Bitcoin Forum
August 10, 2026, 04:31:08 PM *
News: COLDCARD users only: critical vulnerability risks funds stored on COLDCARD devices; immediate action required
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 [24] 25 »  All
  Print  
Author Topic: Large-scale Coldcard compromise (1596 BTC stolen so far)  (Read 8307 times)
pbies
Sr. Member
****
Offline

Activity: 435
Merit: 272



View Profile
August 09, 2026, 05:33:02 PM
 #461

XMR (Monero) is no longer usable on exchanges, so he could use ZCash or just swap chunks in Exodus wallet to other crypto, mix it and pay out.

BTC: bc1qmrexlspd24kevspp42uvjg7sjwm8xcf9w86h5k
sergiorus
Sr. Member
****
Offline

Activity: 994
Merit: 331



View Profile
August 09, 2026, 05:44:57 PM
 #462

XMR (Monero) is no longer usable on exchanges, so he could use ZCash or just swap chunks in Exodus wallet to other crypto, mix it and pay out.

What do you mean by "not usable"?

It's still listed on a plenty of centralised exchanges with decent liquidity as well as on DEXs but with questionable liquidity if that's what you meant.


███████▄▄███▄███▄
███▄▄████████▌██
▄█████████████▐██▌
██▄███████████▌█▌
███████▀██████▐▌█
██████████████▌▌▐
████████▄███████▐▐
█████████████████
███████████████▄██▄
██████████████▀▀▀
█████▀███▀▀▀

▄▄▄██████▄▄▄███████▄▄▄
███████████████████████████
███▌█████▀███▌█████▀▀███████████▄▄▄▄▄▄▄▄
███▌█████▄███▌█████▄███▐███████████████████▄
▐████████████▀███████▄██████████▀▀▀▀▀▀▀▀████▀
▐████████████▄██▄███████████▌█████████▄████▀
▐█████████▀█████████▌█████████████▄▄████▀
██████████▄███████████▐███▌██▄██████▀
██████████████▀███▐███▌██████████████████████
████▀██████▀▀█████████▌███▀▀▀▀███▀▀▀▀▀▀▀████▌

█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
 
P R E M I E R   B I T C O I N   C A S I N O   &   S P O R T S B O O K
 

█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████

█▀▀









▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
98%
RTP


▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█









▀▀▀

█▀▀









▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
HIGH
ODDS


▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█









▀▀▀

██████
██
██
██
██
██
██
██
██
██▄▄▄▄
▀▀▀▀▀▀

███████████████████████████████
 
PLAY NOW
 

███████████████████████████████

██████
██
██
██
██
██
██
██
██
▄▄▄▄██
▀▀▀▀▀▀
joker_josue
Legendary
*
Offline

Activity: 2478
Merit: 7351


**In BTC since 2013**


View Profile WWW
August 09, 2026, 06:03:25 PM
Merited by JayJuanGee (1)
 #463

Do you think someone who clearly doesn't know what passphrase or multi-sig is knows how to insert a message into their transaction? My opinion is that most of these messages come from scammers who play the victim card in the hope that some rich donor will see it and send a big donation.

I think one thing has nothing to do with the other.

Aside from the most paranoid (and rightfully so), the vast majority of people didn't add a 25th word to their seed created in a hardware wallet, considered reliable by the overwhelming majority of the community.

Otherwise, we'll be jeopardizing the entire seed system, which also doesn't make sense.

Therefore, a person not having the passphrase does not mean that they had little knowledge about Bitcoin.




Most people assume that it is a person, but isn't it possible that it is not a person but an advanced AI that was tasked with trying to hack a hardware wallet? Most people think that AI capabilities are what we see in popular models mainly from US companies - but the same companies and the US government itself have admitted that China, for example, has far more advanced AI models that are capable of much more than we can even imagine.

That's a plausible scenario. I'd never thought of that. Could some AI be running loose, stealing money, and even the AI ​​creators themselves don't know about it?

We're already entering the realm of conspiracy theory.   Roll Eyes




Aren't we underestimating the hacker here? He has been so clever to find this bug in Coldcard that wasn't detected before, and now we are assuming that the hacker will have a hard time cashing out those stolen BTC, and he will either end up in the wrong hands or get traced???

I am sure he must have already figured out how to get out of all this without getting noticed. He has a criminal mind, and we are just thinking that he will find trouble spending those bitcoins  Huh  I think we are too innocent to think like this, and if he is reading this, he must be laughing at us.

So, I think the reason why there is a delay in moving those funds is because the attacker knows that he has so many eyes on him, and he probably wouldn't want to make a silly mistake and get caught somehow, so he is surely exploring and researching all his options that he can use to convert his bitcoins either to another untraceable asset, or simply convert it to fiat and use it, because it obviously isn't his goal to just steal the funds and let it lying around in a wallet, but the most difficult thing in such attacks is not the attack itself but it is to use the funds after it.

Time is everything with this type of hack. The more time passes, the harder it is to get rid of the coins, not the other way around.

The longer he waits, the less things get "forgotten," and the better prepared blockchain analysts are to track these coins. The entire community, including exchanges, swaps, and the like, has become better prepared to catch any movement of these coins.

He's already missed the window of opportunity to move without being caught. Now, every step he takes is under surveillance.

Of course, this doesn't mean they won't try to withdraw the money at any time, but the longer it goes on, the more difficult it will be.

That's why I'm saying this: even the hacker himself wasn't expecting to be so successful. Otherwise, as soon as he had acquired the first coins, he would have immediately sent them to mixes and swaps to break their trail.

Perhaps he had already planned this, but the news broke too quickly, leaving him with no room for maneuver.

I'm not saying that he is naive or ingenuous. I'm simply presenting the scenario where the hacker who carried out the attack wasn't expecting the success they had, and was left unsure of what to do. Because stealing 10 BTC is one thing, stealing 1000 BTC is quite another; the whole plan changes.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
Stalker22
Legendary
*
Offline

Activity: 2324
Merit: 1631



View Profile
August 09, 2026, 06:40:47 PM
Merited by JayJuanGee (1)
 #464


He could keep them still for a month or two and then send them back
To return the stolen funds, he'll need to identify each owner first, and you can bet many scammers will claim to be the owners. No single person can do that on his own.

The addresses are now compromised.
Everyone could claim the ownership of the sending addresses (the private keys).
Identifiying the original and authentic owner is almost impossible (it would require checking upon the possession of the physical hw, something that looks very impractical to me).

Even verifying possession of the physical HW will not be definitive proof.  It is theoretically possible for someone in possession of the ColdCard HW to recreate the wallet by importing a compromised seed.  How would that differ from the original wallet of the real victim?

I think on-chain history is the only real proof.  To verify a claim, someone would have to trace where the funds originally came from - like an CEX withdrawal, or from some other KYC-ed account.  Doing that manual forensics for thousands of separate victim addresses is an insane amount of work though.

█████████████████████████
███████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
███▀░░██████▀░▀████░░▀███
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
███▄░░██████░░████░░▄███
█████▄░░▀███░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
 ROOBET .██████. BET ON WORLD CUP  🗺 ⚽︎.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
|.
   BET NOW   
JayJuanGee
Legendary
*
Online Online

Activity: 4536
Merit: 14850


Self-Custody is a right. Say no to "non-custodial"


View Profile
August 09, 2026, 06:51:48 PM
 #465

You are saying also that no entropy was added by any dice rolls, so I would need to be explained the mechanics of how that would be based on if you are saying that there might have been an override of the Cold Card software that pushed it back to the 40 bits of entropy?

It's not 40 bits of entropy, more like 23 (or even less, CC would know better of their die cutting parameters). Watching the official YouTube easy guide "5 minutes setup" of a fresh CC adds some 6 additional bits. Each dice adds around 2 bits on top of this. So that's only around 2 to 3 billion guesses for all seeds out of all entropies + one dice rolls. A laptop can break that in an hour.

You are probably not wrong in your presumption, that even the guys who did dice rolls did not do a sufficient quantity of dice rolls, and I already mentioned my understanding that 100 plus dice rolls adds 256 bits of entropy, 50 plus dice rolls adds 128 bits of entropy, 25 plus dice rolls adds 64 bits of entropy and lower quantity of rolls would add lower amounts of entropy... ~2.5 bits per dice roll.

And, yeah, Cold Card software probably should not have allowed the setting up a wallet without a minimum quantity of extra entropy, perhaps even 25 plus might have had been enough, but maybe they should have had set the bare minimum quantity of dice rolls to a higher number like 30 plus, which would be around 72 bits of entropy, and even that might not have had been enough as a bare minimum amount, since allowing people to do it would mean that people would do the bare minimum, which is what happened, since there are examples of people not doing any dice rolls or just doing a few dice rolls or just making up their dice roll numbers.

The only way to be prepared anywhere in the world is to always have your seed with you.
How many of us have all the seeds with us 365 days a year, always?
If that were actually necessary, we should consider the whole setup to be terribly wrong and faulty. I find this very very wrong to have to carry my mnemonic seeds with me all the time. Sorry, no, this should NOT be necessary! And it is not necessary if we knew that entropy generation wasn't screwed up completely.

Apparently there's more due diligence needed to verify that entropy generation isn't flawed. Easier said, than done, though...

I must say, I'm genuinely surprised how badly a hardware wallet vendor screwed this up like Coinkite did. I thought light-hearted that this shouldn't be possible because it's such a basic and important functionality to NOT screw up the random stuff when you have TRNGs available. I'm still puzzled...

Another reason that a person might need to carry their seed words would be if there might end up being som difficulties crossing a border or maybe some other way that a person's hardware wallet might become compromised, in the event that they are traveling with their hardware wallet.  There may be instances that some guys might want to wipe their device when crossing certain borders.  There also could be instances in which their device might get stolen, lost or confiscated, so then they might want to be able to race to get  to their seed words to be able to sweep the funds in any main wallet or in any hidden wallet(s).

Pick another 10 words from the bowl of paper strips. That's your passphrase.

Have you ever tried to transact with a hardware wallet?  It will frequently require the passphrase to be re-entered, especially if a certain amount of time passes between transactions. 

Accordingly, I am not sure what advantage comes from having to type 10 words each time as compared with maybe having a passphrase that might have some quasi-random string of around 15-ish characters that include numbers, letters, cap letters and symbols.

3. Back up your seed and passphrase on metal.

4. Store your seed and passphrase somewhere secure. Somewhere only you have access to. Preferably 2 places, separate.

I am perfectly fine with the two places idea, even though practically, there are likely some guys who are quite challenged to have two places that are sufficiently within their control.

6. Get a small safe to keep in your home, where you'll store any documentation that needs to be written down. Document everything for your setup, even if only to help yourself remember "How'd I generate this seed? Why'd I set it up this way?"

7. Get home automation and put a sensor on the safe, to send you instant notifications if it is opened or moved. Aqara makes this easy and cheap. On sale, you can get an Aqara hub & sensors for under $50.

What if your house burns down?  I understand the document is separate from the seed, yet if you have the seed without the documents, is the seed still going to be useful?

1) Self-Custody is a right.  Resist being labelled as: "non-custodial" or "un-hosted."  2) ESG, KYC & AML are attack-vectors on Bitcoin to be avoided or minimized.  3) How much alt (shit)coin diversification is necessary? if you are into Bitcoin, then 0%......if you cannot control your gambling, then perhaps limit your alt(shit)coin exposure to less than 10% of your bitcoin size...Put BTC here: bc1q49wt0ddnj07wzzp6z7affw9ven7fztyhevqu9k
asUHWEceyc
Full Member
***
Offline

Activity: 170
Merit: 194

dekleptocraticizationismist


View Profile WWW
August 09, 2026, 07:06:15 PM
 #466

The thing is, at first it all looks very nice and generates a lot of excitement, but when you start to see the real impact, things change a bit.
I'm not saying he's going to return the stolen coins, but at least he might be going through a period of reflection.
That's why I came up with this theory:
Or could it just be an amateur who's in way over his head? Someone who accidentally stumbled upon this weakness, and suddenly ended up with $70 million in stolen funds?

Perhaps we need to look again at the master Satoshi and see how he created his wallets.
They've been sitting there for over 15 years without suffering any problems, despite probably being the most attacked wallets in the world.
Satoshi used Send to Pubkey transactions, whilch may become quantum vulnerable in the future. That's not the best example for the long term. But his random generation must have been pretty good Smiley

Surprisingly good for a Windows XP VM

But, a big bag of private keys also has certain advantages

Also-

How many NVK proximal influencer-podcaster-types (bent, odell, etc) and their investment projects (1031) that funded coinkite lost money in this thing? What about secondary corporate operators that used coldcards for key handholding services?  

Did they "know better" or get a heads up?
Meuserna
Sr. Member
****
Offline

Activity: 345
Merit: 616


View Profile WWW
August 09, 2026, 07:33:22 PM
Merited by vapourminer (4), LoyceV (4), hosemary (1)
 #467

Pick another 10 words from the bowl of paper strips. That's your passphrase.

Have you ever tried to transact with a hardware wallet?  It will frequently require the passphrase to be re-entered, especially if a certain amount of time passes between transactions. 

Accordingly, I am not sure what advantage comes from having to type 10 words each time as compared with maybe having a passphrase that might have some quasi-random string of around 15-ish characters that include numbers, letters, cap letters and symbols.

That's a huge flaw in most hardware wallets.

Most hardware wallets make entering a passphrase so cumbersome that people use a short and weak passphrase instead.

These days, my hardware wallets are Krux and ShieldSigner. Both include the option for Passphrase QR, which makes using very strong passphrases really easy. Save your passphrase as a QR code. To load the wallet, scan the QR with the passphrase.

Before I switched to Krux, I was a Ledger user. I hate Ledger, but one thing they did right was make it easy to use a strong passphrase. Ledger devices allowed setting up 2 PIN codes to unlock the device.

PIN 1 unlocked the device to the seed-only wallet.

PIN 2 unlocked the device to the seed+passphrase wallet.

That made using a very strong passphrase really easy. Unlock the device using PIN 2. Done.

For years, I've been using passphrases that are over 50 characters long.

My hope is that the ColdCard flaw teaches more people (especially devs) the importance of making it easier for users to quickly enter strong passphrases.


3. Back up your seed and passphrase on metal.

4. Store your seed and passphrase somewhere secure. Somewhere only you have access to. Preferably 2 places, separate.

I am perfectly fine with the two places idea, even though practically, there are likely some guys who are quite challenged to have two places that are sufficiently within their control.

2 places: A safe in your home and a safe deposit box at the bank.


6. Get a small safe to keep in your home, where you'll store any documentation that needs to be written down. Document everything for your setup, even if only to help yourself remember "How'd I generate this seed? Why'd I set it up this way?"

7. Get home automation and put a sensor on the safe, to send you instant notifications if it is opened or moved. Aqara makes this easy and cheap. On sale, you can get an Aqara hub & sensors for under $50.

What if your house burns down?  I understand the document is separate from the seed, yet if you have the seed without the documents, is the seed still going to be useful?

Your seed and passphrase should be backed up on metal in 2 places: A safe in your home and a safe deposit box at the bank. Your documentation for your wallet should be in 2 places too. This is especially true for anybody doing multisig.

Bitcoin self custody comes with self responsibility. Those who aren't prepared to do it right or don't have the means to do it right should buy ETFs instead. It makes me sad to say that, but self custody needs to be done right.

Meuserna
Sr. Member
****
Offline

Activity: 345
Merit: 616


View Profile WWW
August 09, 2026, 09:23:14 PM
Merited by PrivacyG (2), vapourminer (1)
 #468

Sometimes, this forum is bizarre.

Mods deleted a comment where I explained how ColdCard wallet attackers are now targeting seed-only wallets they suspect are only decoys. Mods said the comment was off topic.

Using a seed-only wallet as a decoy is how ColdCard attackers know which seeds might be hiding coins behind a passphrase. There are often clues that a wallet is actually just a decoy.

How is that not relevant to this conversation?

I believe the safe way to set up a decoy is to leave the seed-only wallet unused, and set up a decoy using a weak passphrase.

An empty seed-only wallet gives anyone who finds it no clue that the wallet has ever been used. Adding a few sats there as a decoy gave the ColdCard attackers reason to see if they could find more hidden behind a passphrase. Now, if the passphrase for the real wallet is strong enough, those coins are safe (but should still be moved to a new seed+passphrase or multisig wallet for long term safety).

Stalker22
Legendary
*
Offline

Activity: 2324
Merit: 1631



View Profile
August 09, 2026, 09:33:12 PM
Last edit: August 09, 2026, 09:43:22 PM by Stalker22
Merited by vapourminer (1), ABCbits (1)
 #469

Sometimes, this forum is bizarre.

Mods deleted a comment where I explained how ColdCard wallet attackers are now targeting seed-only wallets they suspect are only decoys. Mods said the comment was off topic.
~

The mods did not delete your post, they just merged your comment with your previous post.
You can see it here: https://bitcointalk.org/index.php?topic=5589927.msg67024234#msg67024234

Just try not to make multiple posts in a row!  It is against the forum rules.  You can always use the edit button if you need to add something later.

█████████████████████████
███████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
███▀░░██████▀░▀████░░▀███
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
███▄░░██████░░████░░▄███
█████▄░░▀███░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
 ROOBET .██████. BET ON WORLD CUP  🗺 ⚽︎.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
|.
   BET NOW   
PrivacyG
Legendary
*
Offline

Activity: 1610
Merit: 2938


Fight for Privacy.


View Profile
August 09, 2026, 09:39:25 PM
 #470

I believe the safe way to set up a decoy is to leave the seed-only wallet unused, and set up a decoy using a weak passphrase.
This is actually a fantastic idea.  Although it is an unnecessary effort in this Coldcard case.  If you have a strong Pass phrase, they would not find it any way no matter how long they search.  The weak decoy would only be useful in a 5 Dollar wrench attack.  And even then.  It is only useful if the attacker does not believe you may be hiding more.

Which is what I believe would come after a short search for weak Pass phrases in the Coldcard case too.  Look for weak ones and then move on and try to find treasures.  They have all the time to do it.  And money to purchase better equipment now too.  Unless they are caught.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
Meuserna
Sr. Member
****
Offline

Activity: 345
Merit: 616


View Profile WWW
August 09, 2026, 10:36:16 PM
Merited by vapourminer (4), PrivacyG (2)
 #471

I believe the safe way to set up a decoy is to leave the seed-only wallet unused, and set up a decoy using a weak passphrase.
This is actually a fantastic idea.  Although it is an unnecessary effort in this Coldcard case.  If you have a strong Pass phrase, they would not find it any way no matter how long they search.  The weak decoy would only be useful in a 5 Dollar wrench attack.  And even then.  It is only useful if the attacker does not believe you may be hiding more.

Which is what I believe would come after a short search for weak Pass phrases in the Coldcard case too.  Look for weak ones and then move on and try to find treasures.  They have all the time to do it.  And money to purchase better equipment now too.  Unless they are caught.

Yeah.

Decoy wallets aren't effective for a $5 wrench attack unless you have enough Bitcoin in the decoy wallet to convince the attacker they got everything. And, really, at the point when you've become a target for a violent in-person attack, your life is what you need to worry about.

But for a ColdCard-style seed-hunting attack, I think a decoy wallet set up using a weak passphrase is a good idea because it becomes like an alarm that tells you someone is trying to crack your passphrase. Even if your passphrase is strong enough to prevent the attack (mine is well over 50 characters) it's still good to know someone is trying. Of course, the attacker has to take the decoy coins in order for you to know they found 'em and are trying to crack your passphrase.

Using a weak passphrase as a decoy can also be a great form of security if your main wallet is set up some other way, such as multisig. A weak singlesig passphrase might convince an attacker to keep churning through passphrases to see if they can find your real wallet... which is especially useful if that's not how your real wallet is set up.

This whole ColdCard attack is terrible, and my heart breaks for everyone who lost coins. But one sliver of good news is that the attack made everyone start looking for vulnerabilities to patch or improve on.

I didn't lose any coins in this attack, but it did make me rethink every aspect of my own setup. We should all be doing that, because there's always room to improve even if it doesn't lead to changing your setup. I've been focusing on how I document mine for future reference, and how I teach the basics.

philipma1957
Legendary
*
Offline

Activity: 4942
Merit: 12336


'The right to privacy matters'


View Profile WWW
Today at 01:21:54 AM
 #472

Do you think someone who clearly doesn't know what passphrase or multi-sig is knows how to insert a message into their transaction? My opinion is that most of these messages come from scammers who play the victim card in the hope that some rich donor will see it and send a big donation.

I think one thing has nothing to do with the other.

Aside from the most paranoid (and rightfully so), the vast majority of people didn't add a 25th word to their seed created in a hardware wallet, considered reliable by the overwhelming majority of the community.

Otherwise, we'll be jeopardizing the entire seed system, which also doesn't make sense.

Therefore, a person not having the passphrase does not mean that they had little knowledge about Bitcoin.




Most people assume that it is a person, but isn't it possible that it is not a person but an advanced AI that was tasked with trying to hack a hardware wallet? Most people think that AI capabilities are what we see in popular models mainly from US companies - but the same companies and the US government itself have admitted that China, for example, has far more advanced AI models that are capable of much more than we can even imagine.

That's a plausible scenario. I'd never thought of that. Could some AI be running loose, stealing money, and even the AI ​​creators themselves don't know about it?

We're already entering the realm of conspiracy theory.   Roll Eyes




Aren't we underestimating the hacker here? He has been so clever to find this bug in Coldcard that wasn't detected before, and now we are assuming that the hacker will have a hard time cashing out those stolen BTC, and he will either end up in the wrong hands or get traced???

I am sure he must have already figured out how to get out of all this without getting noticed. He has a criminal mind, and we are just thinking that he will find trouble spending those bitcoins  Huh  I think we are too innocent to think like this, and if he is reading this, he must be laughing at us.

So, I think the reason why there is a delay in moving those funds is because the attacker knows that he has so many eyes on him, and he probably wouldn't want to make a silly mistake and get caught somehow, so he is surely exploring and researching all his options that he can use to convert his bitcoins either to another untraceable asset, or simply convert it to fiat and use it, because it obviously isn't his goal to just steal the funds and let it lying around in a wallet, but the most difficult thing in such attacks is not the attack itself but it is to use the funds after it.

Time is everything with this type of hack. The more time passes, the harder it is to get rid of the coins, not the other way around.

The longer he waits, the less things get "forgotten," and the better prepared blockchain analysts are to track these coins. The entire community, including exchanges, swaps, and the like, has become better prepared to catch any movement of these coins.

He's already missed the window of opportunity to move without being caught. Now, every step he takes is under surveillance.

Of course, this doesn't mean they won't try to withdraw the money at any time, but the longer it goes on, the more difficult it will be.

That's why I'm saying this: even the hacker himself wasn't expecting to be so successful. Otherwise, as soon as he had acquired the first coins, he would have immediately sent them to mixes and swaps to break their trail.

Perhaps he had already planned this, but the news broke too quickly, leaving him with no room for maneuver.

I'm not saying that he is naive or ingenuous. I'm simply presenting the scenario where the hacker who carried out the attack wasn't expecting the success they had, and was left unsure of what to do. Because stealing 10 BTC is one thing, stealing 1000 BTC is quite another; the whole plan changes.


He did not want the coins.

This smacks of other agenda.

Why do 500 seeded wallets in 1 shot.

Moron move. Unless stealing was not the agenda.


Be ready to do them and do 1 a month. Only do wallets seeds a little at a time .

If a coldcard was drained here and there most of us would think  the owner of the wallet was careless.

In a year he could have grabbed 10-12 wallets with 1 or 2 coins each.

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|..BTC......XMR...
..USDT.....LTC...
....Fees  0.8%.....
ryzaadit
Legendary
*
Offline

Activity: 3290
Merit: 1404



View Profile
Today at 02:24:14 AM
Merited by ABCbits (1)
 #473

I'm not a law expert.

But I'm kinda curious. In case we have a class action against Coinkite due to the buggy device they provide to customers.

I checked, Coinkite is from Canada - Ontario. I searched basic laws for any kind related to customer protection and found something that can be used as a baseline for the class action:
  • Canada Consumer Product Safety Act (CCPSA)
  • Ontario Sale of Goods Act
  • Ontario Consumer Protection Act, 2002

I know all the victim will not get their money back or compensation, but maybe Coinkite will pay some fine to Canada Goverment or something. At least they should have suffered financial damage, not just trust damage to their service and hardware or sales damage but also needed a serious financial damage.



In other side, I try search class-action and found out these guys claiming collecting some people and other to make a class action againts Coinkite.


But, I don't trust these guys. He has a history of cases.


Let's said, there has some class action againts Coinkite and Canadaian Goverment found out they're guilty. How much do you think they will pay for the fine and damage ? 5,000,000$ or somethings ?


▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
yxlm2009
Newbie
*
Offline

Activity: 1
Merit: 0


View Profile
Today at 03:46:50 AM
 #474

With a Coldcard Mk3 device in hand, you’re able to pull out UID0 and figure out the wafer batch range. Hackers would likely buy several Coldcard Mk3 units across different regions, dump their UIDs to conduct precise heists. If all shipments go to the same address, that can be used as a clue to track them down.
Wind_FURY
Legendary
*
Offline

Activity: 3738
Merit: 2215



View Profile
Today at 05:31:35 AM
Merited by vapourminer (1)
 #475

XMR (Monero) is no longer usable on exchanges, so he could use ZCash or just swap chunks in Exodus wallet to other crypto, mix it and pay out.

What do you mean by "not usable"?

It's still listed on a plenty of centralised exchanges with decent liquidity as well as on DEXs but with questionable liquidity if that's what you meant.
 

I believe that he was talking about the delistings that happened in many major exchanges. The privacy features of Monero is currently too good, and it makes it scary for the government.

 

That's why I advocate for NO on-chain privacy features for Bitcoin.

Furthermore I found another post about another theory saying that the ColdCard issue could be an inside job. It would actually surprise me if there's a nefarious entity in the company.

Quote

I did my own investigation because I obviously don't trust them.

What I found is that the external dependency of the firmware with the critical vulnerability hidden in it was written by CoinKite's CTO @DocHex pretending to be someone else.

All of the following can be verified

As a SeedSigner user I'm very familiar with @nvk's FUD of it.

One of his main talking points is that the SeedSigner and its dependencies cannot be verified down to the metal, whereas ColdCard's software stack is developed in-house at Coinkite, top-to-bottom and controlled.


So imagine my surprise when it turns out that the CC's firmware depends on a random project maintained by a nym named @switck, who joined GitHub on August 2020.

3 months later Coinkite's CTO was asking him for permission to use it in CC's firmware.

Just imagine you're @Coinkite's CTO, you "find" this 6 day old project with this weird commit history and you go "yeah that looks legit, I'll make the ColdCard firmware depend on this external dependency made by some random anon
" 🤔

This violation of their own philosophy is weird, but it gets worse. It turns out @switck's controls @DocHex's personal GPG key and signs his own libngu commits with it.

This is a very strong sign that both nyms are the same person, as it's impossible to fake these signatures.

https://x.com/oomahq/status/2085717166884618584


The post is very long. Go to the link if you want to read all of that.

joker_josue
Legendary
*
Offline

Activity: 2478
Merit: 7351


**In BTC since 2013**


View Profile WWW
Today at 06:52:29 AM
Merited by vapourminer (1)
 #476

He did not want the coins.

This smacks of other agenda.

Why do 500 seeded wallets in 1 shot.

Moron move. Unless stealing was not the agenda.


Be ready to do them and do 1 a month. Only do wallets seeds a little at a time .

If a coldcard was drained here and there most of us would think  the owner of the wallet was careless.

In a year he could have grabbed 10-12 wallets with 1 or 2 coins each.

Perhaps. I don't rule out the possibility that there's another objective behind this.

But the point is that he may not have needed to hack into 500 wallets to be very successful. Raiding one or two at a time wasn't enough either, because those one or two might not have anything inside.

In turn, given that entropy is weak, he may have had incredible success in his first attempts. Imagine that the first 10 wallets he found with money each had over 10 BTC? Could he have stopped? He could have, but he was unlikely to.

He probably thought: "Wow... this works, I'll keep running the script to see if I can find more." Within a few hours he's already stolen several hundred coins. Now, why would he stop?

It ends up being a common characteristic of successful robbers. The effectiveness of their robberies is so good that they don't stop until they make a mistake and get caught. This case is the same; his success was so great that now any step he takes can be easily detected.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
manisell
Newbie
*
Offline

Activity: 1
Merit: 0


View Profile
Today at 07:18:12 AM
 #477

this one was quite shocking, still curiously following the updates
Myleschetty
Full Member
***
Offline

Activity: 1606
Merit: 122

I53D79AQRM46


View Profile
Today at 07:58:21 AM
 #478

In other side, I try search class-action and found out these guys claiming collecting some people and other to make a class action againts Coinkite.


But, I don't trust these guys. He has a history of cases.


Let's said, there has some class action againts Coinkite and Canadaian Goverment found out they're guilty. How much do you think they will pay for the fine and damage ? 5,000,000$ or somethings ?


Despite all of this, I think that every victim of the Coldcard hack wallet should exercise caution because some individuals will take advantage of the situation to start scams involving advance fees, recovery, or refunds because the public won't be aware of what's going on through the dm. Individuals who lost their Bitcoin due to the hack are still at risk and vulnerable.

XMR (Monero) is no longer usable on exchanges, so he could use ZCash or just swap chunks in Exodus wallet to other crypto, mix it and pay out.

What do you mean by "not usable"?

It's still listed on a plenty of centralised exchanges with decent liquidity as well as on DEXs but with questionable liquidity if that's what you meant.
 

I believe that he was talking about the delistings that happened in many major exchanges. The privacy features of Monero is currently too good, and it makes it scary for the government.

 

That's why I advocate for NO on-chain privacy features for Bitcoin.

Furthermore I found another post about another theory saying that the ColdCard issue could be an inside job. It would actually surprise me if there's a nefarious entity in the company.
I think he believes that all of CEX delisted it at that time but Monero is still listed on CEX like Mexc.
We can not blame those who believe that the ColdCard hack was an insider job because the security flaw was discovered years ago and the ColdCard team did nothing about it.
As a result, people will likely assume that it was a planned attack because no rational person would do that.
vapourminer
Legendary
*
Offline

Activity: 5124
Merit: 6664


what is this "brake pedal" you speak of?


View Profile
Today at 09:40:53 AM
 #479

He did not want the coins.

This smacks of other agenda.

Why do 500 seeded wallets in 1 shot.

Moron move. Unless stealing was not the agenda.


Be ready to do them and do 1 a month. Only do wallets seeds a little at a time .

If a coldcard was drained here and there most of us would think  the owner of the wallet was careless.

In a year he could have grabbed 10-12 wallets with 1 or 2 coins each.

apparently bug this was soooo beyond stupid and easy for AI to help find that they prolly figured take it now before others will. after all not much honor among thieves and who knows how many peeps stumbled across this and didnt have the resources just yet.

Danish Ali
Newbie
*
Offline

Activity: 23
Merit: 1


View Profile
Today at 09:54:03 AM
 #480

He did not want the coins.

This smacks of other agenda.

Why do 500 seeded wallets in 1 shot.

Moron move. Unless stealing was not the agenda.


Be ready to do them and do 1 a month. Only do wallets seeds a little at a time .

If a coldcard was drained here and there most of us would think  the owner of the wallet was careless.

In a year he could have grabbed 10-12 wallets with 1 or 2 coins each.

apparently bug this was soooo beyond stupid and easy for AI to help find that they prolly figured take it now before others will. after all not much honor among thieves and who knows how many peeps stumbled across this and didnt have the resources just yet.


Greed vs. Logic: I could steal 1 BTC quietly every month for a year... or I can hit the red button NOW and make headline news today. Guess speed won over strategy.
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 [24] 25 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!