Bitcoin Forum
August 10, 2026, 02:14:17 PM *
News: COLDCARD users only: critical vulnerability risks funds stored on COLDCARD devices; immediate action required
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 [23] 24 25 »  All
  Print  
Author Topic: Large-scale Coldcard compromise (1596 BTC stolen so far)  (Read 8268 times)
CucakRowo
Hero Member
*****
Offline

Activity: 1036
Merit: 595


aka JAGEND.


View Profile
August 09, 2026, 02:44:40 AM
 #441

Two OP_Return messages brought tears to my eyes.

One said, ''Please return at least some of the stolen money".

Another said, "Suicide tonight if you don't give me back what I worked 12 years, my 6.4 BTC".

Who knows how many dreams these people were carrying in their heart? Maybe this was someone's dream of giving their children a secure little future. Maybe someone had been saving that money hoping they could pay for their aging parents treatment. Maybe some people spent their entire live working to achieve this 3 or 4 BTC, and then, in a matter of minute it was all gone.

There are probably countless stories of heartbreak behind those transaction that we will never hear about.
So many tears, so much fear and desperation, all hidden behind blockchain addresses and transaction ID.

How long can that hacker carry the burden of all these broken lives on his conscience! Will he really close his eyes and sleep peacefully!

collardelay
Newbie
*
Offline

Activity: 24
Merit: 11


View Profile
August 09, 2026, 04:58:55 AM
 #442

Two OP_Return messages brought tears to my eyes.

One said, ''Please return at least some of the stolen money".

Another said, "Suicide tonight if you don't give me back what I worked 12 years, my 6.4 BTC".

Who knows how many dreams these people were carrying in their heart? Maybe this was someone's dream of giving their children a secure little future. Maybe someone had been saving that money hoping they could pay for their aging parents treatment. Maybe some people spent their entire live working to achieve this 3 or 4 BTC, and then, in a matter of minute it was all gone.

There are probably countless stories of heartbreak behind those transaction that we will never hear about.
So many tears, so much fear and desperation, all hidden behind blockchain addresses and transaction ID.

How long can that hacker carry the burden of all these broken lives on his conscience! Will he really close his eyes and sleep peacefully!


You would be surprised how evil people can be.
Italian Panic
Hero Member
*****
Offline

Activity: 1106
Merit: 762


NO DEPO CODE VEGAR7, NO KYC Casino


View Profile WWW
August 09, 2026, 06:48:38 AM
 #443

A very interesting read on an improvement idea that could solve the self custody trilemma:



Waiting for some commercial solution to implement it.

I’m sure that generating secure seeds and passphrases will be quite a challenge in light of what happened with ColdCard, but this solution also requires relying on third parties and provides a phone number, so it could compromise the privacy of those who don’t have a front man. I think we’ll need to look a little further ahead; we’ll need to find a real solution for self-custody as we understand it today and for our long- and very long-term goals.

██████
██
██

████████████████
███████████████
█████████████
█████████████▄▄████▄▄████▄▄███████▌██▄▄████▄██
████████████▄██▀▀▀▀██▄██▄███▀███████▄██▀▀▀▀███
██████████▐██▄▄▄▄▄▄██▌▐██▀███████▌▐███████▐██
████████████▐██▀▀▀▀▀▀▀▀▐██▄███████▌▐██▄████▐██
█████████████▀██▄▄▄▄█████▀███▄▄▄██▀██▀██▄▄▄▄███
██████████████▀▀▀▀▀▀██████▀▀▀▀▀▀▄▌███▀▀▀▀▀▀▀
████████████████████████████▄███▄██
███████████████████████████▀█████▀










██
██
██████
▄▄███████▄▄
▄███████████████▄
▄███████████████████▄
▄█████████████████████▄
▄███████████████████████
████████████████████████
█████████████████████████
████████████████████████
▀███████████████████████▀
█████████████████████▀
▀███████████████████▀
▀███████████████▀
▀▀███████▀▀
 
  150 FS NO DEPOSIT BONUS ..... Subscribe to Our Telegram ( > ) .....   PLAY NOW   
joker_josue
Legendary
*
Offline

Activity: 2478
Merit: 7351


**In BTC since 2013**


View Profile WWW
August 09, 2026, 08:05:56 AM
Merited by vapourminer (1)
 #444

How long can that hacker carry the burden of all these broken lives on his conscience! Will he really close his eyes and sleep peacefully!

Well, it seems that the coins, after being stolen, were not touched again.
Is the hacker still thinking about what to do, or is he feeling guilty?

The thing is, at first it all looks very nice and generates a lot of excitement, but when you start to see the real impact, things change a bit.
I'm not saying he's going to return the stolen coins, but at least he might be going through a period of reflection.



I’m sure that generating secure seeds and passphrases will be quite a challenge in light of what happened with ColdCard, but this solution also requires relying on third parties and provides a phone number, so it could compromise the privacy of those who don’t have a front man. I think we’ll need to look a little further ahead; we’ll need to find a real solution for self-custody as we understand it today and for our long- and very long-term goals.

Perhaps we need to look again at the master Satoshi and see how he created his wallets.

They've been sitting there for over 15 years without suffering any problems, despite probably being the most attacked wallets in the world.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
LoyceV
Legendary
*
Offline

Activity: 4130
Merit: 22433


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
August 09, 2026, 08:27:01 AM
Merited by vapourminer (1)
 #445

The thing is, at first it all looks very nice and generates a lot of excitement, but when you start to see the real impact, things change a bit.
I'm not saying he's going to return the stolen coins, but at least he might be going through a period of reflection.
That's why I came up with this theory:
Or could it just be an amateur who's in way over his head? Someone who accidentally stumbled upon this weakness, and suddenly ended up with $70 million in stolen funds?

Perhaps we need to look again at the master Satoshi and see how he created his wallets.
They've been sitting there for over 15 years without suffering any problems, despite probably being the most attacked wallets in the world.
Satoshi used Send to Pubkey transactions, whilch may become quantum vulnerable in the future. That's not the best example for the long term. But his random generation must have been pretty good Smiley

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
joker_josue
Legendary
*
Offline

Activity: 2478
Merit: 7351


**In BTC since 2013**


View Profile WWW
August 09, 2026, 08:38:14 AM
 #446

The thing is, at first it all looks very nice and generates a lot of excitement, but when you start to see the real impact, things change a bit.
I'm not saying he's going to return the stolen coins, but at least he might be going through a period of reflection.
That's why I came up with this theory:
Or could it just be an amateur who's in way over his head? Someone who accidentally stumbled upon this weakness, and suddenly ended up with $70 million in stolen funds?

I don't think he's exactly an amateur, but I understand the point.

I can imagine the situation: he discovers the flaw and goes to test it to see if it's really true.
Start running the script, perhaps with the goal of verifying if your own wallets are affected. Within minutes, they begin targeting third-party wallets with hundreds of BTC being transferred to your account.
I believe the first reaction will be one of shock, but at the same time, incredibly exciting.
Suddenly 1000 BTC appears in your account. You must be ecstatic in your basement.
You're probably already thinking of a thousand and one things you'll want to do with that money.

As the hours tick by and the news breaks, the dilemma begins: how are you going to move the money without getting caught? I stole hundreds of BTC from people who saved their whole lives. What have I done!?

Now you may be debating whether to return everything, return part of it, or ignore the matter altogether.



Perhaps we need to look again at the master Satoshi and see how he created his wallets.
They've been sitting there for over 15 years without suffering any problems, despite probably being the most attacked wallets in the world.
Satoshi used Send to Pubkey transactions, whilch may become quantum vulnerable in the future. That's not the best example for the long term. But his random generation must have been pretty good Smiley

I'm talking about the seed (so to speak), because to date that's what's guaranteeing the security of these coins.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
philipma1957
Legendary
*
Offline

Activity: 4942
Merit: 12336


'The right to privacy matters'


View Profile WWW
August 09, 2026, 10:38:43 AM
 #447

How long can that hacker carry the burden of all these broken lives on his conscience! Will he really close his eyes and sleep peacefully!

Well, it seems that the coins, after being stolen, were not touched again.
Is the hacker still thinking about what to do, or is he feeling guilty?

The thing is, at first it all looks very nice and generates a lot of excitement, but when you start to see the real impact, things change a bit.
I'm not saying he's going to return the stolen coins, but at least he might be going through a period of reflection.



I’m sure that generating secure seeds and passphrases will be quite a challenge in light of what happened with ColdCard, but this solution also requires relying on third parties and provides a phone number, so it could compromise the privacy of those who don’t have a front man. I think we’ll need to look a little further ahead; we’ll need to find a real solution for self-custody as we understand it today and for our long- and very long-term goals.

Perhaps we need to look again at the master Satoshi and see how he created his wallets.

They've been sitting there for over 15 years without suffering any problems, despite probably being the most attacked wallets in the world.

He could keep them still for a month or two and then send them back on the grounds that cold card company is crushed for the idiocy that caused the issue in the first place.

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|..BTC......XMR...
..USDT.....LTC...
....Fees  0.8%.....
LoyceV
Legendary
*
Offline

Activity: 4130
Merit: 22433


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
August 09, 2026, 10:48:34 AM
Merited by vapourminer (1), Foxpup (1)
 #448

I can imagine the situation: he discovers the flaw and goes to test it to see if it's really true.
Start running the script, perhaps with the goal of verifying if your own wallets are affected. Within minutes, they begin targeting third-party wallets with hundreds of BTC being transferred to your account.
I believe the first reaction will be one of shock, but at the same time, incredibly exciting.
Suddenly 1000 BTC appears in your account. You must be ecstatic in your basement.
You're probably already thinking of a thousand and one things you'll want to do with that money.
And then he realizes he can't spend the money. To use it, he'll need to launder it. To launder it, he'll need criminal connections. Having $100 million in your name and looking for criminal connections makes you a massive target, not to mention the thousands of robbed people worldwide who can drink your blood. Meeting the wrong person: death. Getting caught: life in prison. Returning the money: practically impossible now because someone else will take it instantly.

Quote
I'm talking about the seed (so to speak), because to date that's what's guaranteeing the security of these coins.
I wasn't around back then, but I assume Bitcoin-qt back then used the computer's random number generator. Satoshi didn't reuse addresses, so he simply created (give or take) 20,000 different random private keys. There was no "seed" yet.

He could keep them still for a month or two and then send them back
To return the stolen funds, he'll need to identify each owner first, and you can bet many scammers will claim to be the owners. No single person can do that on his own.

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
Pumpsta
Member
**
Online Online

Activity: 80
Merit: 15


View Profile
August 09, 2026, 10:54:08 AM
 #449

Man, so many holders are devastated by this now Undecided Is all the compromised btc gone now or the hacker's still running through seeds? If the hack is so easy then why isn't there any collective race to act first so the btc ends in wallets of people who intend to return them to the affected owners?

Do not think dice rolls helped, those wallets do exist, and are also gone.

what do you mean even dice rolls don't help?? I kept reading about dice rolls being the best way to make a seed, they're not anymore?
fillippone
Legendary
*
Online Online

Activity: 2982
Merit: 21244


Duelbits.com - Rewarding, beyond limits.


View Profile WWW
August 09, 2026, 11:15:33 AM
 #450


He could keep them still for a month or two and then send them back
To return the stolen funds, he'll need to identify each owner first, and you can bet many scammers will claim to be the owners. No single person can do that on his own.

The addresses are now compromised.
Everyone could claim the ownership of the sending addresses (the private keys).
Identifiying the original and authentic owner is almost impossible (it would require checking upon the possession of the physical hw, something that looks very impractical to me).

Livingleged
Full Member
***
Offline

Activity: 280
Merit: 154



View Profile
August 09, 2026, 11:24:05 AM
 #451

As the hours tick by and the news breaks, the dilemma begins: how are you going to move the money without getting caught? I stole hundreds of BTC from people who saved their whole lives. What have I done!?

Now you may be debating whether to return everything, return part of it, or ignore the matter altogether.
Same thoughts actually, but I’m more particular about whether it’s  possible to even ignore the matter all together when the community’s eyes are on you ?. Now the attacker will be  more pressured except it was actually planned by a team to carry out the attack. Then they will wait for years probably when most people have forgotten about the wallet before they start moving the coins. Thats shitty to me because the internet doesn’t forgets.

Cricktor
Legendary
*
Offline

Activity: 1582
Merit: 4239



View Profile
August 09, 2026, 11:35:02 AM
Last edit: August 09, 2026, 11:45:49 AM by Cricktor
Merited by LoyceV (6), vapourminer (4), fillippone (3), JayJuanGee (1), joker_josue (1)
 #452

He could keep them still for a month or two and then send them back on the grounds that cold card company is crushed for the idiocy that caused the issue in the first place.
As much as I wished that Coinkite gets crushed and vanishes for their anti-open-source stance, arrogance, ignorance and failure to produce safe firmware, it will take a while and they likely need to get sued to step off the hardware wallet market.

I'm not so confident that customers will speak up with their wallets and refuse to ever buy a ColdCard again. Ledger crap is still sold by who-knows-what volume and buyers accept (or simply don't know) that Ledger firmware has code to exfiltrate your Ledger wallet's seed. Maybe potential customers will turn their eyes away from ColdCard, it's not guaranteed.

Stolen coins can't safely be returned to the compromised originating wallet because you have to assume the originating wallet is basically public, the entropy and encoding mnemonic recovery words aren't secret anymore. Someone else besides the original wallet owner and the thief might also know the mnemonic recovery words and hence would be able to move coins sent to the compromised wallet. (fillippone was faster)

It's going to be interesting how the thief or thieves will try to launder the stolen coins. I don't believe the criminals have any emotional strings to those they robbed. It's internet crime, you don't have to see or deal with your victims. All eyes are on the accumulating addresses of stolen coins.

knowngunman
Hero Member
*****
Online Online

Activity: 1428
Merit: 573



View Profile WWW
August 09, 2026, 11:36:25 AM
 #453

I can imagine the situation: he discovers the flaw and goes to test it to see if it's really true.
Start running the script, perhaps with the goal of verifying if your own wallets are affected. Within minutes, they begin targeting third-party wallets with hundreds of BTC being transferred to your account.
I believe the first reaction will be one of shock, but at the same time, incredibly exciting.
Suddenly 1000 BTC appears in your account. You must be ecstatic in your basement.
You're probably already thinking of a thousand and one things you'll want to do with that money.

As the hours tick by and the news breaks, the dilemma begins: how are you going to move the money without getting caught? I stole hundreds of BTC from people who saved their whole lives. What have I done!?

Now you may be debating whether to return everything, return part of it, or ignore the matter altogether.

Nah, he meant business. Considering the effort put on this, he did it deliberately.

Assuming it was a few wallets, I would agree with you on this but meh over thousands addresses? That's not testing. He's probably planning on next strategy. The incident attracts much attention, he might be waiting for as long as possible to let attention shifted before making a move. They know what they are doing, they know about risk management. You can not pull off something like this and rush decisions, you need time to figure out everything in order not to land in trouble.

I agree he's reflecting but definitely not thinking of returning it. He's reflecting on the next step. They are human with no conscience.

 
█▄
R


▀▀██████▄▄
████████████████
▀█████▀▀▀█████
████████▌███▐████
▄█████▄▄▄█████
████████████████
▄▄██████▀▀
LLBIT▀█ 
  TH#1 SOLANA CASINO  
████████████▄
▀▀██████▀▀███
██▄▄▀▀▄▄████
████████████
██████████
███▀████████
▄▄█████████
████████████
████████████
████████████
████████████
█████████████
████████████▀
████████████▄
▀▀▀▀▀▀▀██████
████████████
███████████
██▄█████████
████▄███████
████████████
█░▀▀████████
▀▀██████████
█████▄█████
████▀▄▀████
▄▄▄▄▄▄▄██████
████████████▀
........5,000+........
GAMES
 
......INSTANT......
WITHDRAWALS
..........HUGE..........
REWARDS
 
............VIP............
PROGRAM
 .
   PLAY NOW    
joker_josue
Legendary
*
Offline

Activity: 2478
Merit: 7351


**In BTC since 2013**


View Profile WWW
August 09, 2026, 12:34:36 PM
Merited by tvbcof (2)
 #454

Quote
I'm talking about the seed (so to speak), because to date that's what's guaranteeing the security of these coins.
I wasn't around back then, but I assume Bitcoin-qt back then used the computer's random number generator. Satoshi didn't reuse addresses, so he simply created (give or take) 20,000 different random private keys. There was no "seed" yet.

That's why he said "so to speak".

Back then, seeds weren't used. I had a wallet like that. 10 years later, I went back to that wallet and everything was there, all in order. Without seeds and "complex things".

Perhaps what's needed is to relearn how to build wallets without adding more and more extras.

I once read something very interesting: "The more security a person seeks, the less security they end up having. Confidence increases, and you become careless about simple things."




Nah, he meant business. Considering the effort put on this, he did it deliberately.

I don't know if such a great effort was needed at the beginning.

Entropy was quite low. The good fortune of quickly finding a wallet with substantial funds motivated him to go further and allocate more resources.

But of course, I don't think he's an amateur. It was certainly well-planned, but you can't have spent too much time planning, for fear of someone else discovering the flaw first.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
Lucius
Legendary
*
Offline

Activity: 4060
Merit: 7690



View Profile WWW
August 09, 2026, 01:19:29 PM
Merited by vapourminer (1), joker_josue (1)
 #455

Two OP_Return messages brought tears to my eyes.

One said, ''Please return at least some of the stolen money".

Another said, "Suicide tonight if you don't give me back what I worked 12 years, my 6.4 BTC".

Who knows how many dreams these people were carrying in their heart? Maybe this was someone's dream of giving their children a secure little future. Maybe someone had been saving that money hoping they could pay for their aging parents treatment. Maybe some people spent their entire live working to achieve this 3 or 4 BTC, and then, in a matter of minute it was all gone.

There are probably countless stories of heartbreak behind those transaction that we will never hear about.
So many tears, so much fear and desperation, all hidden behind blockchain addresses and transaction ID.

How long can that hacker carry the burden of all these broken lives on his conscience! Will he really close his eyes and sleep peacefully!


Do you think someone who clearly doesn't know what passphrase or multi-sig is knows how to insert a message into their transaction? My opinion is that most of these messages come from scammers who play the victim card in the hope that some rich donor will see it and send a big donation.



Well, it seems that the coins, after being stolen, were not touched again.
Is the hacker still thinking about what to do, or is he feeling guilty?
~snip~


Most people assume that it is a person, but isn't it possible that it is not a person but an advanced AI that was tasked with trying to hack a hardware wallet? Most people think that AI capabilities are what we see in popular models mainly from US companies - but the same companies and the US government itself have admitted that China, for example, has far more advanced AI models that are capable of much more than we can even imagine.

Wind_FURY
Legendary
*
Offline

Activity: 3738
Merit: 2215



View Profile
August 09, 2026, 01:25:15 PM
Merited by vapourminer (1)
 #456

I'm afraid this incident does reveal why most people won't properly custody their bitcoin, ever.

If it is required from people to roll dice, use a passphrase apart from a seed phrase, or engage in multi-vendor multi-sig setups for "extra security", I'm afraid most people who "believe" in Bitcoin's value proposition will just stick with an ETF from now on.

And to be frank with all of you, I'm starting to think this is very justifiable to a point.

Owning a Bitcoin ETF is not the same as owning Bitcoin!

What really needs to be done is for people to read or reread the Bitcoin white paper again, to understand or remember what Bitcoin is.


It's not, but if you're an older "boomer investor" who merely wants to invest $1,000,000, a large amount of money, in Bitcoin, then a Bitcoin ETF is probably the better option because,

You don't need to go through the preventive measures, especially if that person is not a very technical individual, and treats Bitcoin only as an investment.

Your investment secured by the ETF issuer, and by the legal system if the issuer breached its fiduciary duty.

Pumpsta
Member
**
Online Online

Activity: 80
Merit: 15


View Profile
August 09, 2026, 03:29:51 PM
 #457

Do you think someone who clearly doesn't know what passphrase or multi-sig is knows how to insert a message into their transaction? My opinion is that most of these messages come from scammers who play the victim card in the hope that some rich donor will see it and send a big donation.
That's not excluded for sure but I know what a passphrase is and my wallet wasn't covered by one until very recently. You'd think this kind of compromise doesn't happen this easy, Coldcard's been around as a trustworthy company for how long now... I guess most people are alright with just a seed, I can't recall being told by my wallet that a passphrase strengthens the security of my seed, I mean who tf even thinks about the possibility of getting a low security seed generation from a hw anyway Huh
Cookdata
Legendary
*
Offline

Activity: 1764
Merit: 1452


Not Your Keys, Not Your Bitcoin


View Profile
August 09, 2026, 03:42:07 PM
 #458

As the hours tick by and the news breaks, the dilemma begins: how are you going to move the money without getting caught? I stole hundreds of BTC from people who saved their whole lives. What have I done!?

Now you may be debating whether to return everything, return part of it, or ignore the matter altogether.
Now the attacker will be  more pressured except it was actually planned by a team to carry out the attack. Then they will wait for years probably when most people have forgotten about the wallet before they start moving the coins. Thats shitty to me because the internet doesn’t forgets.

Forget? Who forgets their years of investment only to be stolen by some random thieves on the internet in less than a week? This is no longer an individual case, it's now a global case that will remain active until there is a lead somewhere.
Many victims would have made a report to law enforcement in different parts of the world. $1m alone is too big to ignore, not to talk of $1m in 100 places.

I'm very sure Coldcard lawyers are going to be busy with the rest of the year with different lawsuits.

UmerIdrees
Hero Member
*****
Offline

Activity: 3038
Merit: 950



View Profile WWW
August 09, 2026, 04:52:20 PM
 #459

As the hours tick by and the news breaks, the dilemma begins: how are you going to move the money without getting caught? I stole hundreds of BTC from people who saved their whole lives. What have I done!?

Now you may be debating whether to return everything, return part of it, or ignore the matter altogether.
Now the attacker will be  more pressured except it was actually planned by a team to carry out the attack. Then they will wait for years probably when most people have forgotten about the wallet before they start moving the coins. Thats shitty to me because the internet doesn’t forgets.

Forget? Who forgets their years of investment only to be stolen by some random thieves on the internet in less than a week? This is no longer an individual case, it's now a global case that will remain active until there is a lead somewhere.
Many victims would have made a report to law enforcement in different parts of the world. $1m alone is too big to ignore, not to talk of $1m in 100 places.

I'm very sure Coldcard lawyers are going to be busy with the rest of the year with different lawsuits.

Aren't we underestimating the hacker here? He has been so clever to find this bug in Coldcard that wasn't detected before, and now we are assuming that the hacker will have a hard time cashing out those stolen BTC, and he will either end up in the wrong hands or get traced???

I am sure he must have already figured out how to get out of all this without getting noticed. He has a criminal mind, and we are just thinking that he will find trouble spending those bitcoins  Huh  I think we are too innocent to think like this, and if he is reading this, he must be laughing at us.

Webetcoins
Hero Member
*****
Offline

Activity: 2744
Merit: 558


View Profile
August 09, 2026, 05:21:59 PM
 #460

it seems that the coins, after being stolen, were not touched again.
Is the hacker still thinking about what to do, or is he feeling guilty?

The thing is, at first it all looks very nice and generates a lot of excitement, but when you start to see the real impact, things change a bit.
I'm not saying he's going to return the stolen coins, but at least he might be going through a period of reflection.
He is probably thinking of the best way for him to cash out all or at least some of those assets so that he can use them in real life. Just because he isn't touching the coins doesn't mean he is feeling remorse for what he did, because such people barely care about these things or have such feelings, if they did, they wouldn't do it in the first place. One could argue that those who get into doing such things are the ones who have suffered a lot themselves in life, but doesn't that make it even more logical for them to understand what it means to have nothing or to lose everything you have or have workeed for your entire life?

So, I think the reason why there is a delay in moving those funds is because the attacker knows that he has so many eyes on him, and he probably wouldn't want to make a silly mistake and get caught somehow, so he is surely exploring and researching all his options that he can use to convert his bitcoins either to another untraceable asset, or simply convert it to fiat and use it, because it obviously isn't his goal to just steal the funds and let it lying around in a wallet, but the most difficult thing in such attacks is not the attack itself but it is to use the funds after it.
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 [23] 24 25 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!