Bitcoin Forum
August 12, 2026, 06:54:47 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 [25] 26 »
  Print  
Author Topic: Large-scale Coldcard compromise (1596 BTC stolen so far)  (Read 8714 times)
bitmover
Legendary
*
Offline

Activity: 3122
Merit: 7663


Trêvoid █ No KYC-AML Crypto Swaps


View Profile WWW
August 10, 2026, 11:45:34 AM
Merited by vapourminer (1), JayJuanGee (1)
 #481

This whole incident made me remember from this old post from the guy that "came from the future", written in 2013

Quote
I am a time-traveler from the future, here to beg you to stop what you are doing.

....

In Africa, surveys show that an estimated 70% of people believe that Bitcoin was invented by the devil himself. There's a reason for this. It's a very sensitive issue that today is generally referred to as "the tragedy". The African Union had ambitious plans to help its citizens be ready to step over to Bitcoin. Governments gave their own citizens cell phones for free, tied to their government ID, and thus government sought to integrate Bitcoin into their economy. All went well, until "the tragedy" that is. A criminal organization, believed to be located in Russia, exploited a hardware fault in the government issued cell phones. It's believed that the entire continent of Africa lost an estimated 60% of its wealth in a period of 48 hours. What followed was a period of chaos and civil war, until the Saudi Arabian and North Korean governments, two of the world's major superpowers due to their authoritarian political system's unique ability to adapt to the "Bitcoin challenge", divided most African land between themselves and were praised as heroes by the local African population for it.

https://www.reddit.com/r/Bitcoin/comments/1lfobc/i_am_a_timetraveler_from_the_future_here_to_beg/

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|  BTC     XMR  
  DAI     LTC  
   Fees  0.8%    
Lucius
Legendary
*
Offline

Activity: 4060
Merit: 7709



View Profile WWW
August 10, 2026, 01:36:44 PM
 #482

Do you think someone who clearly doesn't know what passphrase or multi-sig is knows how to insert a message into their transaction? My opinion is that most of these messages come from scammers who play the victim card in the hope that some rich donor will see it and send a big donation.

I think one thing has nothing to do with the other.

Aside from the most paranoid (and rightfully so), the vast majority of people didn't add a 25th word to their seed created in a hardware wallet, considered reliable by the overwhelming majority of the community.

Otherwise, we'll be jeopardizing the entire seed system, which also doesn't make sense.

Therefore, a person not having the passphrase does not mean that they had little knowledge about Bitcoin.


I don't understand how you think adding a passphrase would compromise the entire seed system? However, I will not agree with the fact that someone who has not added additional protection for his seed understands the risks to which he is exposed, whether it is risks as in the case with the CC hack, or risks arising from a physical attack/theft of the same.

Is it easier to add a message to your transaction or set a passphrase in your wallet?

Most people assume that it is a person, but isn't it possible that it is not a person but an advanced AI that was tasked with trying to hack a hardware wallet? Most people think that AI capabilities are what we see in popular models mainly from US companies - but the same companies and the US government itself have admitted that China, for example, has far more advanced AI models that are capable of much more than we can even imagine.

That's a plausible scenario. I'd never thought of that. Could some AI be running loose, stealing money, and even the AI ​​creators themselves don't know about it?

We're already entering the realm of conspiracy theory.   Roll Eyes


It may seem like a conspiracy theory, but the AI ​​used by the general population today is ridiculously intelligent compared to what exists at the military-intelligence level, to the point that there is talk that some countries are using special tools powered by super AI that is starting to make decisive moves instead of humans.

The question is whether any AI has already managed to escape into the online wild, but even if not, it's only a matter of time before it happens. Imagine that same AI looking for ways to fund its own development, and what better way than by hacking cryptocurrencies?

bitmover
Legendary
*
Offline

Activity: 3122
Merit: 7663


Trêvoid █ No KYC-AML Crypto Swaps


View Profile WWW
August 10, 2026, 01:56:20 PM
 #483

The question is whether any AI has already managed to escape into the online wild, but even if not, it's only a matter of time before it happens. Imagine that same AI looking for ways to fund its own development, and what better way than by hacking cryptocurrencies?

For that to happen, the AI would need to hack processing power somewhere and also pay for the electricity. And maintenance of the data center, which needs some physical tasks as well... The AI can't move/install hardware by its own, yet.

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|  BTC     XMR  
  DAI     LTC  
   Fees  0.8%    
kTimesG
Sr. Member
****
Offline

Activity: 924
Merit: 271


View Profile
August 10, 2026, 02:54:20 PM
Merited by LoyceV (4)
 #484

Fun fact: it takes less than 16.000 people that create a fresh wallet on a ColdCard device, to reach more than a 51% chance to stumble upon an already existing seed created by someone else. So, question of the day is: how many new wallets were created, over how many users, over how many sold devices, over 5+ years?

And this factors in boot time, menu interactions, and any USB activity. So imagine this: someone simply buys an affected device, creates his wallet, and boom, he's already rich. What would his next step be? Is he now a criminal? And who owns the BTC (the BTC, not the KYC sourced traceback funds)?

joker_josue
Legendary
*
Offline

Activity: 2478
Merit: 7376


**In BTC since 2013**


View Profile WWW
August 10, 2026, 05:22:28 PM
 #485

I don't understand how you think adding a passphrase would compromise the entire seed system? However, I will not agree with the fact that someone who has not added additional protection for his seed understands the risks to which he is exposed, whether it is risks as in the case with the CC hack, or risks arising from a physical attack/theft of the same.

Is it easier to add a message to your transaction or set a passphrase in your wallet?

Maybe you didn't explain it to me well, but that's not what I meant.

What I wanted to say is that you usually don't need to make a 25th word to make the seed safe.
She is already safe with the 24 words if it is well done

So I understand why not everyone creates an extra word.

Until today, nothing like this had happened in hardware wallets, even those that are less popular.
Less was expected to happen in one as popular as Clodcard.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
JayJuanGee
Legendary
*
Online Online

Activity: 4536
Merit: 14864


Self-Custody is a right. Say no to "non-custodial"


View Profile
August 10, 2026, 06:13:45 PM
Merited by LoyceV (2), vapourminer (1)
 #486

3. Back up your seed and passphrase on metal.
4. Store your seed and passphrase somewhere secure. Somewhere only you have access to. Preferably 2 places, separate.
I am perfectly fine with the two places idea, even though practically, there are likely some guys who are quite challenged to have two places that are sufficiently within their control.
2 places: A safe in your home and a safe deposit box at the bank.

Personally, I would not want to consider a bank safe deposit box at a bank to be completely under my control, so I would not want to store anything valuable there, such as my total stash of bitcoin or even large portions of my bitcoin, even though if it were just part of the formula to access, then maybe it would be o.k, such as 1/3 of the passphrase and/or 1/3 of the seedwords or maybe the instructions for how to do it, but not having enough information merely from the instructions being there.

6. Get a small safe to keep in your home, where you'll store any documentation that needs to be written down. Document everything for your setup, even if only to help yourself remember "How'd I generate this seed? Why'd I set it up this way?"
7. Get home automation and put a sensor on the safe, to send you instant notifications if it is opened or moved. Aqara makes this easy and cheap. On sale, you can get an Aqara hub & sensors for under $50.

What if your house burns down?  I understand the document is separate from the seed, yet if you have the seed without the documents, is the seed still going to be useful?
Your seed and passphrase should be backed up on metal in 2 places: A safe in your home and a safe deposit box at the bank. Your documentation for your wallet should be in 2 places too. This is especially true for anybody doing multisig.

Bitcoin self custody comes with self responsibility.

I am personally not comfortable with your proposed set up in that you seem to be suggesting 2 places for instructions and 2 places for instructions (documentations) and maybe you are even suggesting that those two places would be different, so then is that 4 places?  Also, with the way that you are proposing, it seems to me that an infiltration of any of the one of the locations may well mean that your whole stash could be taken.  That sounds too risky to me.

Those who aren't prepared to do it right or don't have the means to do it right should buy ETFs instead. It makes me sad to say that, but self custody needs to be done right.

I am not against the idea that some people might not be able to handle self-custody, so they may well hold bitcoin in some 3rd party arrangement, whether that is the spot ETFs, bitcoin on exchanges, bitcoin in treasury companies, and yeah, some of those ways of holding price exposure to bitcoin are more capable of in-kind redemption, which surely bitcoin gets a lot (if not all?) of its power from the ability to self-custody and to be able to transact without permission.

Accordingly, it seems practical for the empowerment of bitcoin (so our bitcoin value does not go to zero or become the same as every other shitty 3rd-party controlled and manipulated financial product) to try to promote the practice of self-custody, even if guys are not putting all of their stash into self-custody.  There are some folks who might not be capable of self-custody but then there are others who are just not ready and/or willing to learn, and surely it can be difficult to suggest that someone in their 60s, 70s or 80s have to learn different ways to hold and store their value - especially if they are not technically inclined (or technically curious), and some people have busy lives that make it challenging to prioritize learning about ways to self-custody bitcoin..

which yeah is also one of the faults that the Cold Card breach brought out, since many folks did not even want to use their Cold Card wallet because they thought that it was not very user-friendly, yet at the same time, the lack of user-friendliness may well could have caused them to conclude (wrongly we subsequently found out) that the behind the scenes operations in Cold Card were done in secure ways.. and yeah, a lot of normies got punished for that assumption, which so many of us are starting to speculate that there may well could have had been some intentionality (in the maliciousness) of the breach since the extent to the recklessness has become so obviously clear given their ongoingly ignoring and/or poo-pooing complaints that specifically were about the security of the key generation that went back to 2021-ish.  ..... so guys took a lot of steps to secure their key but then assumed that the generation of the key was sufficiently robust, and ends up being quite painful, including perhaps scaring some folks away from considering the benefits (to self and benefits to the system) of self-custody.

Fun fact: it takes less than 16.000 people that create a fresh wallet on a ColdCard device, to reach more than a 51% chance to stumble upon an already existing seed created by someone else. So, question of the day is: how many new wallets were created, over how many users, over how many sold devices, over 5+ years?

And this factors in boot time, menu interactions, and any USB activity. So imagine this: someone simply buys an affected device, creates his wallet, and boom, he's already rich. What would his next step be? Is he now a criminal? And who owns the BTC (the BTC, not the KYC sourced traceback funds)?

Of course, if a guy created a wallet that already had fund in it, then surely the obvious conclusion is that the already existing bitcoin is not his.  Yet, there is no one stopping him (except his own moral compass) from taking what is someone else's. 

It is not a difficult question, even though some folks find it as a dilemma because they let their greed override logic.

Maybe if there were 100 bitcoin in there, then just take half, right?  Or maybe no matter what, take 15% as a bounty, which should warn the "actual owner"?  maybe send a private message to the actual owner?  Something like this:   "I took 15% of your coins as a 'finder's fee" bounty, and I am going to give you 3 months to remove your remaining coins, otherwise I am going to take another 15%."  I suppose that it does not have to be all or nothing, even though it is morally questionable to take coins that are not yours, but at the same time, it could take the owner a year or more before he noticed that some coins had been taken from his wallet. There isn't any obligation that we need to ongoingly watch the addresses within our wallets.

I don't understand how you think adding a passphrase would compromise the entire seed system? However, I will not agree with the fact that someone who has not added additional protection for his seed understands the risks to which he is exposed, whether it is risks as in the case with the CC hack, or risks arising from a physical attack/theft of the same.

Is it easier to add a message to your transaction or set a passphrase in your wallet?
Maybe you didn't explain it to me well, but that's not what I meant.

What I wanted to say is that you usually don't need to make a 25th word to make the seed safe.
She is already safe with the 24 words if it is well done

So I understand why not everyone creates an extra word.

Until today, nothing like this had happened in hardware wallets, even those that are less popular.
Less was expected to happen in one as popular as Clodcard.

I am pretty sure that I recall, historically, hearing about all kinds of claims from individuals about their having had lost their coins.  Of course, many of the times, we may well just chalk it off to user-error, even though in the case of some of the close source wallets, sometimes we might be skeptical about some insider knowledge that is allowing the swiping of coins and blaming the users.

1) Self-Custody is a right.  Resist being labelled as: "non-custodial" or "un-hosted."  2) ESG, KYC & AML are attack-vectors on Bitcoin to be avoided or minimized.  3) How much alt (shit)coin diversification is necessary? if you are into Bitcoin, then 0%......if you cannot control your gambling, then perhaps limit your alt(shit)coin exposure to less than 10% of your bitcoin size...Put BTC here: bc1q49wt0ddnj07wzzp6z7affw9ven7fztyhevqu9k
asUHWEceyc
Full Member
***
Offline

Activity: 174
Merit: 197

dekleptocraticizationismist


View Profile WWW
August 11, 2026, 01:09:05 AM
 #487

He did not want the coins.

This smacks of other agenda.

Why do 500 seeded wallets in 1 shot.

Moron move. Unless stealing was not the agenda.


Be ready to do them and do 1 a month. Only do wallets seeds a little at a time .

If a coldcard was drained here and there most of us would think  the owner of the wallet was careless.

In a year he could have grabbed 10-12 wallets with 1 or 2 coins each.

apparently bug this was soooo beyond stupid and easy for AI to help find that they prolly figured take it now before others will. after all not much honor among thieves and who knows how many peeps stumbled across this and didnt have the resources just yet.


For this particular coding deficiency, the AI element of story always sounded to me like a bit of a age-convenient red herring making use of the newness of the methods.

Given the atypical and highly specialized nature of the coldcard platform (with dual communicating secure elements and the like, at least in the case of the Q), I'm becoming dubious that the decrease in activity of the hwrng is likely to be missed even without profiling it in a dedicated manner.  OTOH, apparently it was being used for other critical security operations...just not in the all-important seed generation.

I'm beginning to think that this may be a much bigger quasi-intelligence driven operation involving well more than one high-level actor.  Possibly not even with the real goal of obtaining BTC.  Guiding a herd to and through the gates into corporate-custodialandia at an opportune time could well be way more valuable in the end than purloining a few thousand BTC.  It would be an outcome which would shape very much the future of the roll-out of post-dollar monetary solutions.

Sure looks like part of a multi-pronged divide and conquer strategy. On the one hand, encourage dunce corner chain splintering of ideologically motivated participants- and on the other, pinch funds off layman newcomers, many of whom may not return or recommend bitcoin as strongly as they may have previously- owning one's keys in particular.

"A dummy with AI did it" is a great distraction on multiple levels. Follow it up with: "donate to our AI token fund for running security scans on "core" "infrastructure"..." 
LoyceV
Legendary
*
Offline

Activity: 4130
Merit: 22444


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
August 11, 2026, 10:00:15 AM
Last edit: August 11, 2026, 10:13:02 AM by LoyceV
Merited by vapourminer (1), joker_josue (1)
 #488

I'm beginning to think that this may be a much bigger quasi-intelligence driven operation involving well more than one high-level actor.
I don't think so. Any organized attacker wouldn't have created multiple "waves", but would have swept all addresses at once, starting with the highest balance. It's not as if there was much of a rush to abuse a vulnerability that has been around since 2021, so the attacker could have carefully prepared this. After the news came out, it was to be expected that the first wave would wake up many other attackers.
Also: address reuse made it much easier to track the stolen funds. Unique addresses per swept wallet in combination with lower fees would have made it less obvious. This still makes me think it's someone who's in way over his head.

Fun fact: it takes less than 16.000 people that create a fresh wallet on a ColdCard device, to reach more than a 51% chance to stumble upon an already existing seed created by someone else.
That might explain the occasional user who said his funds were stolen a few years back. It simply means someone created a new wallet, and it was funded already.

Quote
So imagine this: someone simply buys an affected device, creates his wallet, and boom, he's already rich. What would his next step be? Is he now a criminal? And who owns the BTC (the BTC, not the KYC sourced traceback funds)?
Fun fact: every Bitcoin wallet you ever created starts by "brute-forcing" some addresses for you. If the number of potential private keys is large enough, that's not a problem and will never lead to a funded wallet. As for the question if that makes someone a criminal, realize that something is only a crime if it's defined in your country's laws. Morally, it's clear the money isn't yours. But legally, I don't know.

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
tvbcof
Legendary
*
Offline

Activity: 5292
Merit: 1325


View Profile
August 11, 2026, 12:24:20 PM
 #489

I'm beginning to think that this may be a much bigger quasi-intelligence driven operation involving well more than one high-level actor.
I don't think so. Any organized attacker wouldn't have created multiple "waves", but would have swept all addresses at once, starting with the highest balance. It's not as if there was much of a rush to abuse a vulnerability that has been around since 2021, so the attacker could have carefully prepared this. After the news came out, it was to be expected that the first wave would wake up many other attackers.
Also: address reuse made it much easier to track the stolen funds. Unique addresses per swept wallet in combination with lower fees would have made it less obvious. This still makes me think it's someone who's in way over his head.

I think you are missing the point slightly.  People get tunnel vision on theft of BTC, and most people are fairly incapable of thinking farther than that (especially those who dream of obtaining BTC through deception of some form.)

I'm postulating that the goal here might be quite different and much bigger.

The 'theft of BTC' would be a factor insofar as it draws all the attention.  The attack would utilize these 'thefts' by opportunistic 3rd-party nobodies mainly as a smoke screen.  The real goal is to drive private keys into the hands of corporate actors acting as 'custodians'.  It would also help bolster the idea that custodianship is necessary to ensure 'public safety' and thus justify laws surrounding that principle generally.  This would become a general paradigm which extends well past Bitcoin specifically.



sig spam anywhere and self-moderated threads on the pol&soc board are for losers.
LoyceV
Legendary
*
Offline

Activity: 4130
Merit: 22444


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
August 11, 2026, 01:12:09 PM
 #490

The real goal is to drive private keys into the hands of corporate actors acting as 'custodians'.
Right until the first ETF loses all their Bitcoin to a hacker. It has happened to many exchanges in the past, so it can happen to them.

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
tvbcof
Legendary
*
Offline

Activity: 5292
Merit: 1325


View Profile
August 11, 2026, 01:39:07 PM
 #491

The real goal is to drive private keys into the hands of corporate actors acting as 'custodians'.
Right until the first ETF loses all their Bitcoin to a hacker. It has happened to many exchanges in the past, so it can happen to them.

Of course.  Most people(*) will never get 'their' BTC back once Fink has them.  At least not in-kind as we understand it today, and 'in-kind' does not apply anyway when purchased through and left on an exchange or ETF.  I'll wager the 'btc' will be returned in the form of, say, the 'digital euro' and such-like.

That said, most people have no clue about this stuff vs. 'real Bitcoiners'.  I would go so far as to project that most people will be delighted and thankful to Fink for 'saving them' and giving them at least some back in 'digital euro' form before Bitcoin 'failed' (meaning, 'became illegal' or some related disaster.)

---

* ('Most people' includes the likes of Saylor.  He expressed that 'of course he would turn the master keys over Fink if he could get some interest' until the likes of Keiser told him to shut his pie-hole until he understood the community better least he give the game away.)


sig spam anywhere and self-moderated threads on the pol&soc board are for losers.
oll
Full Member
***
Offline

Activity: 343
Merit: 156


old oll


View Profile
August 11, 2026, 01:53:09 PM
Merited by vapourminer (1)
 #492

The real goal is to drive private keys into the hands of corporate actors acting as 'custodians'.
Right until the first ETF loses all their Bitcoin to a hacker. It has happened to many exchanges in the past, so it can happen to them.

Like the general public, I have always believed that the organizers of BTC ETFs are popular among large investors because they will be responsible for any incidents involving bitcoin investors. But actually, after reading the legal information, it turns out that they will simply throw up their hands and say that they cannot restore your investments if the custodian loses all bitcoins in the event of a Hacker attack. And now, ETFs, like custodial storage, look absolutely ridiculous, because these companies invite everyone to invest bitcoins (while they themselves do not have their own personal savings), and at the same time they cannot even ensure the recovery of stolen funds in the event of a hacker attack. The explanation for this is that Bitcoin is a commodity and not a security. Lol. Plus, funds like BlackRock and others keep bitcoin with a single custodian like Coinbase Custody, which violates the moral principle of staying away from centralization.

vapourminer
Legendary
*
Offline

Activity: 5124
Merit: 6693


what is this "brake pedal" you speak of?


View Profile
August 11, 2026, 01:57:08 PM
 #493


Plus, funds like BlackRock and others keep bitcoin with a single custodian like Coinbase Custody, which violates the moral principle of staying away from centralization.

yes but blackrock, coinbase etc have one unique thing that bitcoin will never have: basically, a forgot password link or its equivalent.

its the security blanket of the masses.

maybe it will work?     yikes

oll
Full Member
***
Offline

Activity: 343
Merit: 156


old oll


View Profile
August 11, 2026, 02:32:32 PM
 #494


Plus, funds like BlackRock and others keep bitcoin with a single custodian like Coinbase Custody, which violates the moral principle of staying away from centralization.

yes but blackrock, coinbase etc have one unique thing that bitcoin will never have: basically, a forgot password link or its equivalent.

its the security blanket of the masses.

maybe it will work?     yikes

This can be considered as an advantage. But can this create precedents with password recovery not by the investor himself, but by a hacker or not by the owner himself (malicious intent of a friend, wife, colleague, etc.)?

Pmalek
Legendary
*
Offline

Activity: 3584
Merit: 9450



View Profile
August 11, 2026, 03:49:44 PM
Merited by vapourminer (1), JayJuanGee (1), Cookdata (1)
 #495

People are now experimenting with various ways to generate seeds. I wouldn't recommend that anyone does this, but it's interesting to read what's possible.
Here is a post by someone who created a Bitcoin seed generator powered by a smoke detector. They extracted Americium-241, hooked it to a Geiger counter and a Raspberry Pi to produce true random numbers.

There is a short video of this here:
https://x.com/pete_rizzo_/status/2087063715631837425

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
tvbcof
Legendary
*
Offline

Activity: 5292
Merit: 1325


View Profile
August 11, 2026, 05:29:48 PM
Merited by JayJuanGee (1)
 #496

People are now experimenting with various ways to generate seeds.
...

I'm one.

If one has some confidence in their /dev/[\u]random, a small bash shell script can do the BIP39 (word list):

   https://gist.github.com/atoponce/c608e98f091b1e7446a9d8610ddaf67c

If it is not clear, if one generated their own phrase such as the above, and used it in 'recovery mode' on a hotwallet of their choosing, one would in theory avoid the potential for for the wallet software using lesser random number generation.

---

As for BIP32, I see that Lopp has what looks like an auditable and low dependency implementation in C.

   https://github.com/jamesob/cbip32

The libsodium dependency seems pretty well used by the right players and pretty dis-liked by all the wrong players leading me to have some confidence in that code.

---

I have been pretty suspicious of pretty much all hardware rng's from well before Bitcoin having dealt with situations like
   https://arstechnica.com/information-technology/2013/12/we-cannot-trust-intel-and-vias-chip-based-crypto-freebsd-developers-say/
for a while.  For procedure design, I make the assumption that no hardware random number generator is licensed for general use, in most countries, unless it is subverted.

I make the same basic assumption (hidden instruction sets and the like) about CPU's following the information dug up about Cytrix.  That's why I have been pretty excited about the potential with open ISA;  e.g., the risc-v stuff.  I do not really trust ARM devices such as the Raspberry Pi or most Android-running devices (phones.)


sig spam anywhere and self-moderated threads on the pol&soc board are for losers.
Danish Ali
Newbie
*
Offline

Activity: 28
Merit: 4


View Profile
August 11, 2026, 06:43:17 PM
Merited by tvbcof (1), vapourminer (1)
 #497

yes but blackrock, coinbase etc have one unique thing that bitcoin will never have: basically, a forgot password link or its equivalent.

its the security blanket of the masses.

maybe it will work?     yikes


'Forgot password' button is great right up until central custodian decides to click 'freeze account' button.


Self-custody: 'Not your keys, not your coins.'

Wall Street: 'Not my keys, but at least there is support desk.'

Convenience always wins over principles for 99% of people.
PrivacyG
Legendary
*
Offline

Activity: 1610
Merit: 2944


Fight for Privacy.


View Profile
August 11, 2026, 08:10:40 PM
 #498

He did not want the coins.

This smacks of other agenda.

Why do 500 seeded wallets in 1 shot.

Moron move. Unless stealing was not the agenda.


Be ready to do them and do 1 a month. Only do wallets seeds a little at a time .

If a coldcard was drained here and there most of us would think  the owner of the wallet was careless.

In a year he could have grabbed 10-12 wallets with 1 or 2 coins each.
There is a lot of greed involved in situations like this.  And after a few tens or hundreds of Bitcoin, Wealth is not even the objective any more.  It becomes like a game.  What do you even do with all that money, particularly when it as illegal AND publicly known as it is in his case.

But maybe someone before the attacker who found the vulnerability DID grab one wallet or two a month for years and last month someone else found it and took the rest.  Considering there is no way of knowing who was the first and there are already people who complained about having their Bitcoin stolen.  I suppose it is safe to assume someone may have already used the same exploit in complete silence.

-----

Fun fact: it takes less than 16.000 people that create a fresh wallet on a ColdCard device, to reach more than a 51% chance to stumble upon an already existing seed created by someone else.
If the number is this low then I have really big doubts someone else did not already generate a used Seed in the past.  It makes me wonder how in the World this did not happen many times before.  The number is low enough that you would think the vulnerability would have been found a lot faster than it was.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
Wind_FURY
Legendary
*
Offline

Activity: 3738
Merit: 2215



View Profile
Today at 08:41:37 AM
 #499


XMR (Monero) is no longer usable on exchanges, so he could use ZCash or just swap chunks in Exodus wallet to other crypto, mix it and pay out.

What do you mean by "not usable"?

It's still listed on a plenty of centralised exchanges with decent liquidity as well as on DEXs but with questionable liquidity if that's what you meant.
 

I believe that he was talking about the delistings that happened in many major exchanges. The privacy features of Monero is currently too good, and it makes it scary for the government.

 

That's why I advocate for NO on-chain privacy features for Bitcoin.

Furthermore I found another post about another theory saying that the ColdCard issue could be an inside job. It would actually surprise me if there's a nefarious entity in the company.

I think he believes that all of CEX delisted it at that time but Monero is still listed on CEX like Mexc.
We can not blame those who believe that the ColdCard hack was an insider job because the security flaw was discovered years ago and the ColdCard team did nothing about it.

As a result, people will likely assume that it was a planned attack because no rational person would do that.


The actual red flag was the ColdCard CTO made an anonymous account in Github and started talking to himself through his real account. Why would he do that if there wasn't any deception, and if there wasn't any nefarious motivation.

Which also makes me think about Luke Dash Jr. - Something nefarious is also being hypothesized in BIP-100/FilterBoiCoin. People are starting to say Luke Dash Jr. is a bad actor.

taufik123
Legendary
*
artcontest
Offline

Activity: 3346
Merit: 2455


Duelbits.com


View Profile
Today at 05:02:20 PM
 #500

The actual red flag was the ColdCard CTO made an anonymous account in Github and started talking to himself through his real account. Why would he do that if there wasn't any deception, and if there wasn't any nefarious motivation.
I don't know if this is true news or maybe there is another story behind all this Coldcard disaster. Many conspiracies occur and this kind of crime needs to be taken seriously.
If the CTO of Coldcard is guilty and suspected, there should be a more thorough investigation to find out who the real criminals are behind this hack.
Because the losses are so huge and even Many of them report that their entire lifetime savings are depleted in an instant.

Coldcard is like the perfect trap planted in a Hadrware wallet that then harvests all the proceeds so ruthlessly.
The claim as the best hardware wallet is even always boasted, even making a table that makes it seem as if this Coldwallet is superior to other products.



BTW, they are giving huge discounts now on all their Coldcard devices, does anyone want to buy it?

Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 [25] 26 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!