Over the past week, I keep seeing posts where people say they moved their seed to a Trezor, thinking they're safe.

I wish more Bitcoiners understood: the device is not the wallet. The seed is the wallet, because the seed generates the addresses and keys.

ColdCard owners are getting robbed because their devices generated predictable seeds. Moving a predictable seed to a Trezor doesn't change the fact that the seed was predictable, so the seed can be found by going through the list of all possible seeds generated by ColdCard's borked code.

suzanne5223
Hero Member
*****
Offline

Activity: 3402
Merit: 751


Want top-notch marketing for your brand, Hire me


View Profile WWW
August 06, 2026, 07:35:01 PM
 #385

Their device detected the sweeps and both of them are in the race for RBF transaction.
The hacker lose the race. They ended with paying fees 9,000 sat and receiving 1,000 sat losing 90% of the fund on miners fees.

There is a similar experimental video about Mk3 but with different objectives, the person created 5 different wallets using Mk3 Coldcard, the first wallet was generated using the insecure random number generator, the same seed phrase was used to generate 3 wallets with different passphrases and the last wallet which is the 5th was generated using the same seed phrase from a random account.

http://x.com/ColeTU/status/2085090397223637049

He funded the 5 generated addresses from each wallet with 10800 sats each https://mempool.space/tx/f6a0e25dfa9b03f4a45c65cddeebafb0ea50c9b2732febbafd9a7f40ecf7b7da to see which of the wallet is getting sweep first and it turns out that the insecured RNG which is the first wallet was swept immediately, he could have overide it with a new transaction and pay more fees too but his objective is to see how the scammers are moving the coins and if passphrase 1 word, 2 words or 3 are secured enough with an insucure RNG seed phrase.

So far, the first wallet is swept, and the sats are sitting in this address: https://mempool.space/address/bc1qunqajps4elc78m8fq7s7nglc6x80j49exheq78

The rest of the wallets with the same seed phrase and passphrases are intact, the same wallet with the same seed phrase but a random account is also intact. That means the scammers focus is on default accounts created from Mk3, they don't search all account derivations.
I think the idea of using an exposed Coldcard wallet as an experiment to see the reaction of what the attacker will do was something that was first started by this person based on the time and date he purposely left 0.0025 BTC behind as bait. At the same time, he outshone the Coldcard attacker onchain.

https://x.com/wowens/status/2084041966212591963?s=20

▄▄███████████████████▄▄
▄███████████████████████▄
███████████████████████
████████▀▀▀▀██▀█▄▀███████
███▀▀██▄▄██▄██▌▄▄▄▄▄██
████▄█████▐██▀▄█▀▀█████
█████▌██▀▀▄█▀██▄██▄███
██▄▄▄▄███████████▐███████
████████▐█████████▀▀█████
███████▄██████▀█▄▄▄▄▄████
███████████████████████

▀███████████████████████▀
▀▀███████████████████▀▀

 Kings Game  
 
 🎰   🎲   ⚽ 
████
██
██
██
██
██
██
██
██
██
██
██
████
████████████████████████████


RAKEBACK
..UP TO 30%..
████████████████████████████
████
██
██
██
██
██
██
██
██
██
██
██
████
████
██
██
██
██
██
██
██
██
██
██
██
████
████████████████████████████
 
..500%..
WELCOME BONUS
+ 250 FREE SPINS
████████████████████████████
████
██
██
██
██
██
██
██
██
██
██
██
████

   WIN NOW     
OgNasty
Donator
Legendary
*
Offline

Activity: 5558
Merit: 6436


Leading Crypto Sports Betting & Casino Platform


View Profile WWW
August 06, 2026, 07:38:06 PM
 #386

Their device detected the sweeps and both of them are in the race for RBF transaction.
The hacker lose the race. They ended with paying fees 9,000 sat and receiving 1,000 sat losing 90% of the fund on miners fees.

There is a similar experimental video about Mk3 but with different objectives, the person created 5 different wallets using Mk3 Coldcard, the first wallet was generated using the insecure random number generator, the same seed phrase was used to generate 3 wallets with different passphrases and the last wallet which is the 5th was generated using the same seed phrase from a random account.

http://x.com/ColeTU/status/2085090397223637049

He funded the 5 generated addresses from each wallet with 10800 sats each https://mempool.space/tx/f6a0e25dfa9b03f4a45c65cddeebafb0ea50c9b2732febbafd9a7f40ecf7b7da to see which of the wallet is getting sweep first and it turns out that the insecured RNG which is the first wallet was swept immediately, he could have overide it with a new transaction and pay more fees too but his objective is to see how the scammers are moving the coins and if passphrase 1 word, 2 words or 3 are secured enough with an insucure RNG seed phrase.

So far, the first wallet is swept, and the sats are sitting in this address: https://mempool.space/address/bc1qunqajps4elc78m8fq7s7nglc6x80j49exheq78

The rest of the wallets with the same seed phrase and passphrases are intact, the same wallet with the same seed phrase but a random account is also intact. That means the scammers focus is on default accounts created from Mk3, they don't search all account derivations.
I think the idea of using an exposed Coldcard wallet as an experiment to see the reaction of what the attacker will do was something that was first started by this person based on the time and date he purposely left 0.0025 BTC behind as bait. At the same time, he outshone the Coldcard attacker onchain.

https://x.com/wowens/status/2084041966212591963?s=20

It isn't like this costs the attacker anything though.  It's also probably an automated process at this point, so most likely the person is just wasting their own time and money.  In this case they probably got some social media fame, followers, and maybe a boost to their X payout.  However, this isn't the huge win it may appear to be if you don't understand how the process works.  Whatever it takes to cope with the pain though.  In the end, laughter is the best medicine.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
tvbcof
Legendary
*
Offline

Activity: 5292
Merit: 1321


View Profile
August 06, 2026, 08:57:32 PM
Last edit: Today at 12:21:01 AM by tvbcof
 #387

...
from image:

imagine compromising someone's hardware wallet and still fumbling the bag
...

Imagine controlling everyone who used the device's keys, dice or not, and letting a hoard of bag-fumblers fight over the the dice-less dregs for the next few years.

Imagine further, whale keys sitting safely on the blockchain to be harvested as-needed in the coming decades.


sig spam anywhere and self-moderated threads on the pol&soc board are for losers.
bitmover
Legendary
*
Offline

Activity: 3122
Merit: 7658


Trêvoid █ No KYC-AML Crypto Swaps


View Profile WWW
August 06, 2026, 10:44:03 PM
Merited by JayJuanGee (1)
 #388

Personally, I think that the earlier table that was posted by Forsyth Jones is a good guideline for at least shooting for at least minimal levels of safety, especially if we want to shoot to have our levels to at least be in the orange, and probably better to be in the lighter orange rather than the darker orange, just to be safer, yet even if we land in the darker orange, we should not need to panic, even though we might want to consider if we might want to create a wee bit stronger variation and then move our coins to that stronger variation.

Below is a table showing the strength of each passphrase extension:


I think 32 years is secure enough for me  Cheesy

But even the 12 years variation of 8 characters are basically invulnerable for any practical purposes.

Just create a passphrase you like and can remember. I believe this is the lesson for everyone about this attack/scam

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|  BTC     XMR  
  DAI     LTC  
   Fees  0.8%    
fillippone
Legendary
*
Online Online

Activity: 2982
Merit: 21223


Duelbits.com - Rewarding, beyond limits.


View Profile WWW
August 06, 2026, 10:48:48 PM
 #389

Bitcoin Red Team consists of 16 people who are working around the clock now and running security audits on Bitcoin code bases. According to their report, they have already made close to 5,000 findings and discovered what they believe are 85 critical and 635 high severity issues. They report these issues back to project owners and companies, and I think that's a great thing that has come out of this terrible situation. Whitehats and industry experts joining forces to help secure the wider Bitcoin ecosystem.

https://xcancel.com/callebtc/status/2085024458012586286
Bitcoin code is safe.
The most audited code in the world has been under constant scrutiny by the best minds since 16 years.
The code is arguably kept simple just to avoid any hidden bug or negative feature.
Interacting with this code requires using many more codes: wallets, signing devices, cryptographic libraries, exchanges....
Those software are not secure, and prone to AI-driven exploit.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits..REWARDING, BEYOND LIMITS...
█████████████████████████
█████████████████████████
███████████▀▀░░▀█▄░░▀████
████████▀░░░░░░░░▀█▄░████
███████░░░░▄▄░░▄░░░▀█████
██████░░░░░▀▀▄██▀░░░░████
█████░░░██░▄██▀▄▄░░░█████
████░░░░░▄██▀░░▀▀░░██████
█████▄░░▀█▀░██░░░░███████
████░▀█▄░░░░░░░░▄████████
████▄░░▀█▄░░▄▄███████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████▀░░▀░███████████
████████░░░▄░█░██████████
███████████▌▐██░█████████
███████████░███▌▐████████
██████████░█████░████████
██████▀░▄░▀███▀░▄░▀█████
█████░▄▀░░░░█░▄▀░░░░█████
█████░░░░░░░█░░░░░░░█████
██████▄░░░▄███▄░░░▄██████
█████████████████████████
█████████████████████████


























  PLAY NOW  
philipma1957
Legendary
*
Online Online

Activity: 4942
Merit: 12329


'The right to privacy matters'


View Profile WWW
Today at 01:53:04 AM
Last edit: Today at 02:35:54 AM by philipma1957
 #390

Personally, I think that the earlier table that was posted by Forsyth Jones is a good guideline for at least shooting for at least minimal levels of safety, especially if we want to shoot to have our levels to at least be in the orange, and probably better to be in the lighter orange rather than the darker orange, just to be safer, yet even if we land in the darker orange, we should not need to panic, even though we might want to consider if we might want to create a wee bit stronger variation and then move our coins to that stronger variation.

Below is a table showing the strength of each passphrase extension:


I think 32 years is secure enough for me  Cheesy

But even the 12 years variation of 8 characters are basically invulnerable for any practical purposes.

Just create a passphrase you like and can remember. I believe this is the lesson for everyone about this attack/scam

buy this

https://www.amazon.com/gp/product/B000I2FW2Q/ref=ox_sc_act_title_1?smid=ATVPDKIKX0DER&th=1


a set of 36 punches

next buy this

https://www.amazon.com/gp/product/B0GMH6LGJT/ref=ox_sc_act_title_1?smid=A1MDC9YLETZE7Z&th=1

30 washers

https://www.amazon.com/gp/product/B0FG2LRFZ2/ref=ox_sc_act_title_1?smid=A1FA0UJGUNVMLI&th=1

1/4 nuts and bolts


now here comes the important part.

go to the punch set and out of all 36 pick 20 letters and number see the photos



 




I picked those 20 because they are easy to see that they are different from each other

so.

A B D E F G H J M P

R S T V W Y Z 3 4 8

PUT THEM IN THIS




Move and rotate it a pull a bar out with closed eyes

pretend it was the Z    1 in 20 shot.  put it in the mixer rotate flip spin pull new letter or number say 3

so Z3 is 1 in 400 put it back again and again

pretend YOU do 12 times get the passphrase below

Z3B                    1 IN                        8,000
Z3BG                   1 IN                    160,000
Z3BGP                 1 IN                  3,200,000
Z3BGPT               1 IN                64,000,000
Z3BGPT8             1 IN                1,280,000,000
Z3BGPT8Y           1 IN                25,600,000,000
Z3BGPT8YY           1 IN             512,000,000,000
Z3BGPT8YYA         1 IN        10,240,000,000,000
Z3BGPT8YYA3       1 IN      204,800,000,000,000
Z3BGPT8YYA3S     1 IN        4,096,000,000,000,000                12 PULLS OF THE 20 PUNCHES IS       4,096 X 1 TRILLION
Z3BGPT8YYA3S4   1 IN       81,920,000,000,000,000               13 PULLS OF THE 20 PUNCHES IS       81,920 X 1 TRILLION
Z3BGPT8YYA3S4H   1 IN  1,638,400,000,000,000,000              14 PULLS OF THE 20 PUNCHES IS   1,638,400 X 1 TRILLION
Z3BGPT8YYA3S4H8 1 IN 32,768,000,000,000,000,000             15 PULLS OF THE 20 PUNCHES IS  32,768,000 X 1 TRILLION

SO A 15 character passphrase is pretty okay it is 65 bits  which is crack able but it is after the seed of 12 or 20 or 24 words

a 20 character passphrase built with 20 punches is 85 bits

a 24 character passphrase built wit 20 punches is 102 bits.

cold card seed at 40 bits is around 1,099,511,627,776 when compared to the 15 character passphrase above

 15 characters is 32,768,000 harder

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|..BTC......XMR...
..USDT.....LTC...
....Fees  0.8%.....
Forsyth Jones
Legendary
*
Offline

Activity: 1988
Merit: 2191


I love Bitcoin!


View Profile WWW
Today at 03:01:28 AM
Merited by Pmalek (3), vapourminer (1), JayJuanGee (1)
 #391

It's vacation time in most countries in the Northern Hemisphere. I believe there are still many people in a similar situation.

Some people tend to take a few days to be 100% offline, so they may not even be aware of this whole problem yet. They may have already run out of coins and not even know it.

I think that in a week, when many people return from vacation, they will have a sad surprise. More reports will emerge and the numbers will increase.

At this point, I have stopped trusting these hardware wallets. Are there even any option left for really good hardware wallets?
What's the point of having one if they can have such bugs which can sweep out millions of funds in such a short time.
I know it's not the users fault here but the company has to take the responsibility here for the mess up and ensure their users get their funds back.
Who knows, it can even be an insider job. That's always the first thought I get when such hacks happen.

I think 32 years is secure enough for me 

But even the 12 years variation of 8 characters are basically invulnerable for any practical purposes.

Just create a passphrase you like and can remember. I believe this is the lesson for everyone about this attack/scam

The question is this: imagine you bought a hardware wallet. You depend on the developer's competence, on 3rd parties who review the code for you (if it has an open source license), meanwhilte, the manufactors pursue certification licenses for their devices (usually for secure elements and microcontrollers). The guy chose Coldcard, at this moment, he's enjoying a vacation on some paradise island (little does he know it might be the last time) and has no idea of the sea of disappointment he is about to dive into.

A simple act that could SAVE his savings:

- Having thought about ways to prevent himself in case of disasters like this, things like: carrying a seed phrase (encrypted, steganographic or not) with him, he could move the funds to a new wallet if he knew about this targeted hack on Coldcard.

- He could have added a strong passphrase, but let's say he knows the passphrase by heart, but he doesn't have the seed phrase with him, he needs the both things (remembering that he is on a family trip, visiting the Eiffel Tower, etc), he failed again.

- Memorizing the seed phrase and passphrase? You always have to maintain it (doing spaced repetition, keep reminding yourself from time to time so you don't forget, and have them written down somewhere, separately).

How would you solve this problem if you had a coldcard and haven't been affected yet? Imagine yourself in his shoes, what would you do? How to solve this problem?

The passphrase, you either need to keep it somewhere (geographically far from the seed phrase) or have it memorized. Another way is to keep it discreetly in your agenda (paper) or in your leather wallet.

Many people (myself included) own more than one hardware wallet or some form of airgapped storage (even better, as long as you know what you're doing). This would also prevent a lot of problems, since people practically entrusted their lives to it.

The Coldcard case made it clear, at the very least, that creating a wallet, writing down the seed phrase, depositing some funds, and only opening the wallet 10 years later IS NOT ENOUGH. A strategy for acting during trips is more than necessary.



This is also good, as long as it's kept at home, in a safe, on the property, etc. but what about when traveling? What about the risk of someone who knows what this is about seizing it and asking questions in a not-so-friendly way?  Roll Eyes

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits..REWARDING, BEYOND LIMITS...
█████████████████████████
█████████████████████████
███████████▀▀░░▀█▄░░▀████
████████▀░░░░░░░░▀█▄░████
███████░░░░▄▄░░▄░░░▀█████
██████░░░░░▀▀▄██▀░░░░████
█████░░░██░▄██▀▄▄░░░█████
████░░░░░▄██▀░░▀▀░░██████
█████▄░░▀█▀░██░░░░███████
████░▀█▄░░░░░░░░▄████████
████▄░░▀█▄░░▄▄███████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████▀░░▀░███████████
████████░░░▄░█░██████████
███████████▌▐██░█████████
███████████░███▌▐████████
██████████░█████░████████
██████▀░▄░▀███▀░▄░▀█████
█████░▄▀░░░░█░▄▀░░░░█████
█████░░░░░░░█░░░░░░░█████
██████▄░░░▄███▄░░░▄██████
█████████████████████████
█████████████████████████


























  PLAY NOW  
JayJuanGee
Legendary
*
Offline

Activity: 4536
Merit: 14847


Self-Custody is a right. Say no to "non-custodial"


View Profile
Today at 03:46:15 AM
Merited by purple_sparkles (1)
 #392

Personally, I think that the earlier table that was posted by Forsyth Jones is a good guideline for at least shooting for at least minimal levels of safety, especially if we want to shoot to have our levels to at least be in the orange, and probably better to be in the lighter orange rather than the darker orange, just to be safer, yet even if we land in the darker orange, we should not need to panic, even though we might want to consider if we might want to create a wee bit stronger variation and then move our coins to that stronger variation.
Below is a table showing the strength of each passphrase extension:

I think 32 years is secure enough for me  Cheesy
But even the 12 years variation of 8 characters are basically invulnerable for any practical purposes.

Just create a passphrase you like and can remember. I believe this is the lesson for everyone about this attack/scam

For sure, we probably do not want to give away our exact set up, except maybe amongst friends and sometimes even on the internet we have to be a bit careful in terms of describing our own set-up, security or our inclinations of what we believe might be "good enough." 

I have been warming up more towards the ideas of several members who proclaim that there is quite a bit of value in future-proofing my own chosen set up a bit more, yet I am not going to point out which areas, exactly, in which I might be currently vulnerable - since even with my own set ups, I have variations in their level of security, and some of them I am considering whether to upgrade sooner or later, and it can surely take a long time to upgrade, as we mentioned in another post in which there was a description of maybe doing 50-ish different transfers after the set up had been made.

At the same time, we might have our own ways of keeping back up records in regards to what our set-ups might be, so then we might have to update our various back up records too.  It can be difficult (and problematic) to keep too much information in our heads, even if we might think that some of the information is basic, such as the location of each of the pieces of information that might be needed to reconstruct our seed... and then are those pieces of information complete enough or do they include any changes that  we might have had chosen to make.

This particular attack had a bit of its own uniqueness in terms of potentially creating a bit of a time-buffer for anyone who had any amount of security beyond the various defaults that were built into Cold Card, and that seemed to be one of the problems with the assumptions around cold card, since they seemed to have so many security features within their device.  Accordingly, there were likely a lot of normies (and even somewhat seemingly sophisticated bitcoiners) presuming that since Cold Card had so many various security options that their default must have had at least had some levels of protection, which that was a "HOLY SHIT!!!!" kind of a revelation to find out that Cold Card's default protections (at such a low level as the random number generator) was so damned vulnerable.

1) Self-Custody is a right.  Resist being labelled as: "non-custodial" or "un-hosted."  2) ESG, KYC & AML are attack-vectors on Bitcoin to be avoided or minimized.  3) How much alt (shit)coin diversification is necessary? if you are into Bitcoin, then 0%......if you cannot control your gambling, then perhaps limit your alt(shit)coin exposure to less than 10% of your bitcoin size...Put BTC here: bc1q49wt0ddnj07wzzp6z7affw9ven7fztyhevqu9k
fillippone
Legendary
*
Online Online

Activity: 2982
Merit: 21223


Duelbits.com - Rewarding, beyond limits.


View Profile WWW
Today at 06:47:41 AM
Merited by tvbcof (2)
 #393

Firstly, a very beautiful visualization of the Coldcard Hack:




This particularity resonates with the thread I created a long time ago:

There are 2^256 private keys out there: how big is that number?

Regarding the hack, I was almost rushing to rebuild my setup from scratch. But not being affected, I had a double thoughts about refactoring my cold wallet in a multisig with very convolute password.
I think the major risk here is the user: having a too complicated setup puts the operational risk very high, and I am thinking if this is the real risk, when the entropy used to generate the seed is sufficient.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits..REWARDING, BEYOND LIMITS...
█████████████████████████
█████████████████████████
███████████▀▀░░▀█▄░░▀████
████████▀░░░░░░░░▀█▄░████
███████░░░░▄▄░░▄░░░▀█████
██████░░░░░▀▀▄██▀░░░░████
█████░░░██░▄██▀▄▄░░░█████
████░░░░░▄██▀░░▀▀░░██████
█████▄░░▀█▀░██░░░░███████
████░▀█▄░░░░░░░░▄████████
████▄░░▀█▄░░▄▄███████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████▀░░▀░███████████
████████░░░▄░█░██████████
███████████▌▐██░█████████
███████████░███▌▐████████
██████████░█████░████████
██████▀░▄░▀███▀░▄░▀█████
█████░▄▀░░░░█░▄▀░░░░█████
█████░░░░░░░█░░░░░░░█████
██████▄░░░▄███▄░░░▄██████
█████████████████████████
█████████████████████████


























  PLAY NOW  
Cricktor
Legendary
*
Offline

Activity: 1582
Merit: 4209



View Profile
Today at 07:06:05 AM
Merited by vapourminer (1)
 #394

...
I don't want to diminish the idea of the punches and stamping stuff into metal.

What bothers me is the execution. Putting the punches in such a "tight" container won't mix them very well even when you rotate the container and pick punches blind-folded or with closed eyes. Do you really think humans pick punches in a completely random way out of such container even when they don't look at what they're doing?

There will very likely be some bias based on the initial placement of punches. It may look random and maybe doesn't really matter, but it's not any news that humans are commonly terrible at generating good entropy (by inventing some own procedures).

Use dice or a known way to throw coins where the latter could even compensate for biased coins or if you fear that your way of tossing coins introduces a bias by itself.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits..REWARDING, BEYOND LIMITS...
█████████████████████████
█████████████████████████
███████████▀▀░░▀█▄░░▀████
████████▀░░░░░░░░▀█▄░████
███████░░░░▄▄░░▄░░░▀█████
██████░░░░░▀▀▄██▀░░░░████
█████░░░██░▄██▀▄▄░░░█████
████░░░░░▄██▀░░▀▀░░██████
█████▄░░▀█▀░██░░░░███████
████░▀█▄░░░░░░░░▄████████
████▄░░▀█▄░░▄▄███████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████▀░░▀░███████████
████████░░░▄░█░██████████
███████████▌▐██░█████████
███████████░███▌▐████████
██████████░█████░████████
██████▀░▄░▀███▀░▄░▀█████
█████░▄▀░░░░█░▄▀░░░░█████
█████░░░░░░░█░░░░░░░█████
██████▄░░░▄███▄░░░▄██████
█████████████████████████
█████████████████████████


























  PLAY NOW  
ABCbits
Legendary
*
Offline

Activity: 3696
Merit: 10273



View Profile
Today at 08:08:23 AM
Last edit: Today at 08:26:56 AM by ABCbits
Merited by Pmalek (3), vapourminer (1), JayJuanGee (1), hosemary (1)
 #395

Bitcoin Red Team consists of 16 people who are working around the clock now and running security audits on Bitcoin code bases. According to their report, they have already made close to 5,000 findings and discovered what they believe are 85 critical and 635 high severity issues. They report these issues back to project owners and companies, and I think that's a great thing that has come out of this terrible situation. Whitehats and industry experts joining forces to help secure the wider Bitcoin ecosystem.

https://xcancel.com/callebtc/status/2085024458012586286

I have mixed thought about it. I can see OpenSats actually fund this person[1] and AFAIK OpenSats generally fund promising person and project. But i also worry about quality/accuracy of their finding. "27.5 hours in, we've filed 4,962 findings across 390 projects" from 16 people and some AI sounds too high/fast. Either way, we'll know how accurate are their findings, by looking at release note of wallet and other cryptocurrency software/library in next few months.

[1] https://opensats.org/blog/cashu-calle-receives-lts-grant

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits..REWARDING, BEYOND LIMITS...
█████████████████████████
█████████████████████████
███████████▀▀░░▀█▄░░▀████
████████▀░░░░░░░░▀█▄░████
███████░░░░▄▄░░▄░░░▀█████
██████░░░░░▀▀▄██▀░░░░████
█████░░░██░▄██▀▄▄░░░█████
████░░░░░▄██▀░░▀▀░░██████
█████▄░░▀█▀░██░░░░███████
████░▀█▄░░░░░░░░▄████████
████▄░░▀█▄░░▄▄███████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████▀░░▀░███████████
████████░░░▄░█░██████████
███████████▌▐██░█████████
███████████░███▌▐████████
██████████░█████░████████
██████▀░▄░▀███▀░▄░▀█████
█████░▄▀░░░░█░▄▀░░░░█████
█████░░░░░░░█░░░░░░░█████
██████▄░░░▄███▄░░░▄██████
█████████████████████████
█████████████████████████


























  PLAY NOW  
stompix
Legendary
*
Offline

Activity: 3710
Merit: 7282



View Profile WWW
Today at 08:19:20 AM
Merited by vapourminer (1), JayJuanGee (1)
 #396

I doubt they have planned it this way all along but indeed, it came at one of the worst times possible,
~
I think someone DID plan this carefully.  The first few batched transactions were executed almost simultaneously.  This means someone had to crack all the private keys, find the wallets with the largest balances, prepare and sign all the transactions, and just wait for the right time to execute.

But if they did prepare for that for let's say a few months...
Why did it take 3 days before the first major drain and the second one?
He wasted previous time in which news spread, probably not a lot of people were able to move their funds in the meantime but I'm pretty sure some did, so he lost money on that!

The first attack was on the 30th of June, Thursday, midday for some, the next one happened Friday night to Saturday, and the third one on Sunday.

Why did he or "they" wait for 3-4 days, depending on the timezone to drain them all?
The only explanation I can come is that they were actively still searching for victims during this time, they did not already have already the keys for all of them!

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|  BTC     XMR  
  DAI     LTC  
   Fees  0.8%    
mabji1
Newbie
*
Offline

Activity: 17
Merit: 0


View Profile
Today at 08:39:05 AM
 #397

I doubt they have planned it this way all along but indeed, it came at one of the worst times possible,
~
I think someone DID plan this carefully.  The first few batched transactions were executed almost simultaneously.  This means someone had to crack all the private keys, find the wallets with the largest balances, prepare and sign all the transactions, and just wait for the right time to execute.

But if they did prepare for that for let's say a few months...
Why did it take 3 days before the first major drain and the second one?
He wasted previous time in which news spread, probably not a lot of people were able to move their funds in the meantime but I'm pretty sure some did, so he lost money on that!

The first attack was on the 30th of June, Thursday, midday for some, the next one happened Friday night to Saturday, and the third one on Sunday.

Why did he or "they" wait for 3-4 days, depending on the timezone to drain them all?
The only explanation I can come is that they were actively still searching for victims during this time, they did not already have already the keys for all of them!


It is highly improbable that they had all the keys from day one and simply waited for "fun." The most logical conclusion is a combination of staggered data exfiltration and a deliberate rate-limiting strategy to stay under the radar of on-chain monitoring tools for as long as possible.
Numan467
Jr. Member
*
Offline

Activity: 55
Merit: 9


View Profile
Today at 09:17:38 AM
Merited by JayJuanGee (1)
 #398

Bitcoin Red Team consists of 16 people who are working around the clock now and running security audits on Bitcoin code bases. According to their report, they have already made close to 5,000 findings and discovered what they believe are 85 critical and 635 high severity issues. They report these issues back to project owners and companies, and I think that's a great thing that has come out of this terrible situation. Whitehats and industry experts joining forces to help secure the wider Bitcoin ecosystem.

https://xcancel.com/callebtc/status/2085024458012586286

I have mixed thought about it. I can see OpenSats actually fund this person[1] and AFAIK OpenSats generally fund promising person and project. But i also worry about quality/accuracy of their finding. "27.5 hours in, we've filed 4,962 findings across 390 projects" from 16 people and some AI sounds too high/fast. Either way, we'll know how accurate are their findings, by at release note of wallet and other cryptocurrency software/library in few next months.

[1] https://opensats.org/blog/cashu-calle-receives-lts-grant
It was the numbers that caught my attention. Almost 5,000 results on 390 projects in less than a day is pretty cool, but also makes me wonder how much hand checking was done. While AI can scan code very quickly, proof that it is indeed serious flaw usually takes a lot longer.
That is why I agree with @ABCbits about waiting before judging the results. Project added value if wallet developers begin to fix bugs from these reports. However, if most of reports turn out to be wrong alarms, then developers may spend much of time working on reports other than working on real safety flaws. While it is good news that OpenSats is supporting the project, the amount of the results will be more important than the amount.
montaga
Sr. Member
****
Offline

Activity: 1470
Merit: 312


Freedom, Natural Law


View Profile
Today at 09:22:38 AM
 #399

Amazing how many people still not understand Bitcoin after all the years, embarrassing.


https://bitcointalk.org/index.php?topic=5389446.0
https://bitcointalk.org/index.php?topic=5323755.0

Alternative blank alu plate and engraving pin
https://www.amazon.com/Credit-Anodized-Aluminum-Metal-Blanks/dp/B074W385L8?th=1
.

♣ 𝙱𝚊𝚗𝚔 𝚜𝚎𝚌𝚛𝚎𝚌𝚢 𝚊𝚌𝚝 𝚖𝚞𝚜𝚝 𝚋𝚎 𝚊𝚋𝚘𝚕𝚒𝚜𝚑𝚎𝚍, 𝚘𝚗𝚕𝚢 𝚌𝚛𝚒𝚖𝚒𝚗𝚊𝚕𝚜 𝚑𝚊𝚟𝚎 𝚜𝚘𝚖𝚎𝚝𝚑𝚒𝚗𝚐 𝚝𝚘 𝚑𝚒𝚍𝚎.
𝚃𝚑𝚎𝚛𝚎 𝚒𝚜 𝚗𝚘 𝚕𝚎𝚐𝚒𝚝𝚒𝚖𝚊𝚝𝚎 𝚛𝚎𝚊𝚜𝚘𝚗 𝚏𝚘𝚛 𝚒𝚝𝚜 𝚎𝚡𝚒𝚜𝚝𝚎𝚗𝚌𝚎.🍟
Wind_FURY
Legendary
*
Offline

Activity: 3738
Merit: 2213



View Profile
Today at 09:36:18 AM
Merited by vapourminer (1), Stalker22 (1)
 #400


--SNIP--

Shower thought. The ColdCard situation might be an inside job.

Quote


  👀

Warning, LONG POST copied from X. Does this make a case that it's an inside job?

Quote

Retirement Attack: Coldcard Sold Us a Warning

CEO who dismissed the threat by name, a pseudonym that turned out to be the CTO, two warnings four years apart, and a company whose entire answer was that it would have already known.

They Sold the Warning

On 21 December 2020 (22 Dec UTC), replying to Bitcoin security researcher Michael Flaxman, who had just posted about hardware wallets eliminating the risk of a retirement attack during seed generation and Rodolfo Novak “NVK” addressed the question head on.

- My money is on people screwing themselves out of their BTC before any vendor tries a retirement attack.
  Alternatively people could just use dice Wink

Ten weeks later on 1 March 2021, Coinkite’s CTO shipped a commit titled “First pass w/ libNgU” that routed Coldcard’s seed generation into a software pseudorandom number generator seeded from the device’s serial number and a clock.
NVK’s threat model in December 2020 pointed outward. Users were the risk. Vendors were not. Ten weeks after he said so his co-founder shipped the vendor version and it stayed shipped for five years.

The dice line is the other half: He offered it with a wink and it turned out to be the only thing standing between his customers and total loss.

Oops They sold it again

On 10 October 2021: seven months into shipping the defect the official Coldcard account posted that Coldcard makes retirement attacks impossible.

Someone in the replies asked what a retirement attack was.
Coinkite answered it themselves. It’s when the project makers could have a “bug” in the entropy generation for later retrieval.

Their scare quotes not mine. By then somebody had already tried to warn them.

The escape hatch was optional on purpose

Look at what that 2021 post was actually selling: Dice rolls. The documentation it linked to still opens with a sentence that reads differently today; if you don’t trust the TRNGs in your COLDCARD, you can introduce your own randomness with dice. At least ninety nine rolls for a full 256 bits.

But that setting is “opt in” and sits behind the default that looks fine from the outside.It asks the user to press buttons a hundred times to avoid trusting the manufacturer.

Every person who still has their bitcoin took that option, or used a (strong) passphrase, or ran multisig. Every person who got swept trusted the default.

That is the architecture a retirement attack requires. You can’t make the mitigation mandatory because then there’s nothing left to collect. You can’t omit it because the paranoid customers will ask why. So you offer it, document it, recommend at least ninety nine rolls, and let the default do the work. When it detonates the record shows you warned your users, therefore neatly covering your tracks if this was an inside job.

Coinkite built the structure, warned of the attack it enables, and then pushed a firmware with a backdoor for five years.

The pseudonym was the CTO

Here is the detail that reorganizes everything else.

Coldcard’s crypto ran through libngu, a library on GitHub under the account switck. About six stars. Maintained by one person: apparently pseudonymous. When James O’Beirne audited the firmware that’s what he found: a random number generation for a device holding billions of dollars in bitcoin backed up to what he described as a shady library with six stars maintained solely by a pseudoanon.

Dylan LeClair ran GPG verification against that repo and published the output. James O’Beirne then published a full census: fifty-eight commits authored as Switck carry a good signature from Peter D. Gray’s personal key: the same key that signs nineteen other commits in the same repo under Gray’s own name. The key is expired and the signatures are still good. The RNG selection commit is among them. Signed 28 January 2021, switck published no GPG key of they/their own.

Peter Gray is Coinkite’s CTO and cofounded the company with NVK. Coinkite has never had more than about twenty people and by most accounts Gray wrote the large majority of the firmware.

So switck was Coinkite’s own CTO. Cryptographically proven; not inferred. Every outside reviewer who looked at libngu saw an unaudited third party dependency by an anonymous stranger and worried about supply chain risk. Coinkite’s own people knew it was in house and had no reason to review it as external code.

The use of a pseudonym here means that no one audited that chunk of code. Outsiders assumed insiders had. Insiders knew there was no outside to check.

They were warned in 2021

Five weeks after the commit on 7 April 2021 someone in a Telegram group flagged the change. Their post sounds in retrospect like a man watching a car roll toward a cliff. Roughly quoting:

“The 4.0.x firmware was a radical deviation from every firmware since 2018, with all crypto and BIP39 related code replaced by libNgU. Is it was wise to replace the many-years-old TrezorCrypto code, which has been heavily scrutinized by white hats like Johoe and penetration tested by wallet.fail, with something new. “switck” might be a talented pseudonymous coder, but the commit history is bad” (and they linked to it)

The post sat in a Coldcard Telegram group under an embedded NVK tweet about the 4.0.x upgrade: the same tweet in which he said he doesn’t check Telegram.

That warning posted five weeks after the defect shipped was correct in every single way. Five years and four months before the money starting mysteriously leaving peoples cold storage.

They were warned again in 2025

In May 2025 James O’Beirne audited coldcard/firmware. He wanted to establish conclusively where the RNG was sourced from. He traced it into libngu, found the six-star pseudonymous repo, and was confused about why it was there at all. Because linking libsecp256k1 from Python is easy and that appeared to be the stated purpose.

He sent Coinkite a report. In his own words: he had “doubts about whether the true RNG was actually in use”, and he pointed out that the “hardcoded yasmarang constants in libngu were sloppy”. He advised them to rip the whole thing out and link against libsecp256k1 directly.

That’s the bug! He identified the exact library, constants, and the question of whether the hardware RNG was being used. And he told them to remove it!

Coinkite’s answer, as O’Beirne reports, was that if something was wrong “we’d already know about it by now” and that everything was properly configured for the real boards.

That is not a technical response. That is an appeal to their own reputation offered to a developer who had just traced the code and found otherwise. And in a separate post O’Beirne identifies Peter Gray “@DocHex” as “the same guy that shrugged off my report of the possibility of the defect in May 2025.” The same Gray who wrote the library. The same Gray who was switck.

There was follow-up of a kind. A Signal group titled “LNGU Clean up” was created on 23 May 2025, with members shown as “n,” “Doc,” “andres,” and one other. Doc-hex is Gray. “n” is NVK. So Coinkite formed a group about cleaning up libNgU and named it after the problem. Then they shipped… nothing! Absolutely no fix fourteen months. The group’s messages were set to disappear after four weeks so whatever was said there is gone, just like the bitcoins that were in hundres of hard working peoples Coldcards.

O’Beirne blames himself for not pushing harder. He calls not following up rigorously a horrible mistake on his part.
Hold that next to Coinkite’s public explanation which is that an attacker probably used AI to find something nobody could reasonably have caught. The developer who caught it is apologizing. The company that was responsibly informed is blaming the clankers.

He didn’t know what was in his own crypto library

Coinkite’s technical postmortem is worth reading in full because its author is if nothing else candid.

He explains that he set the macro to zero believing it meant neither implementation would be compiled. That is not what it does. And he writes that the bulk of the randomness in the device was coming from a PRNG he did not know was in the codebase at all because it arrived through a submodule. Meanwhile the carefully written hardware TRNG code was still being used, but only by accident and only for things that didn’t matter.
He is describing a submodule he wrote.

The company selling immunity to entropy tampering did not know which random number generator its product used for five years. The man who says he didn’t know is the man who authored both sides of the mistake. And the answer when it finally surfaced was that libngu XORed one software PRNG against a second software PRNG seeded from constants hardcoded in public source. Two deterministic streams XORed together produce a deterministic stream. The built in health check rejects adjacent repeated values which any nondegenerate PRNG passes without effort.
Those are the same hardcoded yasmarang constants O’Beirne told them to rip out.

Coldcard seeds generated in that window contained no physical randomness whatsoever.

They bought a press release not an audit

Peter Todd says Coinkite brought him on in early 2014 as “Chief Naysayer”: an advisory role. Years before the first hardware wallet existed there was a press release. By his account he was given nothing to work on: no tasks, no work to bill for, and then the arrangement quietly dropped. He says it’s still on a LinkedIn profile that he hasn’t logged into in a over decade.

His assessment now in his own words: “if they had kept him on and asked him to audit the codebases, there’s a good chance he’d have spotted the practices at issue, and maybe eighty million dollars wouldn’t have been stolen”. He puts that audit at roughly $50k and asks what Coinkite spent on podcast sponsorships instead.
The company announced that a famous skeptic was reviewing them and then never asked him to review anything. The press release was the product.

All the things they said

Coinkite’s public position throughout this crisis has been that it had no idea the flaw existed until the day the money started moving. Two documented warnings and a Signal group named after the problem say otherwise.

NVK’s stated position on attribution: they “don’t have full attribution or scope yet”, and they “won’t speculate until the technical evaluation is complete”. Coinkite then suggested publicly that the attacker likely used an automated tool to comb the public source and find the flaw before they did. That’s speculation. This propisition rests on absolutely no evidence. And it happens to be the only theory of the case in which nobody at Coinkite knew and nobody at Coinkite failed.

You can decline to speculate or you can float the hypothesis that clears you. Doing both inside the same week tells you which one was the priority.

Coinkite told customers it kept purchase data for 90 days. When breach notifications went out they reached buyers going back to 2019. Challenged, the company pointed at a policy page, conceded it has no deletion schedule and said the addresses would be kept “for now.”

A verifiable lie caught within a few days of the largest breach of trust in hardware wallet history, and on a question where the answer was easily verifiable. This speaks volumes of NVK’s character.


The fix broke too

On 31 July Coinkite shipped out an emergency firmware update. Three days later a contributor opened pull request #692 against the Coldcard firmware repo, reporting that the hotfix had introduced a new failure on the hardware RNG path.

The entropy fix itself is correct: rng_get() now resolves to the board’s true hardware accessor instead of the software fallback. But rng_get_or_fault() had no recovery path for the STM32’s RNG seed error flags. After a seed error the peripheral stops delivering data and the shipped code never clears the condition; so every later call times out and raises OSError(EFAULT) for the rest of that boot. Because rng_get() now sits on the keypad scan path (an interrupt callback that runs before login) that exception lands before the PIN prompt. Power cycling clears the flags; if the error recurs on the next boo: the user is locked out of the upgrade menu too and the device is essentially bricked.

The original report overstated the stickiness. The flags do not survive a power cycle: so this is not a permanent brick from a single glitch. It is still a serious regression: an emergency patch for a five-year review failure shipped fast that can take the device down before the user can enter a PIN.

#692 was closed in favor of #693, a cleaner recovery sequence from a Coinkite contributor, with #698 as the Mk3 follow-up. Both were still open when this was written. The point is not that nobody noticed. The point is that the first hotfix for a five-year entropy failure needed a second round of patches within days. Giving the attacker MORE TIME to execute sweeping funds from vulnerable wallets.

What they’ll say

Three objections are coming, and they’re the ones I’d make if I was NVK for sure
Galaxy says the waves may not share an operator. True: and irrelevant to the part that matters. Galaxy’s caution is about waves two, three, and four. Once wave one went loud on 30 July the vulnerability was public property and anyone with tooling could pile in. That’s what waves three and four look like. Wave one is the one that tells you something. 1,082 BTC out of 1,195 addresses in 41 minutes with seeds already computed; executed by someone who had been preparing while nobody else on earth knew there was anything to prepare for.

The bug was publicly findable: anyone could have found it. Two people found it in public and said so, in 2021 and in 2025. Both were told it was fine. The set of people who knew this was a live question before 30 July is not the general public. It’s a short list and Coinkite was on it.

A mass sweep is too loud for an insider. It’s too loud for the rational insider who bleeds quietly over years and never triggers a referral. The loudness cuts against a careful inside job. It does not erase the warnings, the Signal group, or their response that if something was wrong they’d already know.

What I think happened

Somebody inside that company knew what was sitting in the codebase and knew what it was worth.
Look at the timeline:

Ten weeks before the bug shipped the CEO publicly waved off the idea that a vendor would ever run a retirement attack and pointed at dice as the alternative. His co-founder and CTO then wrote a crypto library under a pseudonymous GitHub account with about six stars, and shipped the device’s entire randomness path through it.

Five weeks later someone flagged the swap in a Coldcard Telegram group and was ignored.

Seven months after that the company marketed immunity to the exact attack class the defect enables and made the only reliable defense an “opt in”.

Four years in: a Bitcoin developer audited the firmware found the library, named the hardcoded constants, told them to remove the whole thing, and was told they’d already know if something was wrong. They opened a Signal group called “LNGU Clean up,” set the messages to disappear, and shipped nothing. Coins were leaving through 695 transactions nobody noticed. Then somebody who had been precomputing seeds for a long time took 1,082 BTC in 41 minutes.

Each of these has an innocent explanation available. All of them stacked in the same direction inside a company of twenty people. This is not a run of bad luck. Inverse Hanlon’s razor exists for exactly this shape: when incompetence needs that many separate coincidences to line up the same way the incentive is the simpler explanation.

I can’t say for 100% it was an inside job of course: every document that would definititevly prove it belongs to them. The “LNGU Clean up” thread, whatever survived a four week expiration. Whatever code review they ran and when. The commit history around anyone who touched rng.c after May 2025. Roughly 600 attacker addresses are already in front of federal investigators and Coinkite says it’s cooperating. Cooperation is cheap. Coinkite has apologized, published a postmortem, shipped a fix that needed a second round of patches within days, and offered its customers not a single sat as compensation.

The man who found this in May 2025 is publicly apologizing for not pushing harder. And NVK is blaming AI.
The people who still have their bitcoins are the ones who read Coldcard’s own documentation, saw the line offering them a way to distrust the manufacturer’s randomness, and took it. Nobody told them that one sentence in the docs was the difference between keeping their money and losing it.

Holla atchya boi,
-IH

https://x.com/inverse_hanlon/status/2084689208627925384


Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 [20] 21 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!