Bitcoin Forum
August 14, 2026, 10:17:58 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 [27]
  Print  
Author Topic: Large-scale Coldcard compromise (1596 BTC stolen so far)  (Read 9154 times)
Wind_FURY
Legendary
*
Offline

Activity: 3738
Merit: 2215



View Profile
August 13, 2026, 06:49:16 AM
 #521

The actual red flag was the ColdCard CTO made an anonymous account in Github and started talking to himself through his real account. Why would he do that if there wasn't any deception, and if there wasn't any nefarious motivation.


I don't know if this is true news or maybe there is another story behind all this Coldcard disaster. Many conspiracies occur and this kind of crime needs to be taken seriously.

If the CTO of Coldcard is guilty and suspected, there should be a more thorough investigation to find out who the real criminals are behind this hack.
 
Because the losses are so huge and even Many of them report that their entire lifetime savings are depleted in an instant.


Personally, I believe that the CTO should be suspected based on that action that was already posted, and therefore should be investigated. Because the QUESTION - Why did he do THAT?

Quote

Coldcard is like the perfect trap planted in a Hadrware wallet that then harvests all the proceeds so ruthlessly.
The claim as the best hardware wallet is even always boasted, even making a table that makes it seem as if this Coldwallet is superior to other products.




That's laughable today, but before the exploit, it was probably a very effective marketing scheme.

Quote

BTW, they are giving huge discounts now on all their Coldcard devices, does anyone want to buy it?


Will the CTO personally deliver it?

  

██████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
██████████████████████
.SHUFFLE.COM..███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
█████████████████████
████████████████████
██████████████████████
████████████████████
██████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
██████████████████████
██████████████████████
██████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
.
...Next Generation Crypto Casino...
Meuserna
Sr. Member
****
Offline

Activity: 348
Merit: 620


View Profile WWW
August 13, 2026, 07:13:30 AM
Merited by bitbollo (1), Lucius (1)
 #522

Coldcard was seen as the 'luxury car' of cold storage devices among a lot of people including a lot of fairly technical people.  For a reason!

Because they looked cyber-punk and they marketed their products as being more secure even though they weren't. And we know they weren't because thousands of their users are being robbed.

ColdCard devices are cheap plastic, and the design flaws are baffling. The camera for scanning QR codes isn't even pointed in the right direction. The screen on the Q is larger than their calculator-style devices, but they barely utilize the larger screen. The font is still tiny and the color is darker than it should be, making it harder to read. These are bizarre design flaws that show a lack of attention to detail. And the error in the code further proved a lack of attention to detail. That was shocking.

I wish I could convince people who claim to be serious about Bitcoin self custody to stop thinking a brand is their savior. It's bizarre. If you're going to trust a company to secure your Bitcoin, why not just buy into an ETF?

I love Bitcoin, and I love this community, but my God, all it takes to sucker people is a pic with laser eyes. Ledger literally added key-extraction to their firmware and people still trust them. That's crazy. ColdCard's shoddy code caused the biggest heist in the entire history of hardware wallets, and people are making excuses for trusting them because calculators and Blackberries look cool? Just... wow.

I'm literally begging some of you to take self custody more seriously, and I know you don't want to hear it. You want to be told you should trust ColdCard. That's crazy.

Don't trust a brand. Don't trust your Bitcoin to any code that isn't open source, and don't trust any seed you cannot back up on pen and paper unless you're only storing a few sats there (Tangem!). "Most is open source" means some isn't open source. And "Source Verifiable" means it isn't open source at all. "Seedless" means poison if anything goes wrong.

Bitcoin is open source. Your hardware wallet should be too. And at this point, I think it's time to admit that trusting somebody else's code to generate the seed phrase you'll use to secure your financial future isn't wise. There are many better ways to randomly generate the first 11 or 23 words. It's fine to let a device calculate the checksum, but you're better off randomly generating your own first 11 or 23.

I know almost nobody in this forum wants to hear this stuff. People here are brand loyal. And, y'know what? I am too. I'm brand loyal for my coffee, my beer, my phone and my toilet paper. But for securing my Bitcoin? No way. I generate my own seed, excluding the checksum, and I doublecheck that on multiple devices. I trust Bitcoin's code and hardware wallets that adhere strictly to it while being open source, and I doublecheck everything on a separate hardware wallet when setting up a wallet. Brand loyal? For Bitcoin? No way.

To anybody who thinks they should trust ColdCard, I ask this: What has the Coinkite CEO been doing for the past two weeks, as thousands of his customers were being robbed? That is not a rhetorical question.

I'm literally begging some of you to take self custody more seriously.

tvbcof
Legendary
*
Online Online

Activity: 5292
Merit: 1325


View Profile
August 13, 2026, 08:31:43 AM
 #523

Coldcard was seen as the 'luxury car' of cold storage devices among a lot of people including a lot of fairly technical people.  For a reason!

Because they looked cyber-punk and they marketed their products as being more secure even though they weren't. And we know they weren't because thousands of their users are being robbed....

Sorry, but you are clearly either a bozo who doesn't have enough experience to differentiate between a design flaw and a feature, and you don't have enough experience with hardware, or Bitcoin, to understand it.  (I mean, someone who cannot figure out how to turn a device 180 to see the screen!?!  C'mon.)  Or you are an AI bot intent on wasting my time.


sig spam anywhere and self-moderated threads on the pol&soc board are for losers.
Lucius
Legendary
*
Offline

Activity: 4060
Merit: 7713



View Profile WWW
August 13, 2026, 01:32:22 PM
 #524

~snip~
I'm literally begging some of you to take self custody more seriously.


You're wasting your time, literally. I honestly don't care if some people think their coins are still safe with Ledger, or that these incompetent idiots should be given a second chance - but it is very dangerous to convince others that all this we are discussing is just a small insignificant incident. Some people are truly amazing (in a negative way of course).

Whoever has that device should break it and throw it in the trash, and anyone with any sense should not buy it even if it's on sale for just $1.

obuoma
Full Member
***
Offline

Activity: 388
Merit: 147



View Profile
August 13, 2026, 02:07:54 PM
 #525



BTW, they are giving huge discounts now on all their Coldcard devices, does anyone want to buy it?
The question is, would you buy even if they offer them so cheap that they can be considered free? As of today, they have not been able to properly account for what they have caused people. From the table you shared, it was obvious they marketed their products as the best yet this mess happened. Who in his right minds will trust them with their money? My conclusion is that ColdCard are not sincere and they are rather complacent. Telling people to still buy their products at this point is a sign of insensitivity.

███████████    B I T L I S T        🔄 MIXERS     📈 EXCHANGES     🎰 CASINOS    ███████████
████████████████████     CATALOG CRYPTO WEBSITES #KYCFREE    ████████████████████
███████████    |   Bitcointalk Archive   |   Image Hosting   |  Currency Converter  |    ███████████
kTimesG
Sr. Member
****
Offline

Activity: 924
Merit: 272


View Profile
August 13, 2026, 03:07:42 PM
 #526

But I think he is wrong about 16000 picks of 1.099 trillion  is 50% for a collison.

16000 is 1 in 8600 bing
160000 is 1.16% google
1,600,000 is 65% google.

 My guess is they could have sold 160,000 wallets which would be under 2% of freak match

The entropy in the ColdCard's PRNG only has 22 bits. Advancing the PRNG state requires between 0 and 7 bits. More wallets are found at early stages (less PRNG advances).

If you average these, then the number of new wallets needed until the first collision appears is around sqrt(2**26) so I'd say it's actually well below 10.000. So very high chances to happen even after a few thousand wallets.

BTW I stopped scanning since it was becoming too boring and EVERYTHING I found was already sweeped between Jul 30 and Aug 2nd. That's tens of thousands of addresses being sweeped in 3 days.

I summed up the outgoing TX amounts between these dates to be more than 150 million dollars. But there were probably more wallets than what I gathered (which is around 2300 different seeds that got funded via whatever BIP you can think of).

tvbcof
Legendary
*
Online Online

Activity: 5292
Merit: 1325


View Profile
August 13, 2026, 04:37:23 PM
 #527


Worthwhile (though I have not watched the whole thing yet.)

  The Bitcoin Attacks are NOT About Money | Simon Dixon
  https://www.youtube.com/watch?v=wt8OMKpJk-U

BTW, Dixon and I have some startling parallels through our respective journeys, but I've never met the man or, as far as I know, interacted with him.


sig spam anywhere and self-moderated threads on the pol&soc board are for losers.
LoyceV
Legendary
*
Offline

Activity: 4130
Merit: 22470


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
August 13, 2026, 06:12:08 PM
 #528

Coldcard is like the perfect trap planted in a Hadrware wallet that then harvests all the proceeds so ruthlessly.
The claim as the best hardware wallet is even always boasted, even making a table that makes it seem as if this Coldwallet is superior to other products.
I try to avoid companies that kick down competitors instead of just showing their own product. That looks more like dirty politics than technology.

The question is, would you buy even if they offer them so cheap that they can be considered free?
I'm not even giving them my address if the device is free. But they can find some addresses to ship them to on this page.

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
PrivacyG
Legendary
*
Offline

Activity: 1610
Merit: 2950


Fight for Privacy.


View Profile
August 13, 2026, 06:48:51 PM
Merited by vapourminer (1), JayJuanGee (1)
 #529

but yeah, holy fucking shit!!! The bug was introduced in March 2021 and yeah perhaps sloppily, and then there started to be reports of lost funds, which should have had caused the discovery of the bug within months of those reports of losses,
Considering how easy this compromise seems to have been, I am extremely annoyed by the fact that it means there has been no serious Audit of their code in the last FIVE YEARS, which I thought was a normal habit for supposed high security devices like Hardware Wallets.

It makes you think what happened in the other cases where you see people reporting their other Hardware Wallet funds being stolen.  It has been kind of normal so far to see people complaining about this so I do get why at some point people started to ignore these and immediately assume the victim was to blame for their own probable mistake.  But I agree.  They should have investigated what happened as soon as the first such report became public.

The fact that all someone had to do to exploit this was to simply create a Seed over and over again until it collided with another already used Seed is absolutely crazy!

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
OgNasty
Donator
Legendary
*
Offline

Activity: 5558
Merit: 6442


Leading Crypto Sports Betting & Casino Platform


View Profile WWW
August 13, 2026, 06:51:43 PM
Merited by cAPSLOCK (1)
 #530

Every time I see something about this horrific incident the amount of BTC stolen rises.  It makes me sad there are people out there who are going to lose their funds and have absolutely no idea anything is wrong.  I wonder how long these wallets will be getting drained for.  Is it a race of hackers at this point trying to steal the scraps?  Have no white hats stepped up to steal as much as they can in order to refund victims?  Such a sad situation all around...

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
JayJuanGee
Legendary
*
Offline

Activity: 4536
Merit: 14874


Self-Custody is a right. Say no to "non-custodial"


View Profile
August 13, 2026, 10:37:08 PM
 #531

I am not really talking about them in terms of being an enemy, and so each of us have rights to feel various kinds of attachment, and from my perspective, in this particular case, and based on your last few posts, you seem to have Stockholm syndrome.
I am certainly thinking and talking of Coinkite as the enemy for reasons I won't go into at the moment.  In fact, a bitter enemy who I would like to see suffer greatly.  Right now I don't know who 'them' is though, and it is rare for certain classes of criminals to become accused, indicted, prosecuted, or covicted so I don't wait for these to occur before considering them an enemy.

Of course, I was referring to the matter generally in terms of the Coinkite principles who would have had been responsible for decisions around matters related to the random number generator or that ended up affecting the way that the software was written and the various oversights and/or subsequent decisions not to fix it or not to investigate further into it.  Of course, guilty actors can be prosecuted and/or companies can be prosecuted whether civilly or criminally.

I have to say that you are probably mis-reading, or not reading deeply enough into my writings as I intended if you think I have 'Stackholm syndrome' (or any such psychological condition which would cause me to 'defend' them.)  That is understandable in part because I have an older style of writing, and I also like to try to look at and describe things from all angles as a method of analyzing things.

Sure.  In writing, we might have misunderstandings, and so we bat around all kinds of ideas in a forum like this, and sometimes there are misunderstandings along the way and even exaggerations to make certain points (correctly or not).
 
...We can disagree too, so even though I think that it is problematic to be saying anything nice about Cold Card, you have a right to say it, and you are likely to get push back from various members on the forum, including yours truly.
To me, pushback is a good thing as it gets everyone thinking more.

Thanks for the rest of your reply.

Sometimes the agreements/disagreements might be strong, yet then maybe when we find out certain facts (or findings) further down the road, we might end up having to change our perspective or maybe we grow into another perspective based on further thoughts (and logic) on the matter.

It can be tricky to lock into any story or position too much when we are in the early stages of what seems to be an evolving story - including that there are all kinds of conspiracy theories coming out too, that still need to be substantiated, even if some of the stories might be based on a lot of seemingly convenient "coincidences.".... and at other times, coincidences end up being just that..with some things merely happening to play out at the same time.

1) Self-Custody is a right.  Resist being labelled as: "non-custodial" or "un-hosted."  2) ESG, KYC & AML are attack-vectors on Bitcoin to be avoided or minimized.  3) How much alt (shit)coin diversification is necessary? if you are into Bitcoin, then 0%......if you cannot control your gambling, then perhaps limit your alt(shit)coin exposure to less than 10% of your bitcoin size...Put BTC here: bc1q49wt0ddnj07wzzp6z7affw9ven7fztyhevqu9k
taufik123
Legendary
*
artcontest
Offline

Activity: 3346
Merit: 2477


Duelbits.com


View Profile
Today at 03:49:32 PM
 #532

I don't know if this is true news or maybe there is another story behind all this Coldcard disaster. Many conspiracies occur and this kind of crime needs to be taken seriously.
If the CTO of Coldcard is guilty and suspected, there should be a more thorough investigation to find out who the real criminals are behind this hack.
Because the losses are so huge and even Many of them report that their entire lifetime savings are depleted in an instant.
Mash is a mystery, but some people may have already filed a Class Action to sue Conkite for the losses experienced by many users.
And there has also been no official report from law enforcement authorities (such as the Canadian Police or federal agencies)
stating that Peter Gray (Doc Hex) will be arrested or criminally charged for such exploitation.

-snip-
My conclusion is that ColdCard are not sincere and they are rather complacent. Telling people to still buy their products at this point is a sign of insensitivity.
The point is that they are not really taking the matter seriously, or they are already losing a lot of money.
But, if their CTO is involved, of course the money will return to them in other forms, and the flow of funds is still being tracked.

I try to avoid companies that kick down competitors instead of just showing their own product. That looks more like dirty politics than technology.
Companies that do this kind of marketing are quite selfish and don't want to show their weaknesses, they just want to look perfect in the eyes of their users.
In fact, all the advantages that are talked about and written in boldly do not prove anything.
Being a weak HW and the scandal about the CTO involved further lifted the veil of the ugliness of this company.

tvbcof
Legendary
*
Online Online

Activity: 5292
Merit: 1325


View Profile
Today at 10:12:32 PM
 #533


Friends.  I see people who are supposed to know about these things, and who pumped Coinkite products heavily in the past, STILL suggest getting firmware binaries from Coinkite.

I strongly advise to NOT do this.  There are massive and growing questions around Coinkite generally, but little doubt in my mind that their team is fairly clever.

I have not seen it attempted, and would have to build a new machine to try it myself, but someone needs to try to get a reproducible build off of released versions of Coinkite's firmware.  I will offer a $1000 usd-equiv bounty for anyone who proves this viable and documents their work in a reproducible manner.  I'll arbitrate who (if anyone) gets the reward depending on timing and who did the better documentation.  The judging process and the results will be public domain, and I might up the bounty if the results are exemplary and if I choose to.

Alas, ever fairly bright and technical people are sometimes woefully ignorant about certain aspects of the construction and release processes of software.

For my part, I won't be running any of Coinkite's gear until it is possible to obtain the firmware from a 3rd party or build it myself.  Of course I drained all value from seeds generated on Coldcard.  I would assume they would go out of business, but that just means that their manpower/brainpower will switch over to another effort.  Hopefully enough information will eventually be know to track where they go.  I find it highly unlikely that anyone will ever be prosecuted for this, but that is not the only way for them (and their friends) to pay at least something for their malfeasance.


sig spam anywhere and self-moderated threads on the pol&soc board are for losers.
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 [27]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!