Bitcoin Forum
August 11, 2026, 11:34:36 AM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 [25]  All
  Print  
Author Topic: Large-scale Coldcard compromise (1596 BTC stolen so far)  (Read 8454 times)
bitmover
Legendary
*
Offline

Activity: 3122
Merit: 7662


Trêvoid █ No KYC-AML Crypto Swaps


View Profile WWW
August 10, 2026, 11:45:34 AM
Merited by vapourminer (1), JayJuanGee (1)
 #481

This whole incident made me remember from this old post from the guy that "came from the future", written in 2013

Quote
I am a time-traveler from the future, here to beg you to stop what you are doing.

....

In Africa, surveys show that an estimated 70% of people believe that Bitcoin was invented by the devil himself. There's a reason for this. It's a very sensitive issue that today is generally referred to as "the tragedy". The African Union had ambitious plans to help its citizens be ready to step over to Bitcoin. Governments gave their own citizens cell phones for free, tied to their government ID, and thus government sought to integrate Bitcoin into their economy. All went well, until "the tragedy" that is. A criminal organization, believed to be located in Russia, exploited a hardware fault in the government issued cell phones. It's believed that the entire continent of Africa lost an estimated 60% of its wealth in a period of 48 hours. What followed was a period of chaos and civil war, until the Saudi Arabian and North Korean governments, two of the world's major superpowers due to their authoritarian political system's unique ability to adapt to the "Bitcoin challenge", divided most African land between themselves and were praised as heroes by the local African population for it.

https://www.reddit.com/r/Bitcoin/comments/1lfobc/i_am_a_timetraveler_from_the_future_here_to_beg/

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|  BTC     XMR  
  DAI     LTC  
   Fees  0.8%    
Lucius
Legendary
*
Offline

Activity: 4060
Merit: 7698



View Profile WWW
August 10, 2026, 01:36:44 PM
 #482

Do you think someone who clearly doesn't know what passphrase or multi-sig is knows how to insert a message into their transaction? My opinion is that most of these messages come from scammers who play the victim card in the hope that some rich donor will see it and send a big donation.

I think one thing has nothing to do with the other.

Aside from the most paranoid (and rightfully so), the vast majority of people didn't add a 25th word to their seed created in a hardware wallet, considered reliable by the overwhelming majority of the community.

Otherwise, we'll be jeopardizing the entire seed system, which also doesn't make sense.

Therefore, a person not having the passphrase does not mean that they had little knowledge about Bitcoin.


I don't understand how you think adding a passphrase would compromise the entire seed system? However, I will not agree with the fact that someone who has not added additional protection for his seed understands the risks to which he is exposed, whether it is risks as in the case with the CC hack, or risks arising from a physical attack/theft of the same.

Is it easier to add a message to your transaction or set a passphrase in your wallet?

Most people assume that it is a person, but isn't it possible that it is not a person but an advanced AI that was tasked with trying to hack a hardware wallet? Most people think that AI capabilities are what we see in popular models mainly from US companies - but the same companies and the US government itself have admitted that China, for example, has far more advanced AI models that are capable of much more than we can even imagine.

That's a plausible scenario. I'd never thought of that. Could some AI be running loose, stealing money, and even the AI ​​creators themselves don't know about it?

We're already entering the realm of conspiracy theory.   Roll Eyes


It may seem like a conspiracy theory, but the AI ​​used by the general population today is ridiculously intelligent compared to what exists at the military-intelligence level, to the point that there is talk that some countries are using special tools powered by super AI that is starting to make decisive moves instead of humans.

The question is whether any AI has already managed to escape into the online wild, but even if not, it's only a matter of time before it happens. Imagine that same AI looking for ways to fund its own development, and what better way than by hacking cryptocurrencies?

bitmover
Legendary
*
Offline

Activity: 3122
Merit: 7662


Trêvoid █ No KYC-AML Crypto Swaps


View Profile WWW
August 10, 2026, 01:56:20 PM
 #483

The question is whether any AI has already managed to escape into the online wild, but even if not, it's only a matter of time before it happens. Imagine that same AI looking for ways to fund its own development, and what better way than by hacking cryptocurrencies?

For that to happen, the AI would need to hack processing power somewhere and also pay for the electricity. And maintenance of the data center, which needs some physical tasks as well... The AI can't move/install hardware by its own, yet.

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|  BTC     XMR  
  DAI     LTC  
   Fees  0.8%    
kTimesG
Sr. Member
****
Offline

Activity: 924
Merit: 271


View Profile
August 10, 2026, 02:54:20 PM
Merited by LoyceV (4)
 #484

Fun fact: it takes less than 16.000 people that create a fresh wallet on a ColdCard device, to reach more than a 51% chance to stumble upon an already existing seed created by someone else. So, question of the day is: how many new wallets were created, over how many users, over how many sold devices, over 5+ years?

And this factors in boot time, menu interactions, and any USB activity. So imagine this: someone simply buys an affected device, creates his wallet, and boom, he's already rich. What would his next step be? Is he now a criminal? And who owns the BTC (the BTC, not the KYC sourced traceback funds)?

joker_josue
Legendary
*
Offline

Activity: 2478
Merit: 7358


**In BTC since 2013**


View Profile WWW
August 10, 2026, 05:22:28 PM
 #485

I don't understand how you think adding a passphrase would compromise the entire seed system? However, I will not agree with the fact that someone who has not added additional protection for his seed understands the risks to which he is exposed, whether it is risks as in the case with the CC hack, or risks arising from a physical attack/theft of the same.

Is it easier to add a message to your transaction or set a passphrase in your wallet?

Maybe you didn't explain it to me well, but that's not what I meant.

What I wanted to say is that you usually don't need to make a 25th word to make the seed safe.
She is already safe with the 24 words if it is well done

So I understand why not everyone creates an extra word.

Until today, nothing like this had happened in hardware wallets, even those that are less popular.
Less was expected to happen in one as popular as Clodcard.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
JayJuanGee
Legendary
*
Offline

Activity: 4536
Merit: 14861


Self-Custody is a right. Say no to "non-custodial"


View Profile
August 10, 2026, 06:13:45 PM
Merited by LoyceV (2), vapourminer (1)
 #486

3. Back up your seed and passphrase on metal.
4. Store your seed and passphrase somewhere secure. Somewhere only you have access to. Preferably 2 places, separate.
I am perfectly fine with the two places idea, even though practically, there are likely some guys who are quite challenged to have two places that are sufficiently within their control.
2 places: A safe in your home and a safe deposit box at the bank.

Personally, I would not want to consider a bank safe deposit box at a bank to be completely under my control, so I would not want to store anything valuable there, such as my total stash of bitcoin or even large portions of my bitcoin, even though if it were just part of the formula to access, then maybe it would be o.k, such as 1/3 of the passphrase and/or 1/3 of the seedwords or maybe the instructions for how to do it, but not having enough information merely from the instructions being there.

6. Get a small safe to keep in your home, where you'll store any documentation that needs to be written down. Document everything for your setup, even if only to help yourself remember "How'd I generate this seed? Why'd I set it up this way?"
7. Get home automation and put a sensor on the safe, to send you instant notifications if it is opened or moved. Aqara makes this easy and cheap. On sale, you can get an Aqara hub & sensors for under $50.

What if your house burns down?  I understand the document is separate from the seed, yet if you have the seed without the documents, is the seed still going to be useful?
Your seed and passphrase should be backed up on metal in 2 places: A safe in your home and a safe deposit box at the bank. Your documentation for your wallet should be in 2 places too. This is especially true for anybody doing multisig.

Bitcoin self custody comes with self responsibility.

I am personally not comfortable with your proposed set up in that you seem to be suggesting 2 places for instructions and 2 places for instructions (documentations) and maybe you are even suggesting that those two places would be different, so then is that 4 places?  Also, with the way that you are proposing, it seems to me that an infiltration of any of the one of the locations may well mean that your whole stash could be taken.  That sounds too risky to me.

Those who aren't prepared to do it right or don't have the means to do it right should buy ETFs instead. It makes me sad to say that, but self custody needs to be done right.

I am not against the idea that some people might not be able to handle self-custody, so they may well hold bitcoin in some 3rd party arrangement, whether that is the spot ETFs, bitcoin on exchanges, bitcoin in treasury companies, and yeah, some of those ways of holding price exposure to bitcoin are more capable of in-kind redemption, which surely bitcoin gets a lot (if not all?) of its power from the ability to self-custody and to be able to transact without permission.

Accordingly, it seems practical for the empowerment of bitcoin (so our bitcoin value does not go to zero or become the same as every other shitty 3rd-party controlled and manipulated financial product) to try to promote the practice of self-custody, even if guys are not putting all of their stash into self-custody.  There are some folks who might not be capable of self-custody but then there are others who are just not ready and/or willing to learn, and surely it can be difficult to suggest that someone in their 60s, 70s or 80s have to learn different ways to hold and store their value - especially if they are not technically inclined (or technically curious), and some people have busy lives that make it challenging to prioritize learning about ways to self-custody bitcoin..

which yeah is also one of the faults that the Cold Card breach brought out, since many folks did not even want to use their Cold Card wallet because they thought that it was not very user-friendly, yet at the same time, the lack of user-friendliness may well could have caused them to conclude (wrongly we subsequently found out) that the behind the scenes operations in Cold Card were done in secure ways.. and yeah, a lot of normies got punished for that assumption, which so many of us are starting to speculate that there may well could have had been some intentionality (in the maliciousness) of the breach since the extent to the recklessness has become so obviously clear given their ongoingly ignoring and/or poo-pooing complaints that specifically were about the security of the key generation that went back to 2021-ish.  ..... so guys took a lot of steps to secure their key but then assumed that the generation of the key was sufficiently robust, and ends up being quite painful, including perhaps scaring some folks away from considering the benefits (to self and benefits to the system) of self-custody.

Fun fact: it takes less than 16.000 people that create a fresh wallet on a ColdCard device, to reach more than a 51% chance to stumble upon an already existing seed created by someone else. So, question of the day is: how many new wallets were created, over how many users, over how many sold devices, over 5+ years?

And this factors in boot time, menu interactions, and any USB activity. So imagine this: someone simply buys an affected device, creates his wallet, and boom, he's already rich. What would his next step be? Is he now a criminal? And who owns the BTC (the BTC, not the KYC sourced traceback funds)?

Of course, if a guy created a wallet that already had fund in it, then surely the obvious conclusion is that the already existing bitcoin is not his.  Yet, there is no one stopping him (except his own moral compass) from taking what is someone else's. 

It is not a difficult question, even though some folks find it as a dilemma because they let their greed override logic.

Maybe if there were 100 bitcoin in there, then just take half, right?  Or maybe no matter what, take 15% as a bounty, which should warn the "actual owner"?  maybe send a private message to the actual owner?  Something like this:   "I took 15% of your coins as a 'finder's fee" bounty, and I am going to give you 3 months to remove your remaining coins, otherwise I am going to take another 15%."  I suppose that it does not have to be all or nothing, even though it is morally questionable to take coins that are not yours, but at the same time, it could take the owner a year or more before he noticed that some coins had been taken from his wallet. There isn't any obligation that we need to ongoingly watch the addresses within our wallets.

I don't understand how you think adding a passphrase would compromise the entire seed system? However, I will not agree with the fact that someone who has not added additional protection for his seed understands the risks to which he is exposed, whether it is risks as in the case with the CC hack, or risks arising from a physical attack/theft of the same.

Is it easier to add a message to your transaction or set a passphrase in your wallet?
Maybe you didn't explain it to me well, but that's not what I meant.

What I wanted to say is that you usually don't need to make a 25th word to make the seed safe.
She is already safe with the 24 words if it is well done

So I understand why not everyone creates an extra word.

Until today, nothing like this had happened in hardware wallets, even those that are less popular.
Less was expected to happen in one as popular as Clodcard.

I am pretty sure that I recall, historically, hearing about all kinds of claims from individuals about their having had lost their coins.  Of course, many of the times, we may well just chalk it off to user-error, even though in the case of some of the close source wallets, sometimes we might be skeptical about some insider knowledge that is allowing the swiping of coins and blaming the users.

1) Self-Custody is a right.  Resist being labelled as: "non-custodial" or "un-hosted."  2) ESG, KYC & AML are attack-vectors on Bitcoin to be avoided or minimized.  3) How much alt (shit)coin diversification is necessary? if you are into Bitcoin, then 0%......if you cannot control your gambling, then perhaps limit your alt(shit)coin exposure to less than 10% of your bitcoin size...Put BTC here: bc1q49wt0ddnj07wzzp6z7affw9ven7fztyhevqu9k
asUHWEceyc
Full Member
***
Offline

Activity: 172
Merit: 195

dekleptocraticizationismist


View Profile WWW
Today at 01:09:05 AM
 #487

He did not want the coins.

This smacks of other agenda.

Why do 500 seeded wallets in 1 shot.

Moron move. Unless stealing was not the agenda.


Be ready to do them and do 1 a month. Only do wallets seeds a little at a time .

If a coldcard was drained here and there most of us would think  the owner of the wallet was careless.

In a year he could have grabbed 10-12 wallets with 1 or 2 coins each.

apparently bug this was soooo beyond stupid and easy for AI to help find that they prolly figured take it now before others will. after all not much honor among thieves and who knows how many peeps stumbled across this and didnt have the resources just yet.


For this particular coding deficiency, the AI element of story always sounded to me like a bit of a age-convenient red herring making use of the newness of the methods.

Given the atypical and highly specialized nature of the coldcard platform (with dual communicating secure elements and the like, at least in the case of the Q), I'm becoming dubious that the decrease in activity of the hwrng is likely to be missed even without profiling it in a dedicated manner.  OTOH, apparently it was being used for other critical security operations...just not in the all-important seed generation.

I'm beginning to think that this may be a much bigger quasi-intelligence driven operation involving well more than one high-level actor.  Possibly not even with the real goal of obtaining BTC.  Guiding a herd to and through the gates into corporate-custodialandia at an opportune time could well be way more valuable in the end than purloining a few thousand BTC.  It would be an outcome which would shape very much the future of the roll-out of post-dollar monetary solutions.

Sure looks like part of a multi-pronged divide and conquer strategy. On the one hand, encourage dunce corner chain splintering of ideologically motivated participants- and on the other, pinch funds off layman newcomers, many of whom may not return or recommend bitcoin as strongly as they may have previously- owning one's keys in particular.

"A dummy with AI did it" is a great distraction on multiple levels. Follow it up with: "donate to our AI token fund for running security scans on "core" "infrastructure"..." 
LoyceV
Legendary
*
Offline

Activity: 4130
Merit: 22436


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
Today at 10:00:15 AM
Last edit: Today at 10:13:02 AM by LoyceV
 #488

I'm beginning to think that this may be a much bigger quasi-intelligence driven operation involving well more than one high-level actor.
I don't think so. Any organized attacker wouldn't have created multiple "waves", but would have swept all addresses at once, starting with the highest balance. It's not as if there was much of a rush to abuse a vulnerability that has been around since 2021, so the attacker could have carefully prepared this. After the news came out, it was to be expected that the first wave would wake up many other attackers.
Also: address reuse made it much easier to track the stolen funds. Unique addresses per swept wallet in combination with lower fees would have made it less obvious. This still makes me think it's someone who's in way over his head.

Fun fact: it takes less than 16.000 people that create a fresh wallet on a ColdCard device, to reach more than a 51% chance to stumble upon an already existing seed created by someone else.
That might explain the occasional user who said his funds were stolen a few years back. It simply means someone created a new wallet, and it was funded already.

Quote
So imagine this: someone simply buys an affected device, creates his wallet, and boom, he's already rich. What would his next step be? Is he now a criminal? And who owns the BTC (the BTC, not the KYC sourced traceback funds)?
Fun fact: every Bitcoin wallet you ever created starts by "brute-forcing" some addresses for you. If the number of potential private keys is large enough, that's not a problem and will never lead to a funded wallet. As for the question if that makes someone a criminal, realize that something is only a crime if it's defined in your country's laws. Morally, it's clear the money isn't yours. But legally, I don't know.

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 [25]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!