Bitcoin Forum
August 08, 2026, 10:35:37 AM *
News: COLDCARD users only: critical vulnerability risks funds stored on COLDCARD devices; immediate action required
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 [21] 22 »  All
  Print  
Author Topic: Large-scale Coldcard compromise (1485.77 BTC stolen so far)  (Read 7003 times)
kTimesG
Sr. Member
****
Offline

Activity: 924
Merit: 266


View Profile
August 07, 2026, 10:36:15 AM
Merited by vapourminer (1), JayJuanGee (1), Stalker22 (1)
 #401

So here's the real deal, not theoretical blah-blah (which got it wrong):

1. The entire attack was already over by Aug 2nd.
2. Most likely each wave belonged to a different entity.
3. There's most likely a lot of missed mini-waves or whatever (each block that mined TXs of more than 1 separate compromised account are unlikely to belong to same owner).

Why I am all but sure about this? I reversed engineer the actual process. The first compromised seed had its initial income address funded on March 18 2021, 19:11:04 GMT. That is exactly one day after v4.0.0 of the firmware was released. All of the accounts that I was able to detect (~ 2050) that still had a balance on Jul. 30 were already sweeped in the last week. That is more than 1200 accounts (more than half of all the compromised seeds) being moved in just the first 48 hours after first wave.

Or more practical: 10654 different addresses moved out funds in the last week. Which is a third of all addresses of all accounts.

The only thing left are three dust addresses totalling less than 1000 satoshis. Everything else is gone, so that explains why the attackers moved to weak passphrases; there was nothing else left to do. Do not think dice rolls helped, those wallets do exist, and are also gone.

I don't think it will be a long time before the security researchers will revise their numbers for the CC actual security bits (it is not even close to 40).

Note: this didn't take months of preparation or trillions of scans. It's simply just a catastrophic system failure on the firmware coder's part. The first attacker simply probably didn't bother to dig deeper, while the subsequent ones did.

vapourminer
Legendary
*
Offline

Activity: 5124
Merit: 6645


what is this "brake pedal" you speak of?


View Profile
August 07, 2026, 10:51:07 AM
Merited by JayJuanGee (1)
 #402

The Coldcard case made it clear, at the very least, that creating a wallet, writing down the seed phrase, depositing some funds, and only opening the wallet 10 years later IS NOT ENOUGH. A strategy for acting during trips is more than necessary.

many many decades ago i used to hide things like a PINs and other codes as phone numbers on a piece of paper. like Vivian xxx-xxx-xxxx would have the PIN for my Visa debit card or things along those lines.. door codes etc.

back then before smartphones no one looked twice at a phone list. now a printed phone list would probably be sus in itself.

now? need to hide 128 bits worth somewhere.

bitmover
Legendary
*
Online Online

Activity: 3122
Merit: 7658


Trêvoid █ No KYC-AML Crypto Swaps


View Profile WWW
August 07, 2026, 11:41:17 AM
 #403


I would rather just buy a hardware wallet and add a passphrase.

Or you can just flip a coin 256 times and add results to iancoleman.io

Dont need to buy anything too fancy

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|  BTC     XMR  
  DAI     LTC  
   Fees  0.8%    
sergiorus
Sr. Member
****
Offline

Activity: 994
Merit: 329



View Profile
August 07, 2026, 11:45:54 AM
Merited by vapourminer (1), JayJuanGee (1)
 #404

Coldcard Maker Coinkite Says It Will Publish Post-Mortem, Declines to Estimate Customer Losses

Bloomberg reported that Coinkite, the maker of the Coldcard Bitcoin hardware wallet, said it is focused on assisting customers affected by the security incident and will publish a post-mortem once its full investigation is complete, rather than speculate on the scale of customer losses. Coinkite said the privacy-focused design of its products prevents it from independently verifying external estimates of the amount stolen. Recent outside research has raised estimated losses from the attack to roughly $130 million.




Source: https://www.bloomberg.com/news/articles/2026-08-06/hacked-bitcoin-wallet-maker-declines-to-estimate-amount-lost


███████▄▄███▄███▄
███▄▄████████▌██
▄█████████████▐██▌
██▄███████████▌█▌
███████▀██████▐▌█
██████████████▌▌▐
████████▄███████▐▐
█████████████████
███████████████▄██▄
██████████████▀▀▀
█████▀███▀▀▀

▄▄▄██████▄▄▄███████▄▄▄
███████████████████████████
███▌█████▀███▌█████▀▀███████████▄▄▄▄▄▄▄▄
███▌█████▄███▌█████▄███▐███████████████████▄
▐████████████▀███████▄██████████▀▀▀▀▀▀▀▀████▀
▐████████████▄██▄███████████▌█████████▄████▀
▐█████████▀█████████▌█████████████▄▄████▀
██████████▄███████████▐███▌██▄██████▀
██████████████▀███▐███▌██████████████████████
████▀██████▀▀█████████▌███▀▀▀▀███▀▀▀▀▀▀▀████▌

█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
 
P R E M I E R   B I T C O I N   C A S I N O   &   S P O R T S B O O K
 

█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████

█▀▀









▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
98%
RTP


▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█









▀▀▀

█▀▀









▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
HIGH
ODDS


▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█









▀▀▀

██████
██
██
██
██
██
██
██
██
██▄▄▄▄
▀▀▀▀▀▀

███████████████████████████████
 
PLAY NOW
 

███████████████████████████████

██████
██
██
██
██
██
██
██
██
▄▄▄▄██
▀▀▀▀▀▀
Pmalek
Legendary
*
Offline

Activity: 3584
Merit: 9432



View Profile
August 07, 2026, 03:20:16 PM
 #405

I have mixed thought about it. I can see OpenSats actually fund this person[1] and AFAIK OpenSats generally fund promising person and project. But i also worry about quality/accuracy of their finding. "27.5 hours in, we've filed 4,962 findings across 390 projects" from 16 people and some AI sounds too high/fast. Either way, we'll know how accurate are their findings, by looking at release note of wallet and other cryptocurrency software/library in next few months.
A few posts down in the thread whose link I posted in my previous post, calle says that the severity of the findings has already been confirmed by (some) projects. They say that certain teams have upgraded while others have downgraded their software releases. I think it's going to be difficult to find out how much of an impact those findings had. Software is regularly updated and unless the developers publicly acknowledge calle's help, we won't know if it's a regular update, an update based on findings from their own team, or an update performed because of vulnerabilities and issues found by the Bitcoin Red Team.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
JayJuanGee
Legendary
*
Offline

Activity: 4536
Merit: 14847


Self-Custody is a right. Say no to "non-custodial"


View Profile
August 07, 2026, 06:35:00 PM
Merited by tvbcof (6), vapourminer (1)
 #406

Firstly, a very beautiful visualization of the Coldcard Hack:

This particularity resonates with the thread I created a long time ago:
There are 2^256 private keys out there: how big is that number?
Regarding the hack, I was almost rushing to rebuild my setup from scratch. But not being affected, I had a double thoughts about refactoring my cold wallet in a multisig with very convolute password.
I think the major risk here is the user: having a too complicated setup puts the operational risk very high, and I am thinking if this is the real risk, when the entropy used to generate the seed is sufficient.

I am finding it quite annoying how much the bitcoin podcast space had moved from single sig to multi-sig, and they are not even accepting that multi-sig can be a good practice for an individual (because it is too complicated blah blah blah).  It is a bit ridiculous how fast several of them seemed to have switched to throw self-custody under the bus.

So in some sense the podcast scene has been pumping the shit out of products that end up fucking up both the privacy and the self-sovereignty aspects of bitcoin.

There were quite a few guys on this forum proclaiming that Bitkey is an inferior product to regular hardware wallets (there is even a thread, I think that has not been active lately) because the Bitkey is not really a hardware wallet in the sense of privacy and self-sovereignty as we know hardware wallets to offer (or supposed to offer) since there seem to be several ways that coins can end up getting recovered through the Bitkey without the user's key even being involved.  At least, recently Bitkey added a screen, but still there seems to be a bit of theater in terms of what a bitcoin wallet should be (referring to privacy, self-sovereignty and security).

I think that self-custody by single sig and a strong passphrase and even self-custody multi-sig are still quite viable (and probably even preferable) paths - even though sometimes there could be multi-sig that would be shared amongst family members, which could work for some kinds of shared funds, and of course, in some business arrangements multi-sig within a group of key players of the business might also be quite practical for how to treat some of the funds.

I don't like the seeming recent push to give up self-autonomy or the abilities to act autonomously as the base case of bitcoin, even though there could be some cases in which a third key might be given to a 3rd party, but not as our ideas of what are base case uses of bitcoin.

...
I don't want to diminish the idea of the punches and stamping stuff into metal.
What bothers me is the execution. Putting the punches in such a "tight" container won't mix them very well even when you rotate the container and pick punches blind-folded or with closed eyes. Do you really think humans pick punches in a completely random way out of such container even when they don't look at what they're doing?

There will very likely be some bias based on the initial placement of punches. It may look random and maybe doesn't really matter, but it's not any news that humans are commonly terrible at generating good entropy (by inventing some own procedures).
Use dice or a known way to throw coins where the latter could even compensate for biased coins or if you fear that your way of tossing coins introduces a bias by itself.

I, personally, like the idea of using a deck of cards.  That is 52 possible outcomes as compared with 6 on the dice and 2 on a coin should allow for fewer draws. In theory, instead of rolling a dice 100 times, you could pick 45 cards for the same amount of entropy (I checked this through AI).  That saves a lot of labor.   Too bad hardware wallets do not have an option to choose playing cards for their entropy creation - even though some of us might be skeptical if the wallets are the ones inputting the supposed entropy.

To practice this idea of cards, I did go to the Github Repo of the Ian Coleman BIP39 Tool in order to try out the inputing of cards, and I had to ask AI to get assistance to make sure that I was setting it up (and doing) it correctly, so then I did a practice round of inputting my cards online (and the preference for security is to do it off-line), and it took me 61 draws to reach 256 bits of entropy, and also it was amazing that I had 27 duplicate draws (a few of them were cards I drew 3 times, such as the king of hearts 3 times and the king of spades 4 times, and I drew the jack of hearts two times, but those two times were twice in a row.

It still is a lot of work to help to ensure that the wallet is not screwing up entropy, so of course, using a tool like this still has to take some safeguards that the words are not being viewed by someone else - as compared with if we were to just have the 2048 words and to draw them from a hat.

By the way, since I had to draw cards 61 times in order to achieve 256 bits of entropy, I suppose that is not much different from rolling dice 100 times, since we could have 10 dice and then just roll 10 at a time 10 times in order to reach 100 rolls... so maybe my going through the exercise of drawing cards 61 times causes me to be less enthusiastic about cards as an entropy solution.

The only thing left are three dust addresses totalling less than 1000 satoshis. Everything else is gone, so that explains why the attackers moved to weak passphrases; there was nothing else left to do. Do not think dice rolls helped, those wallets do exist, and are also gone.

You believe that the dice rolls were not adding any entropy for those who ended up choosing the dice rolls, and that ColdCard's software was not accounting for the dice rolls for those who chose dice rolls - which supposedly 50 rolls would cause 128 bits of entropy and 100 rolls 256 bits of entropy.

1) Self-Custody is a right.  Resist being labelled as: "non-custodial" or "un-hosted."  2) ESG, KYC & AML are attack-vectors on Bitcoin to be avoided or minimized.  3) How much alt (shit)coin diversification is necessary? if you are into Bitcoin, then 0%......if you cannot control your gambling, then perhaps limit your alt(shit)coin exposure to less than 10% of your bitcoin size...Put BTC here: bc1q49wt0ddnj07wzzp6z7affw9ven7fztyhevqu9k
pbies
Sr. Member
****
Offline

Activity: 432
Merit: 272



View Profile
August 07, 2026, 07:50:34 PM
 #407

The PRNG flaw (#ifndef) bug could be from simple oversight by junior or even mid developer.

This happens tons of times in normal, corporational companies.

System works but details are seen later, too late.

Solution: outsider should check the code, always. This is expensive but the only way to grant good programs.

BTC: bc1qmrexlspd24kevspp42uvjg7sjwm8xcf9w86h5k
WellRozey
Jr. Member
*
Offline

Activity: 46
Merit: 32


View Profile
August 07, 2026, 08:02:10 PM
 #408

Correct me if ima wrong but this has never happened with hardware wallet before, this is the first time, not in this manner I believe, and crazy things is I've never heard anyone mentioned this ColdCard before, not even on this forum.

It's always Ledger, Trezor and few others, I'm shocked about how many people are using this HW, that numbers are very high, it's such as shame, I think that the born of AI makes things easier in both good and bad ways.

Hardware manufacturers should start using AI to their advantages too on every decisions they made with their products, finding vulnerability even when your security is very tight is the way to go now, because you just can never tell.
Stalker22
Legendary
*
Offline

Activity: 2324
Merit: 1621



View Profile
August 07, 2026, 08:26:44 PM
Merited by JayJuanGee (1)
 #409

The PRNG flaw (#ifndef) bug could be from simple oversight by junior or even mid developer.

This happens tons of times in normal, corporational companies.

System works but details are seen later, too late.

Solution: outsider should check the code, always. This is expensive but the only way to grant good programs.

Peter D. Gray (Doc-Hex) is not some junior, or even mid level developer.  He is the CTO and co-founder of Coinkite, a veteran developer with decades of experience, and the guy who wrote the vast majority of Coldcard firmware himself.  He literally set up a pseudonymous alt account (switck) on GitHub to write and merge libNgU code, and pass off his own commits as "peer-reviewed" using his own GPG signing keys.

Outsiders did try to warn them about code issues, and Coinkite brushed them off with pure arrogance.

█████████████████████████
███████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
███▀░░██████▀░▀████░░▀███
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
███▄░░██████░░████░░▄███
█████▄░░▀███░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
 ROOBET .██████. BET ON WORLD CUP  🗺 ⚽︎.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
|.
   BET NOW   
philipma1957
Legendary
*
Offline

Activity: 4942
Merit: 12333


'The right to privacy matters'


View Profile WWW
August 07, 2026, 10:09:05 PM
 #410


I would rather just buy a hardware wallet and add a passphrase.

Or you can just flip a coin 256 times and add results to iancoleman.io

Dont need to buy anything too fancy


I have the punches on hand cost = zero

and after careful study of the 36 punches I can use 32 of them.

32x32x32x32x32x32x32x32=1.0995×10¹²  or  1,099,511,627,776          1 washer of 8 characters

32x32x32x32x32x32x32x32=1.0995×10¹²  or  1,099,511,627,776         2nd washer 8 characters

32x32x32x32x32x32x32x32=1.0995×10¹²  or  1,099,511,627,776        3rd washer 8 characters


and 1,099,511,627,776 cube is exactly 121 bits for just the passphrase

and if you own a trezor I one some test your seed I did

my seed works for recovery

adding that  3 washer 24 chart passphrase cost some time and about 1 dollar for the washers.

I have the washers as back for the 20 word seed.

if you don't back the trezor up with a washer system (some type of back up) not too good.




▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|..BTC......XMR...
..USDT.....LTC...
....Fees  0.8%.....
kTimesG
Sr. Member
****
Offline

Activity: 924
Merit: 266


View Profile
August 07, 2026, 10:35:44 PM
 #411

You believe that the dice rolls were not adding any entropy for those who ended up choosing the dice rolls, and that ColdCard's software was not accounting for the dice rolls for those who chose dice rolls - which supposedly 50 rolls would cause 128 bits of entropy and 100 rolls 256 bits of entropy.

Oh, they were definitely accounted, but accounted to what's basically a zero-entropy state.
Transaction from the last wave 93651006580a975b on Aug. 2 spent from 9 distinct compromised CC, all of them used dice. Unless ofcourse someone owned 9 different CC and acted (but the use of a consolidation instead of separate TXs says something else).

I'm running some AI pre-post-mortem analysis, since there's way too much data. All I can say is that the losses are at least $ 142 million, if not more. It's also somewhat possible this bug was used before for years already. Actually, there's a real possibility that multiple users simply got the same seed over the years, due to the birthday paradox and the limited bounds.

Cookdata
Legendary
*
Online Online

Activity: 1764
Merit: 1438


Not Your Keys, Not Your Bitcoin


View Profile
August 07, 2026, 10:47:08 PM
 #412

Their device detected the sweeps and both of them are in the race for RBF transaction.
The hacker lose the race. They ended with paying fees 9,000 sat and receiving 1,000 sat losing 90% of the fund on miners fees.

There is a similar experimental video about Mk3 but with different objectives, the person created 5 different wallets using Mk3 Coldcard, the first wallet was generated using the insecure random number generator, the same seed phrase was used to generate 3 wallets with different passphrases and the last wallet which is the 5th was generated using the same seed phrase from a random account.



http://x.com/ColeTU/status/2085090397223637049

He funded the 5 generated addresses from each wallet with 10800 sats each https://mempool.space/tx/f6a0e25dfa9b03f4a45c65cddeebafb0ea50c9b2732febbafd9a7f40ecf7b7da to see which of the wallet is getting sweep first and it turns out that the insecured RNG which is the first wallet was swept immediately, he could have overide it with a new transaction and pay more fees too but his objective is to see how the scammers are moving the coins and if passphrase 1 word, 2 words or 3 are secured enough with an insucure RNG seed phrase.

So far, the first wallet is swept, and the sats are sitting in this address: https://mempool.space/address/bc1qunqajps4elc78m8fq7s7nglc6x80j49exheq78

The rest of the wallets with the same seed phrase and passphrases are intact, the same wallet with the same seed phrase but a random account is also intact. That means the scammers focus is on default accounts created from Mk3, they don't search all account derivations.



https://x.com/coletu/status/2085823098742317223

After 2 days and 2 hours, the insecure seed phrase with random account number (3459) was swept to this wallet address. https://mempool.space/address/bc1q4gj72x6zz3ax7q6fh4gefamcjjuhu6q0jpf03, apparently the attackers searches different accounts derivation path. I'm wondering how many billions or trillions of private keys they will be generating at this speed.

JayJuanGee
Legendary
*
Offline

Activity: 4536
Merit: 14847


Self-Custody is a right. Say no to "non-custodial"


View Profile
Today at 02:25:57 AM
 #413

You believe that the dice rolls were not adding any entropy for those who ended up choosing the dice rolls, and that ColdCard's software was not accounting for the dice rolls for those who chose dice rolls - which supposedly 50 rolls would cause 128 bits of entropy and 100 rolls 256 bits of entropy.
Oh, they were definitely accounted, but accounted to what's basically a zero-entropy state.
Transaction from the last wave 93651006580a975b on Aug. 2 spent from 9 distinct compromised CC, all of them used dice. Unless ofcourse someone owned 9 different CC and acted (but the use of a consolidation instead of separate TXs says something else).

I am not smart enough to know how the provided link shows that dice were used in order to create the seed words.

Of course, if there were fewer than 50 rolls, so for example, 25 dice rolls, then 64.62 bits of entropy would be provided, which might not be too difficult to crack, but still 64 bits is better than 40 bits.. .which is part of the reason that 50 rolls minimum were to allow for 128 bits of entropy, which is standard for a 12 word seed.

Maybe you are saying that there were dice rolls but fewer than 50 rolls?  maybe fewer than 25 rolls? 

You are saying also that no entropy was added by any dice rolls, so I would need to be explained the mechanics of how that would be based on if you are saying that there might have been an override of the Cold Card software that pushed it back to the 40 bits of entropy? or for some reason the cold card was not accepting the inputted dice roll entropy, even if it might have met the standard of 50 rolls for 12 words or 100 rolls for 24 words.

1) Self-Custody is a right.  Resist being labelled as: "non-custodial" or "un-hosted."  2) ESG, KYC & AML are attack-vectors on Bitcoin to be avoided or minimized.  3) How much alt (shit)coin diversification is necessary? if you are into Bitcoin, then 0%......if you cannot control your gambling, then perhaps limit your alt(shit)coin exposure to less than 10% of your bitcoin size...Put BTC here: bc1q49wt0ddnj07wzzp6z7affw9ven7fztyhevqu9k
joker_josue
Legendary
*
Offline

Activity: 2478
Merit: 7338


**In BTC since 2013**


View Profile WWW
Today at 07:23:16 AM
 #414

The Coldcard case made it clear, at the very least, that creating a wallet, writing down the seed phrase, depositing some funds, and only opening the wallet 10 years later IS NOT ENOUGH. A strategy for acting during trips is more than necessary.

Yes, today we can reach that conclusion. But until two weeks ago, that wasn't what was expected to be necessary.

In reality, this is still not the case, as we continue to see coins that are over 10 years old, intact and safe. Coins that we know belong to people who have already died or to people who lost their seed, remain quietly in their place.

Meuserna said something accurate:
I wish more Bitcoiners understood: the device is not the wallet. The seed is the wallet, because the seed generates the addresses and keys.

The only way to be prepared anywhere in the world is to always have your seed with you.
How many of us have all the seeds with us 365 days a year, always?

Yes, today we might have to start making plans to act at any moment. But, unfortunately, until 2 weeks ago, 99.9% of users not imagined that going on a 2-week vacation would require taking their seed.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
NotATether
Legendary
*
Offline

Activity: 2422
Merit: 10111


┻┻ ︵㇏(°□°㇏)


View Profile WWW
Today at 07:26:21 AM
 #415

The Coldcard case made it clear, at the very least, that creating a wallet, writing down the seed phrase, depositing some funds, and only opening the wallet 10 years later IS NOT ENOUGH. A strategy for acting during trips is more than necessary.

The necessary step is, and I'll keep yelling this from rooftops until it reaches mass adoption, to generate your own seed phrase yourself, without any hardware wallet.

And also make a BIP39 passphrase for your seed.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
BlackHatCoiner
Legendary
*
Offline

Activity: 2114
Merit: 10008


Cross Chain Crypto Swap


View Profile
Today at 07:32:36 AM
 #416

I'm afraid this incident does reveal why most people won't properly custody their bitcoin, ever.

If it is required from people to roll dice, use a passphrase apart from a seed phrase, or engage in multi-vendor multi-sig setups for "extra security", I'm afraid most people who "believe" in Bitcoin's value proposition will just stick with an ETF from now on.

And to be frank with all of you, I'm starting to think this is very justifiable to a point.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
joker_josue
Legendary
*
Offline

Activity: 2478
Merit: 7338


**In BTC since 2013**


View Profile WWW
Today at 07:39:17 AM
 #417

I'm afraid this incident does reveal why most people won't properly custody their bitcoin, ever.

If it is required from people to roll dice, use a passphrase apart from a seed phrase, or engage in multi-vendor multi-sig setups for "extra security", I'm afraid most people who "believe" in Bitcoin's value proposition will just stick with an ETF from now on.

And to be frank with all of you, I'm starting to think this is very justifiable to a point.

Owning a Bitcoin ETF is not the same as owning Bitcoin!

What really needs to be done is for people to read or reread the Bitcoin white paper again, to understand or remember what Bitcoin is.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
BlackHatCoiner
Legendary
*
Offline

Activity: 2114
Merit: 10008


Cross Chain Crypto Swap


View Profile
Today at 07:57:42 AM
 #418

Owning a Bitcoin ETF is not the same as owning Bitcoin!
Obviously, but what most people want to get from Bitcoin is appreciating value overtime. This is what I think is what most people want.

I really hope people aren't into Bitcoin just for the appreciating value aspect, and they also appreciate the fact that nobody can take it away from you without your permission, but I'm just afraid that through the current chaos, it is very difficult to support this claim, considering the average person does not know 99% of what most people in here know about self-custody. Most people will just not roll a dice.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
LoyceV
Legendary
*
Offline

Activity: 4130
Merit: 22423


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
Today at 08:07:50 AM
Last edit: Today at 09:00:07 AM by LoyceV
 #419

some people have a non passphrase wallet as a decoy with passphrases behind it.
I wonder how many people realize that in this case, a "decoy" wallet have increased the risk, as it tells the attacker they found a used seed phrase. That gives them the possibility to start brute-forcing the passphrase. If you would have used the weak seed phrase only in combination with a passphrase, it would have been many orders of magnitude more difficult to find.

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
sergiorus
Sr. Member
****
Offline

Activity: 994
Merit: 329



View Profile
Today at 09:50:09 AM
 #420

Someone on Twitter [1] did their own investigation and is claiming a possible inside job.

It's a thread of many tweets, the link is here


The OP tweet:

Quote
I did my own investigation because I obviously don't trust them.

What I found is that the external dependency of the firmware with the critical vulnerability hidden in it was written by CoinKite's CTO
@DocHex
 pretending to be someone else.

All of the following can be verified:








[1] https://x.com/oomahq/status/2085717166884618584


███████▄▄███▄███▄
███▄▄████████▌██
▄█████████████▐██▌
██▄███████████▌█▌
███████▀██████▐▌█
██████████████▌▌▐
████████▄███████▐▐
█████████████████
███████████████▄██▄
██████████████▀▀▀
█████▀███▀▀▀

▄▄▄██████▄▄▄███████▄▄▄
███████████████████████████
███▌█████▀███▌█████▀▀███████████▄▄▄▄▄▄▄▄
███▌█████▄███▌█████▄███▐███████████████████▄
▐████████████▀███████▄██████████▀▀▀▀▀▀▀▀████▀
▐████████████▄██▄███████████▌█████████▄████▀
▐█████████▀█████████▌█████████████▄▄████▀
██████████▄███████████▐███▌██▄██████▀
██████████████▀███▐███▌██████████████████████
████▀██████▀▀█████████▌███▀▀▀▀███▀▀▀▀▀▀▀████▌

█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
 
P R E M I E R   B I T C O I N   C A S I N O   &   S P O R T S B O O K
 

█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████

█▀▀









▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
98%
RTP


▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█









▀▀▀

█▀▀









▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
HIGH
ODDS


▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█









▀▀▀

██████
██
██
██
██
██
██
██
██
██▄▄▄▄
▀▀▀▀▀▀

███████████████████████████████
 
PLAY NOW
 

███████████████████████████████

██████
██
██
██
██
██
██
██
██
▄▄▄▄██
▀▀▀▀▀▀
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 [21] 22 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!