Bitcoin Forum
August 27, 2026, 03:48:13 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 [31]
  Print  
Author Topic: Large-scale Coldcard compromise (1596 BTC stolen so far)  (Read 10480 times)
bitmover
Legendary
*
Offline

Activity: 3136
Merit: 7687


Trêvoid █ No KYC-AML Crypto Swaps


View Profile WWW
August 26, 2026, 10:52:27 AM
 #601

The question now remains, how will the victims prove that their bitcoin was stolen?
Since there is no kyc to be able to identify owners?

This is what signing a message was created for.

But, other people could have the keys as well.

They could have saved the receipt of their coldcard together with the signed message.

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|  BTC     XMR  
  DAI     LTC  
   Fees  0.8%    
suzanne5223
Hero Member
*****
Online Online

Activity: 3416
Merit: 754


Want top-notch marketing for your brand, Hire me


View Profile WWW
August 26, 2026, 08:17:30 PM
 #602

I imagine there is likely more than one class action being cooked up.
Would they have deep enough pockets for this? I can imagine they spent a lot of money on marketing, sales and the actual product, while they didn't sell that many devices. So if all buyers want their money back, they don't have that amount. If the victims want their losses compensated, they won't have that kind of money it either.

I wonder if they will be able to find the users who now hold those 1500 btc. One small mistake when spending, even in a kyc free exchange (like an ip leak),  might expose their identities

Tell will tell if someone from coldcard is involved


That ColdCard CTO who made an anonymous account and he was talking to the account - HIMSELF, in Github is already a red flag in my opinion.

This issue should definitely be investigated. Users have lost their savings because of developer-INCOMPETENCE or developers being BAD ACTORS.
Yes, he's a red flag, but we can talk about the unprofessional service provided by the Coldcard team and not talk about people who spent weeks assisting Bitcoin holders who were affected by the Coldcard vulnerability by helping them to transfer their funds to safety, with the estimation of tens of millions of dollars worth of BTC protected during the period the Coldcard vulnerability occurred.
https://x.com/BitcoinNewsCom/status/2092703792944808228

▄▄███████████████████▄▄
▄███████████████████████▄
███████████████████████
████████▀▀▀▀██▀█▄▀███████
███▀▀██▄▄██▄██▌▄▄▄▄▄██
████▄█████▐██▀▄█▀▀█████
█████▌██▀▀▄█▀██▄██▄███
██▄▄▄▄███████████▐███████
████████▐█████████▀▀█████
███████▄██████▀█▄▄▄▄▄████
███████████████████████

▀███████████████████████▀
▀▀███████████████████▀▀

 Kings Game  
 
 🎰   🎲   ⚽ 
████
██
██
██
██
██
██
██
██
██
██
██
████
████████████████████████████


RAKEBACK
..UP TO 30%..
████████████████████████████
████
██
██
██
██
██
██
██
██
██
██
██
████
████
██
██
██
██
██
██
██
██
██
██
██
████
████████████████████████████
 
..500%..
WELCOME BONUS
+ 250 FREE SPINS
████████████████████████████
████
██
██
██
██
██
██
██
██
██
██
██
████

   WIN NOW     
ryzaadit
Legendary
*
Offline

Activity: 3304
Merit: 1441



View Profile WWW
Today at 04:02:11 AM
Merited by vapourminer (1)
 #603

This is what signing a message was created for.
But, other people could have the keys as well.
-snip
How about the signed message from the previous transaction before the sweeps?

Pretty sure the majority of the addresses are dormant addresses before they got sweeps, people are usually send their BTC after they got the hardware wallet > created the seed & wallet  > then send the BTC > and leave it for such a long time.

They fill it the fund with either sending from another address or buying it from the exchange.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D  
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
retreat
Hero Member
*****
Offline

Activity: 1848
Merit: 547


Rollbit.com | Crypto's Most Rewarding Casino


View Profile WWW
Today at 04:33:55 AM
Merited by vapourminer (1)
 #604

Just reading this on reddit. It seems the hacker is trying to move the money but still not smart enough to do that.


https://www.reddit.com/r/coldcard/comments/1vy9ekz/coldcard_hacker_discovered_mixers_and_is_doing_a/

I bet that hacker is scratching his head right now thinking of a way to get the money out without being traced.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT|
4,000+ GAMES
███████████████████
██████████▀▄▀▀▀████
████████▀▄▀██░░░███
██████▀▄███▄▀█▄▄▄██
███▀▀▀▀▀▀█▀▀▀▀▀▀███
██░░░░░░░░█░░░░░░██
██▄░░░░░░░█░░░░░▄██
███▄░░░░▄█▄▄▄▄▄████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
█████████
▀████████
░░▀██████
░░░░▀████
░░░░░░███
▄░░░░░███
▀█▄▄▄████
░░▀▀█████
▀▀▀▀▀▀▀▀▀
█████████
░░░▀▀████
██▄▄▀░███
█░░█▄░░██
░████▀▀██
█░░█▀░░██
██▀▀▄░███
░░░▄▄████
▀▀▀▀▀▀▀▀▀
||.
|
▄▄████▄▄
▀█▀
▄▀▀▄▀█▀
▄░░▄█░██░█▄░░▄
█░▄█░▀█▄▄█▀░█▄░█
▀▄░███▄▄▄▄███░▄▀
▀▀█░░░▄▄▄▄░░░█▀▀
░░██████░░█
█░░░░▀▀░░░░█
▀▄▀▄▀▄▀▄▀▄
▄░█████▀▀█████░▄
▄███████░██░███████▄
▀▀██████▄▄██████▀▀
▀▀████████▀▀
.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
░▀▄░▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄░▄▀
███▀▄▀█████████████████▀▄▀
█████▀▄░▄▄▄▄▄███░▄▄▄▄▄▄▀
███████▀▄▀██████░█▄▄▄▄▄▄▄▄
█████████▀▄▄░███▄▄▄▄▄▄░▄▀
███████████░███████▀▄▀
███████████░██▀▄▄▄▄▀
███████████░▀▄▀
████████████▄▀
███████████
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▀▄███░░░▀████░███▄▀██▄
███░████░░░░░▀██░████░███
███░████░█▄░░░░▀░████░███
███░████░███▄░░░░████░███
▀██▄▀███░█████▄░░███▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
OFFICIAL PARTNERSHIP
SOUTHAMPTON FC
FAZE CLAN
SSC NAPOLI
Wind_FURY
Legendary
*
Offline

Activity: 3752
Merit: 2220



View Profile
Today at 05:29:44 AM
 #605

Just reading this on reddit. It seems the hacker is trying to move the money but still not smart enough to do that.


https://www.reddit.com/r/coldcard/comments/1vy9ekz/coldcard_hacker_discovered_mixers_and_is_doing_a/

I bet that hacker is scratching his head right now thinking of a way to get the money out without being traced.


The "hacker" should have used ThorChain, and swapped the stolen Bitcoin to Monero starting in Day Zero and continued that when more Bitcoin is stolen.

But the hacker's current move is good to test how those mixers are good in obfuscation. For that purpose, they should probably test CoinJoin too.

██████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
██████████████████████
.SHUFFLE.COM..███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
█████████████████████
████████████████████
██████████████████████
████████████████████
██████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
██████████████████████
██████████████████████
██████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
.
...Next Generation Crypto Casino...
joker_josue
Legendary
*
Offline

Activity: 2492
Merit: 7417


**In BTC since 2013**


View Profile WWW
Today at 06:39:36 AM
 #606

The "hacker" should have used ThorChain, and swapped the stolen Bitcoin to Monero starting in Day Zero and continued that when more Bitcoin is stolen.

But the hacker's current move is good to test how those mixers are good in obfuscation. For that purpose, they should probably test CoinJoin too.

For that to happen, he needed to have planned for the possibility of acquiring that large amount of Bitcoin.

He probably didn't expect to be so successful, and the fact that he was discovered just a few hours later didn't even give him time to think of a solution.

That's a lot of money; he's going to have to use many, many tools to "launder" all that cash, especially now that there are a thousand eyes on him.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
Pmalek
Legendary
*
Offline

Activity: 3598
Merit: 9490



View Profile
Today at 07:02:08 AM
 #607

How about the signed message from the previous transaction before the sweeps?

Pretty sure the majority of the addresses are dormant addresses before they got sweeps, people are usually send their BTC after they got the hardware wallet > created the seed & wallet  > then send the BTC > and leave it for such a long time.

They fill it the fund with either sending from another address or buying it from the exchange.
That's a big if. Bitcoins exchange hands and ownership all the time. Prior to sending the coins to a Coldcard, they could have belonged to another person - the seller who sold the Coldcard owner their coins. They could have been acquired in a P2P trade where there are no records that can be used as proof. The coins could have been bought at an exchange, which has in the meantime shut down. But even if it hasn't shut down, you can't sign a message from such an address because the service owns the keys, not the end user.

Only some victims would be able to acquire the needed digital proof.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
mabji1
Newbie
*
Offline

Activity: 33
Merit: 0


View Profile
Today at 07:04:55 AM
 #608

https://www.blockchain.com/explorer/addresses/btc/bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r

So intelligent, yet so foolish  Smiley
bitmover
Legendary
*
Offline

Activity: 3136
Merit: 7687


Trêvoid █ No KYC-AML Crypto Swaps


View Profile WWW
Today at 08:54:36 AM
 #609


The "hacker" should have used ThorChain, and swapped the stolen Bitcoin to Monero starting in Day Zero and continued that when more Bitcoin is stolen.

But the hacker's current move is good to test how those mixers are good in obfuscation. For that purpose, they should probably test CoinJoin too.

Thorchain website isn't working right now, and no monero support


I am not sure how you can access it without the front end , but it should be possible. Actually, using the front end would be quite dangerous for him because it could save logs.

He probably didn't expect to be so successful, and the fact that he was discovered just a few hours later didn't even give him time to think of a solution.

That's a lot of money; he's going to have to use many, many tools to "launder" all that cash, especially now that there are a thousand eyes on him.

He could have stealing 5-10 bitcoin per month for a few months, nobody would have noticed and blamed coldcard.

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|  BTC     XMR  
  DAI     LTC  
   Fees  0.8%    
bitbollo
Legendary
*
Offline

Activity: 4088
Merit: 5001


https://bit.ly/bitbollo


View Profile
Today at 09:39:53 AM
 #610

Probably this was already happening since there are severeal online claims of users that have their btc lost using this hardware.
... nobody would have noticed and blamed coldcard.
it could be not excluded that they have just collected the majority of the keys before claiming the whole attack.
it worth mention that there are more "patterns" of attackers, probably there isn't only one cluster/user.

[I read some retard comment about "white hacker" trying to using the same exploit for "save bitcoin from the black hacker" Roll Eyes ]

The amount stolen doesn't look so basic or easy to hide.
Probably we are just not ready to understand and assimilate this issue...
The first has been to underestimate the risk on rely on third parties.
The second has been completely voided the concept of trust - I trust another entity making hardwares and not just my self using a tutorial
Third, if bitcoin would become what we are expecting, it's clear that any amount could become impressively precious.
Forth (worst point) this has been used as wrench for attacking self custody and continue to blame on people that want have their sovereignity managing bitcoin in totally autonomy.

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|..BTC......XMR...
..USDT.....LTC...
....Fees  0.8%.....
ultrloa
Legendary
*
Offline

Activity: 3486
Merit: 1473



View Profile WWW
Today at 11:04:04 AM
 #611

Just reading this on reddit. It seems the hacker is trying to move the money but still not smart enough to do that.


https://www.reddit.com/r/coldcard/comments/1vy9ekz/coldcard_hacker_discovered_mixers_and_is_doing_a/

I bet that hacker is scratching his head right now thinking of a way to get the money out without being traced.

They already done this before.

Quote
Blockchain security firm CertiK has detected that approximately 64 Bitcoin (worth $4.17 million)** and **200 Ether (worth $380,000) linked to the Coldcard attack were transferred to cryptocurrency mixing protocols this week .

https://www.coinainews.com/2026/08/coldcard-hackers-move-45-million-to.html

But they are been flagged now and this is the reason why they are stuck then struggle to pull out their stolen funds. They are provably afraid to move those stuck funds, because by the time they do it for sure they might get tracked by entities investigating this case.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT|
4,000+ GAMES
███████████████████
██████████▀▄▀▀▀████
████████▀▄▀██░░░███
██████▀▄███▄▀█▄▄▄██
███▀▀▀▀▀▀█▀▀▀▀▀▀███
██░░░░░░░░█░░░░░░██
██▄░░░░░░░█░░░░░▄██
███▄░░░░▄█▄▄▄▄▄████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
█████████
▀████████
░░▀██████
░░░░▀████
░░░░░░███
▄░░░░░███
▀█▄▄▄████
░░▀▀█████
▀▀▀▀▀▀▀▀▀
█████████
░░░▀▀████
██▄▄▀░███
█░░█▄░░██
░████▀▀██
█░░█▀░░██
██▀▀▄░███
░░░▄▄████
▀▀▀▀▀▀▀▀▀
||.
|
▄▄████▄▄
▀█▀
▄▀▀▄▀█▀
▄░░▄█░██░█▄░░▄
█░▄█░▀█▄▄█▀░█▄░█
▀▄░███▄▄▄▄███░▄▀
▀▀█░░░▄▄▄▄░░░█▀▀
░░██████░░█
█░░░░▀▀░░░░█
▀▄▀▄▀▄▀▄▀▄
▄░█████▀▀█████░▄
▄███████░██░███████▄
▀▀██████▄▄██████▀▀
▀▀████████▀▀
.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
░▀▄░▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄░▄▀
███▀▄▀█████████████████▀▄▀
█████▀▄░▄▄▄▄▄███░▄▄▄▄▄▄▀
███████▀▄▀██████░█▄▄▄▄▄▄▄▄
█████████▀▄▄░███▄▄▄▄▄▄░▄▀
███████████░███████▀▄▀
███████████░██▀▄▄▄▄▀
███████████░▀▄▀
████████████▄▀
███████████
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▀▄███░░░▀████░███▄▀██▄
███░████░░░░░▀██░████░███
███░████░█▄░░░░▀░████░███
███░████░███▄░░░░████░███
▀██▄▀███░█████▄░░███▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
OFFICIAL PARTNERSHIP
SOUTHAMPTON FC
FAZE CLAN
SSC NAPOLI
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 [31]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!