Cricktor
Legendary

Activity: 1596
Merit: 4345
|
... I briefly followed the circus and drama with nvK and am aware of the grotesque pictures they paint. Well, let's put it this way: karma caught up on that company and its clowns. It's just very sad that the wrong people, their customers, suffered from the consequences of an evil attitude and arrogance of those who are to blame at Coinkite. There were times when (on paper!) I liked Coldcard, Opendime and Blockclock. Prices not so much, but maybe I would've swallowed it. I'm glad, I never did. Once I learned and followed the malice of nvK, any of their products became a no-go for me. I simply refuse to give my hard earned money or coins a company with such morons at the helm. In the end it was the right choice. ... The concept of a stateless signing device has some charm, although it's only comfortable, aka not annoying, when you can easily import your wallet with SeedQR or similar. A DIY aspect is also nice because it opens the opportunity to get this stuff without the crypto coin label attached to it (avoiding a crypto coin purchase trail which is nice for privacy). But I also see the SeedQR as a disadvantage. I'm only comfortable with it when it's the encrypted variant which again has the burden to not ever loose the encryption secret. Hell, safety is such a pain sometimes or shall I say: most of the times? ... I've already quality-control concerns regarding their coding when they've done presumably "a lot of re-implementations". Sounds a lot like marketing bs from them...
|
|
|
|
bitmover
Legendary

Activity: 3136
Merit: 7687
Trêvoid █ No KYC-AML Crypto Swaps
|
 |
August 24, 2026, 09:13:25 PM Last edit: Today at 10:53:03 AM by bitmover |
|
I imagine there is likely more than one class action being cooked up. Would they have deep enough pockets for this? I can imagine they spent a lot of money on marketing, sales and the actual product, while they didn't sell that many devices. So if all buyers want their money back, they don't have that amount. If the victims want their losses compensated, they won't have that kind of money it either. I wonder if they will be able to find the users who now hold those 1500 btc. One small mistake when spending, even in a kyc free exchange (like an ip leak), might expose their identities Time will tell if someone from coldcard is involved
|
| DΞX.fo | | | | | | ▄▄██████ █████████ ██████████ ██████████ ██████████ █████████ ▀▀██████
▄███████ ▄██████████ ████████████ █████████████ █████████████ | | | | ▄▄█ ▄████▀ ▄███▀█▄ ▄██▀█▄██ █████▀▀█ ████████ ████████ ▀██▄████ ▄████▄▄█ ▄█████▀███ ▄█████▀████▀ █████▀███████ ▀██▀█████████ | | | | | BTC XMR DAI LTC Fees 0.8% |
|
|
|
|
Meuserna
|
SeedSigner does not save any keys on the device.
Keys as in buttons? A Seedsigner has navigation keys on the left and three buttons on the right of the case. There are other casings that change the left-side navigation buttons and turn the device into a GameBoy Advance-looking thing. But there is no keyboard, though. Keys, as in, keys to coins. SeedSigner does not save the seed, the wallet, or anything else on the device. That's not a weakness. That's a strength. SeedSigner is stateless. Every time you shut down or reboot, the device wipes the seed and the wallet. On a ColdCard, when you boot the device, you have to enter the PIN to unlock the device. When a SeedSigner boots, there's no PIN to enter because there's no wallet on the device. You have to scan a seed QR to load the wallet. ShieldSigner is a SeedSigner fork that adds features like encrypted seed QR, passphrase QR, and smartcard capability. ShieldSigner is incredible. I'd definitely recommend it to anyone who liked ColdCard. ShieldSigner is so much better. I greatly prefer using a stateless wallet. If the device gets stolen, no worries. There's nothing on it.
|
|
|
|
|
Meuserna
|
 |
August 25, 2026, 12:21:04 AM |
|
... The concept of a stateless signing device has some charm, although it's only comfortable, aka not annoying, when you can easily import your wallet with SeedQR or similar. A DIY aspect is also nice because it opens the opportunity to get this stuff without the crypto coin label attached to it (avoiding a crypto coin purchase trail which is nice for privacy). But I also see the SeedQR as a disadvantage. I'm only comfortable with it when it's the encrypted variant which again has the burden to not ever loose the encryption secret. It's not a burden at all. What's the first thing you're supposed to do when you get a seed phrase? Write it on paper and make a metal backup. So, if you lose your encrypted seed QR decryption key, no worries. Just enter your seed phrase manually and create a new one.
|
|
|
|
tvbcof
Legendary

Activity: 5306
Merit: 1344
|
... I greatly prefer using a stateless wallet. If the device gets stolen, no worries. There's nothing on it.
On top of that, it's much more comfortable to take it through security at the airport, and it doesn't matter what device one uses so there could exist a devices and spares wherever one might need oneself (or one's associates in the case of multisig or whatever) to be working. A good question to have, however, would be how to be SURE the device really is stateless and not subverted to simply make one believe that it is? In other words, how to be sure that the seed material, once loaded, is not tucked away somewhere on the circuitry to later be exfiltrated? This could be a bigger problem with remote devices left on-site for on-site work. It's getting pretty 007-ee by this time though. OTOH, some of these devices have 10's or 100's of millions of dollars tied to them so the motivation to find a way could be significant.
|
sig spam anywhere and self-moderated threads on the pol&soc board are for losers.
|
|
|
|
Meuserna
|
... I greatly prefer using a stateless wallet. If the device gets stolen, no worries. There's nothing on it.
On top of that, it's much more comfortable to take it through security at the airport, and it doesn't matter what device one uses so there could exist a devices and spares wherever one might need oneself (or one's associates in the case of multisig or whatever) to be working. A good question to have, however, would be how to be SURE the device really is stateless and not subverted to simply make one believe that it is? In other words, how to be sure that the seed material, once loaded, is not tucked away somewhere on the circuitry to later be exfiltrated? This could be a bigger problem with remote devices left on-site for on-site work. It's getting pretty 007-ee by this time though. OTOH, some of these devices have 10's or 100's of millions of dollars tied to them so the motivation to find a way could be significant. A SeedSigner is just a Raspberry Pi with a camera and an LCD hat. It has no storage except for the micro SD card slot. And the firmware is 100% open source. You're right about taking it through security. Put a micro SD card with a video game on it instead of SeedSigner firmware. Even if somebody forces you to plug it in and turn it on, all they see is a video game... because that's what it is if that's what's on the micro SD card. On the other hand, I always laughed when people talked about ColdCards being covert. "It looks like a calculator!" And it has a hardware wallet name on it. So much for OpSec. LOL.
|
|
|
|
Pmalek
Legendary

Activity: 3598
Merit: 9486
|
But I also see the SeedQR as a disadvantage. I'm only comfortable with it when it's the encrypted variant which again has the burden to not ever loose the encryption secret.
You shouldn't look at it as a disadvantage in my opinion. The SeedQR is just another variant of your 12/24-word seed, represented in another way. You write down the seed physically on paper, metal, or whatever. It's not encrypted and you are supposed to hide it somewhere safe. Add a passphrase on top of that to increase security and hide that somewhere else. If it works for recovery phrases, the same approach is fine for seedQRs. The encryption is just another optional layer on top of everything else. Keys, as in, keys to coins.
SeedSigner does not save the seed, the wallet, or anything else on the device. That's not a weakness. That's a strength.
SeedSigner is stateless. Every time you shut down or reboot, the device wipes the seed and the wallet.
On a ColdCard, when you boot the device, you have to enter the PIN to unlock the device. When a SeedSigner boots, there's no PIN to enter because there's no wallet on the device. You have to scan a seed QR to load the wallet.
Oh, so that's what he meant. I like stateless modes in signing devices as well. I have a Jade that works similarly. What I don't like about the first model is that it requires USB or Bluetooth connection to a computer to install or update the firmware. Bluetooth can be turned off on a firmware level (you install a firmware that doesn't have it), but that just leaves USB connections. The first model doesn't support SD cards to get data to and from the signer. They added that functionality on Jade Plus - their second model.
|
| EARNBET | | | ⚽ 🏀 🏈 🏓 🎯 🥊 |
| ⚾ 🎾 ⛳ 🏐 🏏 🏎️ | | |
███████▄▄███████████ ████▄██████████████████ ██▄▀▀███████████████▀▀███ █▄████████████████████████ ▄▄████████▀▀▀▀▀████████▄▄██ ███████████████████████████ █████████▌████▀████████████ ███████████████████████████ ▀▀███████▄▄▄▄▄█████████▀▀██ █▀█████████████████████▀██ ██▀▄▄███████████████▄▄███ ████▀██████████████████ ███████▀▀███████████ | ....HIGHEST.... VIP REWARDS ✔ G U A R A N T E E D
| | | 🜲 | KING OF THE CASTLE $200K in prizes | | | ..PLAY NOW.. |
|
|
|
examplens
Legendary

Activity: 4116
Merit: 4919
|
 |
August 25, 2026, 08:50:08 AM |
|
I imagine there is likely more than one class action being cooked up. Would they have deep enough pockets for this? I can imagine they spent a lot of money on marketing, sales and the actual product, while they didn't sell that many devices. So if all buyers want their money back, they don't have that amount. If the victims want their losses compensated, they won't have that kind of money it either. I wonder if they will be able to find the users who now hold those 1500 btc. One small mistake when spending, even in a kyc free exchange (like an ip leak), might expose their identities Tell will tell if someone from coldcard is involved Well, there are indications that the hacker made a mistake and exposed information about himself. Activities were recognised where the operator used a paid account on a "well-known" blockchain service. A pattern of querying the original addresses was observed during the attack and this was repeated. https://www.cryptotimes.io/2026/08/19/block-and-galaxy-research-give-lead-to-law-enforcement-in-111m-coldcard-bitcoin-theft/
|
|
|
|
tvbcof
Legendary

Activity: 5306
Merit: 1344
|
 |
August 25, 2026, 09:30:30 AM |
|
I am not a lawyer, but according to the official story (which studiously avoids any 'conspiracy theories') I'm not really sure I see a crime here. Or at least not one which anyone is likely to get more than a slap on the wrist for. We have:
- a simple mistake from some device maker/seller,
- someone(s) found they could obtain shared control of keys represented in a public blockchain and availed themselves of the discovery.
At this point there is no provable evidence that either Coinkite deliberately sabotaged their hardware with the intent to defraud, or that there was any collusion between Coinkite and the various parties who picked up the dropped private keys. Indeed, it's kind of a weird sin-like thing to even think that way here in 2026.
I personally think it likely that both deliberate sabotage and collusion to engineer a lifting of BTC probably did occur, but that means nothing. Even if it did, it doesn't seem to me like something which would get anyone into serious trouble...at least in a formal court of law.
Actually, foreknowledge of the hack would possibly yield greater monetary benefit in terms of various kinds of 'insider trading', or in terms of getting compensated (or just a pat on the head for doing God's work) by entities who benefited (e.g., coin custodians who won keys as the whole system shifted away from faith in self-custody), but nobody gets in trouble for that kind of stuff these days.
|
sig spam anywhere and self-moderated threads on the pol&soc board are for losers.
|
|
|
bitmover
Legendary

Activity: 3136
Merit: 7687
Trêvoid █ No KYC-AML Crypto Swaps
|
 |
August 25, 2026, 10:30:51 AM |
|
I am not a lawyer, but according to the official story (which studiously avoids any 'conspiracy theories') I'm not really sure I see a crime here. Or at least not one which anyone is likely to get more than a slap on the wrist for. We have:
- a simple mistake from some device maker/seller,
- someone(s) found they could obtain shared control of keys represented in a public blockchain and availed themselves of the discovery.
At this point there is no provable evidence that either Coinkite deliberately sabotaged their hardware with the intent to defraud, or that there was any collusion between Coinkite and the various parties who picked up the dropped private keys. Indeed, it's kind of a weird sin-like thing to even think that way here in 2026.
I personally think it likely that both deliberate sabotage and collusion to engineer a lifting of BTC probably did occur, but that means nothing. Even if it did, it doesn't seem to me like something which would get anyone into serious trouble...at least in a formal court of law.
Actually, foreknowledge of the hack would possibly yield greater monetary benefit in terms of various kinds of 'insider trading', or in terms of getting compensated (or just a pat on the head for doing God's work) by entities who benefited (e.g., coin custodians who won keys as the whole system shifted away from faith in self-custody), but nobody gets in trouble for that kind of stuff these days.
You don't see a crime in transfering 1500 BTC (millions of dollars) from random people to your own wallet? What are you talking about. It is the same as hacking a bank app and transferring money to your own account.
|
| DΞX.fo | | | | | | ▄▄██████ █████████ ██████████ ██████████ ██████████ █████████ ▀▀██████
▄███████ ▄██████████ ████████████ █████████████ █████████████ | | | | ▄▄█ ▄████▀ ▄███▀█▄ ▄██▀█▄██ █████▀▀█ ████████ ████████ ▀██▄████ ▄████▄▄█ ▄█████▀███ ▄█████▀████▀ █████▀███████ ▀██▀█████████ | | | | | BTC XMR DAI LTC Fees 0.8% |
|
|
|
|
avp2306
|
Would they have deep enough pockets for this? I can imagine they spent a lot of money on marketing, sales and the actual product, while they didn't sell that many devices. So if all buyers want their money back, they don't have that amount. If the victims want their losses compensated, they won't have that kind of money it either.
I wonder if they will be able to find the users who now hold those 1500 btc. One small mistake when spending, even in a kyc free exchange (like an ip leak), might expose their identities Tell will tell if someone from coldcard is involved Well, there are indications that the hacker made a mistake and exposed information about himself. Activities were recognised where the operator used a paid account on a "well-known" blockchain service. A pattern of querying the original addresses was observed during the attack and this was repeated. https://www.cryptotimes.io/2026/08/19/block-and-galaxy-research-give-lead-to-law-enforcement-in-111m-coldcard-bitcoin-theft/Now that they already traced the hacker, its good to see what other action they made. Because many people are so curious about this case, they want those people involve in this hacking issue to get captured. Maybe this is also the reason why the funds stolen has left unmoved? https://crypto.news/coldcard-hackers-leave-87-of-stolen-bitcoin-unmoved-after-114m-theft they are maybe afraid to do transaction because it can create fresh traces to the authorities. They should act fast, so they can still recover the funds and return it back to those proven victims.
|
|
|
|
joker_josue
Legendary

Activity: 2492
Merit: 7417
**In BTC since 2013**
|
 |
August 25, 2026, 05:27:00 PM |
|
I have built a couple of these and the project is extremely impressive. It has its weaknesses and its strengths.
Are you satisfied? All the people I've talked to about this equipment speak very well. I believe it is another model to serve as a hold. But it is still very interesting. I think I'll have to venture out.
|
|
|
|
tvbcof
Legendary

Activity: 5306
Merit: 1344
|
 |
August 25, 2026, 08:27:57 PM Last edit: August 25, 2026, 10:18:39 PM by tvbcof |
|
...
A SeedSigner is just a Raspberry Pi with a camera and an LCD hat. It has no storage except for the micro SD card slot. And the firmware is 100% open source. You're right about taking it through security. Put a micro SD card with a video game on it instead of SeedSigner firmware. Even if somebody forces you to plug it in and turn it on, all they see is a video game... because that's what it is if that's what's on the micro SD card. On the other hand, I always laughed when people talked about ColdCards being covert. "It looks like a calculator!" And it has a hardware wallet name on it. So much for OpSec. LOL. I'm uncomfortable with powerful and complex OS's for very simplistic tasks (e.g., Linux). Similarly, with the basically two monopoly-ish architectures in widespread use in the West and licensed by their authorities. ARM and X86 are not Open ISA architectures. For many years I have been enthusiastic about the development trajectory of risc-v for this reason. If/when, if not already, there does seem to be a potential for smaller-scale fabs to exploit a niche market for fully auditable silicon. The reason strong air-gap is so important to me is that it makes otherwise unsafe silicon safe...with the Achilles heal being mainly entropy generation. Thankfully that is easy, if tedious, to overcome when it comes to simple stuff like Bitcoin. Other common cryptographic needs, no so much. I dug through my collection of signing devices and found a Krux. It seems to operate in the same 'stateless' manner as the SeedSigner. To be honest, I didn't really appreciate the distinction between stateful and stateless back several years ago when I was researching this stuff. At least not as much or in the same way as I do now. The Krux operates mainly on risc-v dev boards so it seems. Still researching the operating system. Since the timeframe of the few SeedSigners I have kicking around, their Linux OS has been cut down which is a good thing (as I see it.) I think at this point I would be favorable to a very simple (but durable) and inexpensive stateless device running an extremely primitive OS which is always built from source by the user as a matter of course. In order to avoid a large screen, I would hope it possible to so some sort of a long scrolling bar code as opposed to something like bbqr. That said, I just watched a pretty interesting vid about the likely trajectory of quantum-safety in Bitcoin, and it looks likely that key management is probably going to become much more computationally expensive. https://www.youtube.com/watch?v=E61gUCKcx2s. Probably it does make some sense to consider some of this stuff when choosing the ultimate bitcoin management 'assist-device' which has staying power. Edit: Another huge win for stateless devices, which I now recognize after some experience, is that I would be far less concerned about upgrading them. My experience with wallets is that it is always a matter of puckering-up at upgrade time to see what regressions the 'upgrade' brings along for the ride. I cannot help but come to the conclusion that most of these open source efforts are often undertaken by people who have minimal hands-on experience with production hardware/software and very little budget for testing and QA. Also, minimal attention spans. I still vastly prefer Open Source, but it is a notable disadvantage which I cannot ignore.
|
sig spam anywhere and self-moderated threads on the pol&soc board are for losers.
|
|
|
joker_josue
Legendary

Activity: 2492
Merit: 7417
**In BTC since 2013**
|
 |
August 25, 2026, 10:35:14 PM |
|
I dug through my collection of signing devices and found a Krux. It seems to operate in the same 'stateless' manner as the SeedSigner. To be honest, I didn't really appreciate the distinction between stateful and stateless back several years ago when I was researching this stuff. At least not as much or in the same way as I do now. The Krux operates mainly on risc-v dev boards so it seems. Still researching the operating system. Since the timeframe of the few SeedSigners I have kicking around, their Linux OS has been cut down which is a good thing (as I see it.) I think at this point I would be favorable to a very simple (but durable) and inexpensive stateless device running an extremely primitive OS which is always built from source by the user as a matter of course. In order to avoid a large screen, I would hope it possible to so some sort of a long scrolling bar code as opposed to something like bbqr. Based on your experience, would you prefer to set up a SeedSigner or a Krux (even though its development has stopped)? Or would you prefer to set up a different type of system to generate your seed and use it to sign transactions?
|
|
|
|
tvbcof
Legendary

Activity: 5306
Merit: 1344
|
 |
Today at 01:59:01 AM Last edit: Today at 09:52:51 AM by tvbcof |
|
...
Based on your experience, would you prefer to set up a SeedSigner or a Krux (even though its development has stopped)? Or would you prefer to set up a different type of system to generate your seed and use it to sign transactions? Jeez, I don't really have any hands-on experience to provide much of an opinion. It generally takes me some days of study to make such choices. Off-hand, I really like that the Krux code has been running on a number of platforms, and especially risc-v ones, because it probably means the design is relatively portable and it gives me some confidence in my ability to address some of my supply chain concerns. As for being out of development, in reading the thread I see that 'maix' as a platform is harder to find, but that's on a different level than the applications code. Also a hell of a minefield if scammers are buying domain names and the like. I wouldn't suggest it for noobs or people who don't understand software distribution well. The main dude moving on to a follow-up project, as referenced in the Bitcointalk thread, is interesting. He seemed to be working on the idea I mentioned above with some modicum of encryption of the 'startup cards'. But he also seems to be leaning into making a more complex device rather than a more simple one which is my current interest. '[C|K]rux' seems to be a commonly chosen name for OS's of various types. What, if anything, they may have to do with the application in question is something I don't have a good grasp on yet. My problem with development boards is that they tend to provide a kitchen sink full of communications options which is distinctly what I DON'T want for an air-gapped signing device. The concern also applies to Raspberry Pi. --- I mused a bit about an ideal device (for me.) In using the cold-card I noticed that the actual task of signing transactions is super-simple. It's the various other configurations and options and helper utilities which become more complex. For my part I would prefer a super-simple device which can do simple signings with a few buttons and a minimal display. More complex device configurations would be something I would be comfortable with doing via config files directly on a TF/uSD if it would simplify the device to the absolute minimum. Of course, with stateless, the big task is offloaded from the device completely: putting the right card in front of the camera. Come to think of it instead of, or in addition to, some configs being stored on TF config files, they could also be a 2nd QR on the card. Like multi-sig config and that sort of thing. In this way the device auto-configures to the card to some degree. --- Edit: To answer your second question and re-enforce an earlier statement, I will probably never again generate keys on any single current hardware device, though I might use one device to get seeds for another. Generally I will probably suck it up and do them more or less by hand which is tedious as fuck. After some research I may trust /dev/random on certain operating systems, but only if I can not let the video hardware (much less copy/paste buffer) see them. Edit: As a way to get rid of a screen large enough to return a signed transaction via [bb]qr, I just remembered something I dicked around with a few years ago: ggwave: https://www.youtube.com/watch?v=aj_GLBtU3VwActually, ' dicking around with' is a little bit generous. I bought some but never even got around to even making them operate. Anyway, it would seem another tool in an air-gap toolbox. And, if a device started covertly exfiltrating private key material, one should at least hear it.
|
sig spam anywhere and self-moderated threads on the pol&soc board are for losers.
|
|
|
Wind_FURY
Legendary

Activity: 3752
Merit: 2220
|
 |
Today at 07:52:49 AM |
|
I imagine there is likely more than one class action being cooked up. Would they have deep enough pockets for this? I can imagine they spent a lot of money on marketing, sales and the actual product, while they didn't sell that many devices. So if all buyers want their money back, they don't have that amount. If the victims want their losses compensated, they won't have that kind of money it either. I wonder if they will be able to find the users who now hold those 1500 btc. One small mistake when spending, even in a kyc free exchange (like an ip leak), might expose their identities Tell will tell if someone from coldcard is involvedThat ColdCard CTO who made an anonymous account and he was talking to the account - HIMSELF, in Github is already a red flag in my opinion. This issue should definitely be investigated. Users have lost their savings because of developer-INCOMPETENCE or developers being BAD ACTORS.
|
| .SHUFFLE.COM.. | ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ | ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ | . ...Next Generation Crypto Casino... |
|
|
|
rubencb28
Newbie

Activity: 4
Merit: 1
|
 |
Today at 09:08:09 AM |
|
Coldcard is responsible for this
|
|
|
|
|
tvbcof
Legendary

Activity: 5306
Merit: 1344
|
 |
Today at 09:25:13 AM |
|
I am not a lawyer, but according to the official story (which studiously avoids any 'conspiracy theories') I'm not really sure I see a crime here. ...
You don't see a crime in transfering 1500 BTC (millions of dollars) from random people to your own wallet? What are you talking about. Shades of the Owens/Wilson debate here. 'Can you name a charge?' Of course I am playing devil's advocate (aka, trolling) to some degree, but it's also a serious question to answer prior to contemplating legal action. It is the same as hacking a bank app and transferring money to your own account.
Here is my opinion from a bona-fide O.G. standpoint. There is a huge difference in that fiat currency is, pretty much by definition, backed by the state. They have an obligation to expend resource in defense of their authorization of chosen central bank's 'liability' (which is what we call money.) Such a thing was never expected and never requested by the Bitcoin community (in earlier times at least) and 'we' would do nothing but laugh in the faces of those who lost their savings through, say, inflation. Or 'bail-ins'. If the state enforcement apparatus is required to expend resources to recover funds from hardware wallet mis-haps then they have every right to demand that all such devices are submitted for public use certification prior to use. I would hope to hell that very very few people would want that. The 'law' in Bitcoinland has always been ' not your keys, not your coin', and very few people would have missed that message...though more than a few may have not dwelt on it long enough to have imparted meaningful mental impact. I would be amenable to the argument that stealing _anything_ is illegal, and since we all pay taxes, we all deserve efforts by the state to to right such a wrong in a general sort of a way. (If I were the opponents attorney I would argue that the plaintiff dropped the items in question on the ground and the accused simply picked them up.) I just wouldn't bet a lot of money that a lot of effort and resources would be expended. Now, if things progress into ' conspiritard territory' and evidence of collusion between some of the parties emerges, we very well may be looking at some serious charges. But we are not there yet as far as I can see, and with everyone chasing their tails, I seriously doubt that we ever will be.
|
sig spam anywhere and self-moderated threads on the pol&soc board are for losers.
|
|
|
EstherBtc
Member


Activity: 71
Merit: 10
No Intimidation
|
 |
Today at 10:06:18 AM |
|
Would they have deep enough pockets for this? I can imagine they spent a lot of money on marketing, sales and the actual product, while they didn't sell that many devices. So if all buyers want their money back, they don't have that amount. If the victims want their losses compensated, they won't have that kind of money it either.
I wonder if they will be able to find the users who now hold those 1500 btc. One small mistake when spending, even in a kyc free exchange (like an ip leak), might expose their identities Tell will tell if someone from coldcard is involved Well, there are indications that the hacker made a mistake and exposed information about himself. Activities were recognised where the operator used a paid account on a "well-known" blockchain service. A pattern of querying the original addresses was observed during the attack and this was repeated. https://www.cryptotimes.io/2026/08/19/block-and-galaxy-research-give-lead-to-law-enforcement-in-111m-coldcard-bitcoin-theft/Now that they already traced the hacker, its good to see what other action they made. Because many people are so curious about this case, they want those people involve in this hacking issue to get captured. Maybe this is also the reason why the funds stolen has left unmoved? https://crypto.news/coldcard-hackers-leave-87-of-stolen-bitcoin-unmoved-after-114m-theft they are maybe afraid to do transaction because it can create fresh traces to the authorities. They should act fast, so they can still recover the funds and return it back to those proven victims. The question now remains, how will the victims prove that their bitcoin was stolen? Since there is no kyc to be able to identify owners?
|
|
|
|
|
ryzaadit
Legendary

Activity: 3304
Merit: 1440
|
 |
Today at 10:28:25 AM Last edit: Today at 12:28:12 PM by ryzaadit |
|
Now that they already traced the hacker, its good to see what other action they made. Because many people are so curious about this case, they want those people involve in this hacking issue to get captured.
Doesn't mean those are the exploiters. Have you realized the exploiters tried to mask the transaction with CoinJoin transactions and peel chains? Do you think he's not gonna to use other people's identities, especially for using a service from a centralized service like an exchange. Most likely, the only thing they can catch is the funds, by freezing the asset cause the exploiters most likely gonna to use other people's identities. The question now remains, how will the victims prove that their bitcoin was stolen? Since there is no kyc to be able to identify owners?
There are so many ways for victim to proof the ownership of the stolen coins. Example: - Holding the address has been drained by exploiters.
- Owning the device has been affected.
And by the device, they can make data input from: purchase records during the transaction of the device, serial number, firmware update to the device, some other factor related to the device. - If your BTC comes from buying, then you can show the transaction of the purchase from the exchange compared with an on-chain transaction at the time you send to your address.
- If your BTC comes from mining: can be obtained from mining pool records, and some other factors are related to the mining activity you're doing.
You could ask me, but there could be some people already owning the address since the address has been exposed. Yes, and then it's up to the court to decide which one has the strongest claim. Coinkite release their first hardware wallet Mk1 on 8 December 2017. Those years, are the years we already seeing so much service related to the crypto (exchange, wallet, and others) We are not on the years 2009-2011. Prety sure everyone send their BTC from exchange transaction or their wallet address, and with that's simple proofs comparing to on-chain transaction should easy enough to qualify "who-is-who" the real owner of the address drained and who is having strongest claim.
|
| EARNBET | | | ⚽ 🏀 🏈 🏓 🎯 🥊 |
| ⚾ 🎾 ⛳ 🏐 🏏 🏎️ | | |
███████▄▄███████████ ████▄██████████████████ ██▄▀▀███████████████▀▀███ █▄████████████████████████ ▄▄████████▀▀▀▀▀████████▄▄██ ███████████████████████████ █████████▌████▀████████████ ███████████████████████████ ▀▀███████▄▄▄▄▄█████████▀▀██ █▀█████████████████████▀██ ██▀▄▄███████████████▄▄███ ████▀██████████████████ ███████▀▀███████████ | ....HIGHEST.... VIP REWARDS ✔ G U A R A N T E E D
| | | 🜲 | KING OF THE CASTLE $200K in prizes | | | ..PLAY NOW.. |
|
|
|
|