Bitcoin Forum
August 25, 2026, 10:52:07 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 [28] 29 30 »
  Print  
Author Topic: Large-scale Coldcard compromise (1596 BTC stolen so far)  (Read 10236 times)
ryzaadit
Legendary
*
Offline

Activity: 3304
Merit: 1440



View Profile WWW
August 19, 2026, 10:32:40 AM
 #541

There is news on this topic, which will potentially lead to a full investigation of the theft case.
Would be very nice to have news for update class-action against the victim vs COINKITE. Want they really down so bad or getting financial damage first than the hacker. Cause they're the ones who make these tragedies happen, ignoring some warnings for the vulnerable firmware. So far, the update is only gathering for victim right now to make class-action:
  • Thomas Braziel with 117 victims Coldcard
  • Felipe Ojeda, Bitcoin Supporter from Brazil filling report to the police for these issue

Reading article: https://www.weirfoulds.com/the-coldcard-exploit-why-victims-may-have-two-routes-to-recovery would be very nice to get at least one of them, or maybe both.
Quote
(i) The first is traditional blockchain tracing and asset recovery targeting the bad actor(s), which can proceed almost anywhere in the world.

(ii) The second is to seek to hold Coinkite liable to its customers, with litigation likely being grounded in Canada, where Coinkite is registered.

Source
[1] https://www.theglobeandmail.com/business/article-ftx-claims-broker-now-courting-victims-155-million-coinkite-inc/
[2] https://www.binance.com/en/square/post/08-02-2026-coldcard-s-parent-company-coinkite-may-face-legal-action-351486847585490

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D  
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
joker_josue
Legendary
*
Online Online

Activity: 2492
Merit: 7412


**In BTC since 2013**


View Profile WWW
August 19, 2026, 06:03:23 PM
 #542

There is news on this topic, which will potentially lead to a full investigation of the theft case.:
Bitcoinmagazine reported that the Block investigation revealed that the hacker of the first wave of thefts (1,082 bitcoins that have not yet been touched) used a paid account on the blockchain data service. Due to the similar pattern of wave 2, it is possible that one person is behind both of these waves.
The service's internal logs pretty accurately matched the theft activity. Because of this trace, the identity of the hacker may already be known to the FBI.

It remains to be seen how he paid for this service, whether it was with crypto or not. If it wasn't with crypto, he may have used a prepaid credit card or a stolen one.

But let's see what comes of this investigation.

He continued to believe that the hacker was not expecting the operation to be so successful.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
yxlm2009
Newbie
*
Offline

Activity: 2
Merit: 0


View Profile
August 20, 2026, 12:09:06 AM
 #543

I ran on dual RTX 3080 Ti with my self‑compiled Windows CUDA build for four hours and got a wallet address. I only scanned for bc1 addresses.
Below is the wallet I found, Transaction ID: 154fd47b565a238dff15ccdbe2af08acc1b08f866c3c65e302d48fa6c9dfc20f
4391842 50 187 666 bc1q3dvd6g9j42hjuvc3kzkzz6nh8p3jclqvu7sfv4 c2d2b2144d11e28aa7cf9c4cb42ae0c2d3daffa9e70728bebdaa8120eb71f4aa
oll
Full Member
***
Offline

Activity: 387
Merit: 168


old oll


View Profile
August 20, 2026, 07:48:00 AM
 #544

There is news on this topic, which will potentially lead to a full investigation of the theft case.:
Bitcoinmagazine reported that the Block investigation revealed that the hacker of the first wave of thefts (1,082 bitcoins that have not yet been touched) used a paid account on the blockchain data service. Due to the similar pattern of wave 2, it is possible that one person is behind both of these waves.
The service's internal logs pretty accurately matched the theft activity. Because of this trace, the identity of the hacker may already be known to the FBI.

It remains to be seen how he paid for this service, whether it was with crypto or not. If it wasn't with crypto, he may have used a prepaid credit card or a stolen one.

But let's see what comes of this investigation.

He continued to believe that the hacker was not expecting the operation to be so successful.

If he paid with a prepaid card, then you can assume this guy can start making tea right away, because the FBI will be knocking on his door. But even with crypto, there's still a pretty good chance he'll be found. Consider this: I also think the hacker didn't expect such success because he's not touching the stolen money, and he's obviously a bit shocked. Experienced hackers know from the start which routes crypto will be taken; we have plenty of cases with incredibly resourceful North Korean hackers who haven't hesitated in any action. This hacker's activity also decreased when the hype started. This also suggests he's either inexperienced or out of his depth. Yes, he made a good technical approach; he's most likely a good programmer and used AI.

Lucius
Legendary
*
Offline

Activity: 4074
Merit: 7738



View Profile WWW
August 20, 2026, 12:40:02 PM
 #545

~snip~
Yes, he made a good technical approach; he's most likely a good programmer and used AI.


Or maybe it's an advanced AI model that just performed the given task - to detect, analyze and hack hardware wallets.

And as for paying with a credit card, today it is possible to buy such a card with XMR without KYC and with the use of VPN or Tor. However, for most of the powerful three letter agencies, this is not a problem, the only thing is whether they want to spend some time and resources to find out who is behind everything. In the end, maybe they'll accuse AI - good luck with the capture and conviction Roll Eyes

fillippone
Legendary
*
Offline

Activity: 2996
Merit: 21351


Duelbits.com - Rewarding, beyond limits.


View Profile WWW
August 20, 2026, 08:04:04 PM
 #546

However, for most of the powerful three letter agencies, this is not a problem, the only thing is whether they want to spend some time and resources to find out who is behind everything. In the end, maybe they'll accuse AI - good luck with the capture and conviction Roll Eyes

In the end, capturing him would enable him to capture the 1,600 BTC as well.
Something they will eventually add to the USA Bitcoin Strategic Reserve, as there will be little chance of returning to the legitimate owner.

ultrloa
Legendary
*
Offline

Activity: 3486
Merit: 1473



View Profile WWW
August 20, 2026, 10:33:31 PM
Merited by vapourminer (1)
 #547

However, for most of the powerful three letter agencies, this is not a problem, the only thing is whether they want to spend some time and resources to find out who is behind everything. In the end, maybe they'll accuse AI - good luck with the capture and conviction Roll Eyes

In the end, capturing him would enable him to capture the 1,600 BTC as well.
Something they will eventually add to the USA Bitcoin Strategic Reserve, as there will be little chance of returning to the legitimate owner.


They provably know they cannot do that easily. Since if it happens that US catch the ColdCard hacker that 1600 BTC will not automatically became their property.

There will be a victim classification and they return those funds to proven victims. Its illegal to absorb that funds as long as their are so many claimant of those seize funds. Maybe they can only absorb it once they cannot identify the ownership and no people chasing for those funds anymore.

Here is the sample and they talk about returning the funds of to the victims of this hacking incident https://www.justice.gov/usao-dc/pr/dc-scam-center-strike-force-seizures-cryptocurrency-chinese-transnational-criminals-tops

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT|
4,000+ GAMES
███████████████████
██████████▀▄▀▀▀████
████████▀▄▀██░░░███
██████▀▄███▄▀█▄▄▄██
███▀▀▀▀▀▀█▀▀▀▀▀▀███
██░░░░░░░░█░░░░░░██
██▄░░░░░░░█░░░░░▄██
███▄░░░░▄█▄▄▄▄▄████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
█████████
▀████████
░░▀██████
░░░░▀████
░░░░░░███
▄░░░░░███
▀█▄▄▄████
░░▀▀█████
▀▀▀▀▀▀▀▀▀
█████████
░░░▀▀████
██▄▄▀░███
█░░█▄░░██
░████▀▀██
█░░█▀░░██
██▀▀▄░███
░░░▄▄████
▀▀▀▀▀▀▀▀▀
||.
|
▄▄████▄▄
▀█▀
▄▀▀▄▀█▀
▄░░▄█░██░█▄░░▄
█░▄█░▀█▄▄█▀░█▄░█
▀▄░███▄▄▄▄███░▄▀
▀▀█░░░▄▄▄▄░░░█▀▀
░░██████░░█
█░░░░▀▀░░░░█
▀▄▀▄▀▄▀▄▀▄
▄░█████▀▀█████░▄
▄███████░██░███████▄
▀▀██████▄▄██████▀▀
▀▀████████▀▀
.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
░▀▄░▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄░▄▀
███▀▄▀█████████████████▀▄▀
█████▀▄░▄▄▄▄▄███░▄▄▄▄▄▄▀
███████▀▄▀██████░█▄▄▄▄▄▄▄▄
█████████▀▄▄░███▄▄▄▄▄▄░▄▀
███████████░███████▀▄▀
███████████░██▀▄▄▄▄▀
███████████░▀▄▀
████████████▄▀
███████████
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▀▄███░░░▀████░███▄▀██▄
███░████░░░░░▀██░████░███
███░████░█▄░░░░▀░████░███
███░████░███▄░░░░████░███
▀██▄▀███░█████▄░░███▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
OFFICIAL PARTNERSHIP
SOUTHAMPTON FC
FAZE CLAN
SSC NAPOLI
joker_josue
Legendary
*
Online Online

Activity: 2492
Merit: 7412


**In BTC since 2013**


View Profile WWW
August 21, 2026, 06:34:10 AM
Merited by vapourminer (1), ryzaadit (1)
 #548

However, for most of the powerful three letter agencies, this is not a problem, the only thing is whether they want to spend some time and resources to find out who is behind everything. In the end, maybe they'll accuse AI - good luck with the capture and conviction Roll Eyes

In the end, capturing him would enable him to capture the 1,600 BTC as well.
Something they will eventually add to the USA Bitcoin Strategic Reserve, as there will be little chance of returning to the legitimate owner.


I don't think it would be difficult to find out who the owners are, if the owners so wish. At least for some.

The money didn't just appear out of nowhere inside the Coldcards (so to speak). The owners of those coins had to send them there. This is how you can identify/prove which coins belong to whom.

You have to look at what happened before the coins arrived at Coldcard's addresses. Some people may have mined them; you have the pool records. Others may have bought them; you have the exchange records. Some simply moved the coins from another address to those addresses.

If a legitimate owner can prove that they were the one who sent the coins to the hacked address, then it clearly establishes that they are the rightful owner of those coins.


 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
ryzaadit
Legendary
*
Offline

Activity: 3304
Merit: 1440



View Profile WWW
August 21, 2026, 08:05:37 AM
Merited by Pmalek (3), vapourminer (1)
 #549

Something they will eventually add to the USA Bitcoin Strategic Reserve, as there will be little chance of returning to the legitimate owner.
Depends on where the Bitcoin came from. And in this case, which is these belong to the victim of the hardware wallet COLDCARD. and still higher chance is back to the legitimate owner.

Let's say the authorities can make a track, catch, and get all the fund is being drained by the hacker. To determine the funds will be based on the court result, and hopefully the court result determines that the funds are being stolen or forfeitable property. Then the victim can potentially get their fund back.

The DOJ (Department of Justice) can process all funds that are being forfeited by victim compensation, restitution, or other authorized process. The only problem if we don't have a claim or an identifiable victim, then somehow these funds that are being seized will go to US authorities.

I see some case are actually DOJ (Department of Justice) are actually given back the fund to the victim:
[1] 2025: $680,000 + 480.996 BNB from SafeMoon exploit: United States returns over $680,000 in stolen cryptocurrency using civil asset forfeiture
[2] 2022: 12.16 BTC from government imposter scam U.S. Attorney Dena J. King Announces The Successful Forfeiture And Return Of Stolen Cryptocurrency To Elderly Man Victimized By Government Imposter Scam
[3] 2026: $470,735 Victim of Scam Investment Department of Justice to Return $470,735 to Victims of Cryptocurrency Investment Scheme

DOJ claiming they already returning all the asset they're seized to the victim for more than $13 billion since 2000 Source:Victim Program. I think for right now are really matter is to gather up all the victim to reporting their losses to the authority or maybe joined some class-action. Hopefully in the future, some authorities make arrest to the one who are responbility for the drained all coldcard victim and offering a claim victim refund.

Source:
[1] https://www.justice.gov/criminal

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D  
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
Myleschetty
Full Member
***
Offline

Activity: 1663
Merit: 124


I53D79AQRM46


View Profile
August 21, 2026, 03:08:53 PM
 #550

I notice that nobody is discussing the Coldcard team's post from yesterday regarding the release of their new firmware to improve security, in which the impacted users were instructed to migrate their assets and regenerate their mnemonic phrases. I find it surprising that they advised impacted users to move their money after hackers had stolen it. The users responses to the post said it all, but are these Coldcard team even human?

ryzaadit
Legendary
*
Offline

Activity: 3304
Merit: 1440



View Profile WWW
August 21, 2026, 03:34:05 PM
Merited by vapourminer (1)
 #551

I notice that nobody is discussing the Coldcard team's post from yesterday regarding the release of their new firmware to improve security
Learning from the previous firmware update.

It would be very wise to get some feedback first from someone who has already tried update to the latest firmware, cause at the time we were facing the compromise issue they made an update firmware, and guess what?

It's an error, and everyone can't even update their firmware. Look here: https://x.com/northernH0DL/status/2083305136047149495 these are from the previous firmware update during the compromise time.



So, if you want to update your firmware, just make sure to get some feedback from someone already made the update. Just to make sure, it's okay to update the firmware. Still quite surprised everyone is still using these hardware wallets, even though Mk5 is not affected by the drain.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D  
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
Monetarium
Newbie
*
Offline

Activity: 7
Merit: 7


View Profile
August 21, 2026, 04:44:07 PM
Merited by Pmalek (3)
 #552

Coinkite's release notes for 5.6.1/1.5.1Q (the 20th) are worth reading past the changelog line: the seed generation fix itself landed earlier, in 5.6.0/1.5.0Q, so what's new here is a policy change, a new seed now needs entropy from the user rather than the device RNG alone.

The release notes also repeat the thing that keeps getting lost in these threads. Installing it does not make an existing seed safe. If the seed was generated on affected firmware between 2021 and July this year, it is the same seed after the update as before it, and the fix is a new seed on fixed firmware plus moving the coins.  Wink
Meuserna
Sr. Member
****
Offline

Activity: 357
Merit: 634


View Profile WWW
August 21, 2026, 05:11:09 PM
Merited by LoyceV (2)
 #553

The release notes also repeat the thing that keeps getting lost in these threads. Installing it does not make an existing seed safe. If the seed was generated on affected firmware between 2021 and July this year, it is the same seed after the update as before it, and the fix is a new seed on fixed firmware plus moving the coins.  Wink

Nothing can make an existing seed safe. A seed phrase can't be changed, and ColdCard seeds were guessable.

Before ColdCard's firmware update, generating a new seed would have just given you a new easily findable wallet.

That being said, I can't imagine why anybody thinks it's smart to stick with ColdCard. For over five years, they failed at their main job, and their response to a catastrophe of their own making only made matters worse. First, they spread misinformation before they knew the facts, then their CEO spent over a week deleting old tweets while retweeting other people (which he later deleted).

fillippone
Legendary
*
Offline

Activity: 2996
Merit: 21351


Duelbits.com - Rewarding, beyond limits.


View Profile WWW
August 21, 2026, 07:08:37 PM
 #554


That being said, I can't imagine why anybody thinks it's smart to stick with ColdCard.

Even continuing using those devices would be extremely unsafe. They have planted a trick on their devices once, who says they didn’t it twice?
The sooner everybody understand this from Coldcard was a totally adversarial move against bitcoin, the better.

tvbcof
Legendary
*
Online Online

Activity: 5306
Merit: 1344


View Profile
August 21, 2026, 08:43:43 PM
Last edit: August 21, 2026, 08:54:41 PM by tvbcof
Merited by vapourminer (1)
 #555


That being said, I can't imagine why anybody thinks it's smart to stick with ColdCard.

Even continuing using those devices would be extremely unsafe. They have planted a trick on their devices once, who says they didn’t it twice?
The sooner everybody understand this from Coldcard was a totally adversarial move against bitcoin, the better.

I think it highly likely that they did deliberately plant 'tricks' on the device (incl firmware), and if so, they almost certainly wouldn't hesitate to load it up with a variety of such tricks.  The main thing holding them back would be the fear of creating undeniable evidence of crimes for which they could one day be charged in a court of law.

That said, I still use my CCQ because it is useful to me.  This is possible due to the (supposed) air-gap.  I don't use it for generating entropy of course, and moved all value to seeds created on entropy harvested in different ways (and no, I would not trust that one of the tricks they could have employed was subverting user input entropy.)

The main risk I see as a threat in the way I use the device would be that they subverted the communications means.  Specifically, activated radio communications even when turned off and/or undermined the ability to physically cut the NFC.  I can (and have) monitored the radiation emanating from the device and have not seen anything, and I never did use USB.  There are, I suppose, attack modes possible through SD, but the possibilities there seem remote to me.  Lastly, the BBQR, working closely with a wallet creator (e.g., Nunchuk) could possibly sign unexpected transactions.  The possibilities here seem remote to me as well.

Switching to another device opens a whole different set of questions about whether they also have developed surreptitiously engineered means of failure (or are simply incompetent.)  I don't see it as some sort of be-all-end-all is security.  The Coinkite event shifted me along a path that I was already on about dis-favoring hardware devices for security related work.

The Coinkite event also further added to my desire to avoid relying on people who might be disposed to the belief that my goyish BTC were promised to them by God 3000 years ago.  I only learned of this potential when ~nvk started quietly deleting his older posts.  Oh well.


sig spam anywhere and self-moderated threads on the pol&soc board are for losers.
avp2306
Hero Member
*****
Offline

Activity: 1792
Merit: 635


Latest promotion? Go to contesthunters.com


View Profile
August 22, 2026, 09:43:51 PM
 #556


That being said, I can't imagine why anybody thinks it's smart to stick with ColdCard.

Even continuing using those devices would be extremely unsafe. They have planted a trick on their devices once, who says they didn’t it twice?
The sooner everybody understand this from Coldcard was a totally adversarial move against bitcoin, the better.

Once they already show that their device have hidden weakness or it experience hacking issues, then basically people should not trust that wallet again.

The incident happen on Coldcard shows that hackers can penetrate when they see a flaws without user noticing it for many years. If the hackers did it once on those compromised wallets. No one out here can guarantee that they cannot repeat the same attack, because chances that incident will happen still high, if they use the same compromised wallet.

So best action to do is to migrate to another transparent hardware wallet to make sure that they are totally safe.


███████▄▄▀▀▀▀▀▄▄▄▄██████▄▄▀▀████▀▀▄▄
████▄▄▀▄▄████▄██▄▄▄█████▀▀▀▀█████
██▄▀▄▄██▀▀███▄▀██████▀▄▄██████▄██▄█
▄█▄▄▀▀████▄▄▀███████▄██████████▌████
█▀██▀▀▀▀███▄▄██████▐██████████████
▐▌█████▄▄▀█▀▀█████████████████▌███
█████▀▀▐▌████████▐█████████▀
██████████████████▄████████▀▄███▄▀
███████▄▄█████▄▀██▀▀▀▀▀███▀████▀
████▀▄▄▄▄▀▀███▄▄▄▀▄██▄▄▄▄███▄▄▀▀█▀▄█
█████████▀▀▀▀▀▀████▀▀████▀▀▀▄▄▄▀▄█▀
██▄▄▀▀▀▀▀▀██████▄▄▄██▀▀▀▀▀▀▀▄▄▄██▀
▄▀█████████████▀▀▀███████████▀▀▀
████
██
██
██
██
██
██
██
██
██
██
██
████
 

🛡️

📱
 
INSTANT TRANSACTIONS
SECURE & TRUSTWORTHY
24/7 ENTERTAINMENTS
PLAY ON ANY DEVICE
████
██
██
██
██
██
██
██
██
██
██
██
████
██
██
██
██
██
██
██
██
██
██
██
██
██
 
 $20 
██
██
██
██
██
██
██
██
██
██
██
██
██
 
  PLAY NOW  
Pmalek
Legendary
*
Offline

Activity: 3598
Merit: 9486



View Profile
August 23, 2026, 07:01:00 AM
Merited by LoyceV (6), vapourminer (2), Lucius (1), ABCbits (1)
 #557

Coinkite's release notes for 5.6.1/1.5.1Q (the 20th) are worth reading past the changelog line: the seed generation fix itself landed earlier, in 5.6.0/1.5.0Q, so what's new here is a policy change, a new seed now needs entropy from the user rather than the device RNG alone.

The release notes also repeat the thing that keeps getting lost in these threads. Installing it does not make an existing seed safe. If the seed was generated on affected firmware between 2021 and July this year, it is the same seed after the update as before it, and the fix is a new seed on fixed firmware plus moving the coins.  Wink
The new firmware now requires combining entropy from the chips and secure elements in the hardware wallets with user entropy which can be derived from three sources:

1. At least 65 key presses. I guess it's presses on the keyboard of the device.
2. 50 dice rolls.
3. 128 flips of a coin.

If I was a Coldcard user, there is nothing that NVK or anyone else from Coinkite could do to regain my trust, regardless if I lost money in the hacks or not. They have failed horribly. Game over.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
LoyceV
Legendary
*
Offline

Activity: 4144
Merit: 22534


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
August 23, 2026, 08:31:56 AM
 #558

If I was a Coldcard user, there is nothing that NVK or anyone else from Coinkite could do to regain my trust, regardless if I lost money in the hacks or not. They have failed horribly. Game over.
This!
"Fool me once, shame on you. Fool me twice, shame on me."

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
Cricktor
Legendary
*
Offline

Activity: 1596
Merit: 4345



View Profile
August 23, 2026, 10:15:03 AM
Merited by vapourminer (1)
 #559

If I was a Coldcard user, there is nothing that NVK or anyone else from Coinkite could do to regain my trust, regardless if I lost money in the hacks or not. They have failed horribly. Game over.
I'm certainly biased because I didn't and still don't like the stance of Coinkite regarding their source code base and especially the strange attitude nvK displayed so far.

I'm not a Coldcard user and will never become one after what happened. It's not that I can't forgive a company which made errors, but how Coinkite screwed up and failed is systematic and I frankly don't know what they would have to do and change to even have a chance to regain my trust.

For me they were already done with their "verifiable source code drama", more so now with their stupid flawed firmware screw-up and subsequent handling of it. Did they even once admit that they badly screwed up and some of their customers loosing their coins in consequence? Yeah, rhetorical question...

They deserve "Game over!", indeed.

Lucius
Legendary
*
Offline

Activity: 4074
Merit: 7738



View Profile WWW
August 23, 2026, 01:04:45 PM
 #560

~snip~
If I was a Coldcard user, there is nothing that NVK or anyone else from Coinkite could do to regain my trust, regardless if I lost money in the hacks or not. They have failed horribly. Game over.


It seems to me that they are trying to show that they are doing something just to have something to say in their defense if they ever find themselves in court. The other option would be silence and ignoring, which in the future could be interpreted as an admission of guilt.

There is definitely nothing to fix, their reputation is completely destroyed and they can be happy that they don't end up in prison or that some desperate person who lost his life savings doesn't take revenge on them.

Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 [28] 29 30 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!