Bitcoin Forum
September 17, 2026, 08:23:25 AM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 [37] 38 »
  Print  
Author Topic: Large-scale Coldcard compromise (1596 BTC stolen so far)  (Read 12809 times)
LoyceV
Legendary
*
Offline

Activity: 4172
Merit: 22711


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
September 07, 2026, 07:16:16 AM
Merited by vapourminer (1), Lucius (1)
 #721

This goes to show that they lack empathy for the victims of this attack.
It sounds more like they're trying to hide reality from followers, so they can still sell their risky product.

I mean: I'm not going to link it, but have you seen their website?
  • Red warning banner: Security update for the firmware.
  • Large font: "Bitcoin Security and Fun Devices"
  • VIEW STORE
  • Made in Canada
  • founded in 2012
  • tools for self-custody
  • a personal data haven for critical secrets
  • Bitcoin-only security
  • Air-gapped workflows
  • Security & transparency
  • product guide
  • Why we keep them separate
  • Made with heart by ~
Nothing in this screams: "our customers got robbed!". It's almost as if they don't want people to know 1596 BTC was stolen from their shitty devices!

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
tvbcof
Legendary
*
Offline

Activity: 5320
Merit: 1367


View Profile
September 07, 2026, 07:38:31 AM
Merited by vapourminer (1)
 #722

They can share three letters with another word, and may be complete in three-letter form.  'air' and 'airplane' come to mind.
They can share the same three letters, yes, but I was talking about four letters being needed. 'Air' and 'airplane' share the same first three letters but the fourth letter, 'p' isn't present in 'air' or in any other word of the BIP39 wordlist. Therefore, the moment you start typing 'airp' to recover a wallet created on that standard, 'airplane' is the only word that fits in that position.

Of course.  I'm not saying that there is some sort of a terminal flaw in the theoretical logic.  That would be silly.  I am saying that it would have been better to avoid any such situations which could complicate user implementations or create human question marks in dusty old punched plates.  At least make it so that a null character is not necessary to account for in a 'first 4 character set' if one has the choice.  But I did not design BIP-39 (or any of the word sets) so maybe those who did have considerations which I'm not thinking of.  Maybe it was just damn difficult to find enough words?

Relatedly, consider an implementation which I have seen a number of times with CCQ where auto-completion intending to type in word autocompletes at the 2nd or 3rd letter and auto-increments to the next word and the last part of one word becomes the first part of the next.  This can bite on the last word, which is a checksum and more significantly limited in selection size.  A single letter mis-typed due to auto-completion of the previous word can auto-complete a word completely.  Then the total solution is considered valid.  If the code continues upon solution, then the code needs to have the ability to reliably create a show-state confirmation and means of editing reliably to fix problems.

Indeed, maybe a human interface device requiring one to fiddle with a few buttons in input a full 24 word list on a limited line display is a 'feature' after all insofar as the user cannot work fast enough to make certain kinds of mistakes.  Ergo, a usable keypad is a bug and not a feature.

Admittedly, with the consensus view in the community being a model where users only need one seed (or several in multi-sig) which controls their entire wealth, then it doesn't matter so much if reliable input is a bitch.


sig spam anywhere and self-moderated threads on the pol&soc board are for losers.
Cricktor
Legendary
*
Offline

Activity: 1610
Merit: 4478



View Profile
September 07, 2026, 11:39:14 AM
Merited by LoyceV (8), Pmalek (3)
 #723

...
They don't want honest feedback and a mostly negative narrative. This is the ugly face of corporate damage control.


...
Same here, heavily lawyer scrutinized corporate damage control. I'm not really surprised to see what can be seen on their website. They will not admit, they fucked up and consequently had customers who used their defective firmware to create weak entropy wallets and subsequently lost their coins to malicious actors. They won't pour fuel into potential lawsuit fires against them.

Do I like it? Definitely not! Coinkite can burn down to ashes, same as Ledger, none of both companies will see any money from me. I don't trust both, that's it.

Can anybody trust a company that babbles about security and is negligent to ever check their own firmware code to actually produce decent and secure entropy? Coinkite apparently didn't for years with their defective firmware after "hasty" GPL code cleanup to deprive others to use their code base for commercial products. Hypocrites!

avp2306
Hero Member
*****
Offline

Activity: 1820
Merit: 640


Latest promotion? Go to contesthunters.com


View Profile
September 07, 2026, 11:58:25 PM
Merited by vapourminer (1)
 #724

...
Same here, heavily lawyer scrutinized corporate damage control. I'm not really surprised to see what can be seen on their website. They will not admit, they fucked up and consequently had customers who used their defective firmware to create weak entropy wallets and subsequently lost their coins to malicious actors. They won't pour fuel into potential lawsuit fires against them.

Do I like it? Definitely not! Coinkite can burn down to ashes, same as Ledger, none of both companies will see any money from me. I don't trust both, that's it.

Can anybody trust a company that babbles about security and is negligent to ever check their own firmware code to actually produce decent and secure entropy? Coinkite apparently didn't for years with their defective firmware after "hasty" GPL code cleanup to deprive others to use their code base for commercial products. Hypocrites!

I think this is the best thing they could do, since maybe they cannot afford to refund their clients affected by this hacking incident.

But if people would pursue a case against them, its really possible for those affected user to demand a refund to Coinkite, knowing that there's solid evidence that they are been affected by their faulty firmware.

I read this article and maybe affected user try to look at this route, To ask for refund from Coinkite https://ferrer-bonsoms.com/en/the-coldcard-case-how-to-claim-compensation-if-your-hardware-wallet-was-drained-by-the-firmware-flaw

Also better for people not to buy their products anymore, because its so clear that they are avoiding being accountable on that issue.

██████████████████████████████████████████████████████████████████
█████████▄███████▄▄█████████████▄▄█████████████████▄▄█████████████
████████▐██▀████▀▀█████████████▐██▀███████████████▐██▀████████████
██████████▌██████▄██▄▄▄▄████▄▄▀██▄▄▄▄▄▄███████▄▄▀███▄▄▄████████
████████▀██▄████▀▀▀▄███▀████▄██▀████████▌█████▄██▀▄██▀█▄███████
██████████▀██▄█████▄██▀▄▄██▄██▀███▀████▌█████▄██▀██▀▄█████████
███████▄▄▄██▀██▄██▐██▀▀██▌▄██▀███▀████▌▄███▄██▀██▀▐█▀█▄██████
████████▀███████████████▀▀██████▀████▌▄████▐██▌███▌█████▀▀█████
███████▌█████▐██▌▐███▄██▀██▀███▀█▌███▐███▀▄▄▀███▀███▄█▀█████████
█████▀██▄▄▄▄███▀██▌▀▀█████▀▀███████▀▀██▐█▀██▀▀███▀▀▀███████████
████████▀▀▀▀▀███▐█████████████████████████████████████████████████
██████████████████▌███████████████████████████████████████████████
██████████████████████████████████████████████████████████████████












████
▀▀▀▀
████
████

▄▄▄▄
████
▀▀▀▀
████
████

▄▄▄▄
████
▀▀▀▀
████
████
▄▄▄▄
████
▀▀▀▀

████
████
▄▄▄▄
████
▀▀▀▀

████
████
▄▄▄▄
████
























████
▄▄▄▄
████
▀▀▀▀

████
████
▄▄▄▄
████
▀▀▀▀

████
████
▄▄▄▄
████
████
▀▀▀▀
████
████

▄▄▄▄
████
▀▀▀▀
████
████

▄▄▄▄
████
▀▀▀▀
████













..BET NOW..
Meuserna
Sr. Member
****
Offline

Activity: 377
Merit: 683


View Profile WWW
September 11, 2026, 07:37:15 PM
 #725

Has anybody done analysis on the wallets that were found, in terms of how the wallets were generated?

Were most of them 12 word seed phrases? What percent were 24 word seed phrases?

I used to think 24 word seed phrases were overkill, but I use them anyway... because why not?

But now, I realize that a 24 word seed phrase helps protect you from less than optimal randomness, simply because it's exponentially harder to crack a 24 word seed phrase. Granted, with true randomness, a 12 word seed phrase is uncrackable. But, still... an extra ounce of prevention is worth 21 million pounds of cure.

These days, my recommendation is: 24 word seed phrase with 7 words or more as a passphrase, on a hardware wallet/signer that is fully open source, airgapped, stateless, and encrypted. Overkill? That depends on how important your Bitcoin is to you, I guess.

TheDigitalMan
Jr. Member
*
Offline

Activity: 56
Merit: 37


View Profile
September 12, 2026, 08:31:02 AM
 #726

I have been following this incident with some interest.  What I would like to analyze is an actual seed phrase that was compromised.  Is there anyone that has shared their Coldcard generated Seed Phrase?  I'm talking about one that had the bitcoin drained out of it.  I would like to reconstruct the entropy to see how it looks.  If anyone has a seed phrase generated by the Coldcard that doesn't have any funds in it, I would be interested in a copy of it.  I really want to look at the seed phrases that were involved in the actual exploit if possible.  I suppose I could write my own python script to emulate what the attacker did and run it until I uncovered accounts that had been drained.  Then I would have the seed phrase for that account.  Before I go to that effort I thought I might ask nicely and see if anyone would be willing to share?  Thank you so much for taking the time to read this post.  I am working on a security related project and would really like to analyze the entropy used in some of the Coldcard's compromised accounts.  Cheers.
LoyceV
Legendary
*
Offline

Activity: 4172
Merit: 22711


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
September 12, 2026, 09:11:54 AM
Merited by vapourminer (1)
 #727

I would like to analyze is an actual seed phrase that was compromised.
You don't need an actual compromised seed phrase for that: Just recreate one seed phrase in the same way using the weak entropy, and you'll have everything you need.

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
Meuserna
Sr. Member
****
Offline

Activity: 377
Merit: 683


View Profile WWW
September 12, 2026, 08:48:01 PM
Merited by vapourminer (1)
 #728

I would like to analyze is an actual seed phrase that was compromised.
You don't need an actual compromised seed phrase for that: Just recreate one seed phrase in the same way using the weak entropy, and you'll have everything you need.

Exactly.

The ColdCard seeds won't look wrong. They'll look like perfectly random seed phrases. The issue is, the possibilities come from a significantly smaller subset. It's still billions upon billions of possibilities... but it should be beyond quadrillions upon quadrillions upon quadrillions of possibilities.

BTC-BACKPACKER
Newbie
*
Offline

Activity: 2
Merit: 0


View Profile
September 12, 2026, 08:56:14 PM
 #729

I've seen a lot of people still using the "Q" as a signing device , they state that the Q is a great device as long as you properly generate your seed phrase and not rely on random number generators ....are they wrong ?
Meuserna
Sr. Member
****
Offline

Activity: 377
Merit: 683


View Profile WWW
September 12, 2026, 10:31:10 PM
Merited by LoyceV (4)
 #730

I've seen a lot of people still using the "Q" as a signing device , they state that the Q is a great device as long as you properly generate your seed phrase and not rely on random number generators ....are they wrong ?

Once you know code can't be trusted, you'd be a fool to trust it. Oh, but they fixed it? Suuure.

Fool me once, shame on you.
Fool me twice, shame on me.

Only you can decide how to secure your Bitcoin, but there will never be a day I'd trust mine to ColdCard.

TheDigitalMan
Jr. Member
*
Offline

Activity: 56
Merit: 37


View Profile
September 13, 2026, 01:02:50 AM
 #731

I would like to analyze is an actual seed phrase that was compromised.
You don't need an actual compromised seed phrase for that: Just recreate one seed phrase in the same way using the weak entropy, and you'll have everything you need.

I would like to do that. How could I go about it? It is my understanding that the code was closed source. Obviously if I had owned a Coldcard and still had the old firmware loaded on it I could create one.  But I do not or ever have owned a Coldcard. Anyway, I would like to recreate one seed phrase in the same way using the weak entropy. I'll admit, I do not know how to do that? Could you point me in the right direction as to how I might do that? Thanks.
JayJuanGee
Legendary
*
Offline

Activity: 4564
Merit: 15016


Self-Custody is a right. Say no to "non-custodial"


View Profile
September 13, 2026, 01:14:42 AM
Merited by Pmalek (3), tvbcof (2), ryzaadit (2), Cricktor (2)
 #732

The release notes also repeat the thing that keeps getting lost in these threads. Installing it does not make an existing seed safe. If the seed was generated on affected firmware between 2021 and July this year, it is the same seed after the update as before it, and the fix is a new seed on fixed firmware plus moving the coins.  Wink
Nothing can make an existing seed safe. A seed phrase can't be changed, and ColdCard seeds were guessable.

Changing a seedphrase creates a new wallet and it does not do anything for the existing wallet and seedphrase.

Does the above highlight help?
My bad! So we agree!

I absolutely disagree with the idea of keeping the Coldcard, though. If you haven't lost any funds, I'd consider moving them to a reputable signing device like SeedSigner, and throw that thing to the trash.
Let me make it clear that I don't recommend that anyone other than highly technical people do anything with any of Coinkite's products.  I consider them unsafe.  Yes, it's 'playing with fire', but at the same time, so is playing with ANY hardware device at this point in time. 

Nope.

Just because Cold Card showed a very high level of vulnerability, arrogance and stupidness, that does not put all hardware wallets into the same category.

Frequently I find relativistic arguments that put similar categories of items in the same group to be close to retarded.  It is like seeing some politicians as corrupt and evil and then also seeing that a variety of other politicians showing similar corrupt and evil attributes, and then proclaiming that all politicians are the same, when they are not.  Some are more corrupt and evil than others, and some are not corrupt and/or evil.

Similar arguments can be made in regards to hardware wallets.  Some have greater vulnerabilities than others, and some even have corrupt and/or evil players, such as the coinkite team has shown themselves to be (at least NVK and the CTO and maybe some others on the team who were in a position of knowing about the various RNG vulnerabilities and not doing anything about it).

Indeed, playing with Bitcoin itself is now and always has been 'playing with fire.'

That is a bit much @tvbcof.  You must have difficulties viewing some of the nuances of the world.  Everything in the world is not black or white.

SeedSigner has the distinct advantage of letting the user have more control of the supply chain.  The potential in-built weakness (at the 'pi' or processor level) are unlikely to be narrowly targeted toward subverting crypto-currency except insofar as they may exist to attack cryptography generally.  I've not researched the SeedSigner project in detail, but I would assume that they now (or will be soon) taking pains to deal with the entropy issue, and there will always be the issues associated with cold attacks on storage of secrets for any hardware device.

I would mention again that I hope people do NOT throw these things in the trash.  They could be useful for further analysis in some sort of an attempt to further understand this fairly devastating attack on the Bitcoin community at large.

I don't have any arguments (enlightened or otherwise) regarding these points.

I am not a lawyer, but according to the official story (which studiously avoids any 'conspiracy theories') I'm not really sure I see a crime here.  Or at least not one which anyone is likely to get more than a slap on the wrist for.  We have:
 - a simple mistake from some device maker/seller,

 - someone(s) found they could obtain shared control of keys represented in a public blockchain and availed themselves of the discovery.

Well under the law there are criminal charges that are brought by the state, and there are civil charges that can be brought by other individuals and/or by the state.

If we presume that you are ONLY referring to criminal law (especially since you used the term "crime," then whether or not there is a violation of a statute or some common law standard, we have to look at the crime that we are alleging to have had taken place to see its the evidence that would be argued to show that a violation that took place - perhaps something like fraud or maybe some other crime could be alleged?  Let's just go through the elements of fraud to figure out how such a crime could be prosecuted:

1) misrepresentation of material facts

CC marketed itself as the gold standard and seems to have had misrepresented how its random number generation was taking place.  

2) knowledge of their misrepresentations

Even if coinkite might not have had know about the flaw in the software, after several complaints of loss of funds they should have had become aware at some point in time prior to July 30, 2026.  there were a lot of customer complaints from 2021 and then also some specific report in May 2025.. so then there was reckless disregard for the truth.  The standard is not negligence as you suggested @tvbcof

3) intent to deceive
This might be a bit of a harder hurdle if we cannot find that Coinkite personally profited.  Even if it were to be argued that a "retirement plan" was in place, it would likely need to be shown that there was an intent to steal the funds by key principles of the company, otherwise maybe if intention was shown to be by key principles, then the individuals might be criminally charged rather than the company.

4) reasonable reliance of the victims on the false statements
This one can probably be easily proved in that many clients relied on the supposed good coinkite security features and the clients took adequate and sufficient measures to secure their coins and to believe that their coins were secure.

5) damage or economic loss
the damage and economic losses were extensive.

So, yeah, 3 is probably the hardest of the elements to show.

At this point there is no provable evidence that either Coinkite deliberately sabotaged their hardware with the intent to defraud, or that there was any collusion between Coinkite and the various parties who picked up the dropped private keys. 

I doubt that the situation is as much of a slam dunk as you are proclaiming it to be, even though prosecutors would have some discretion in regards to whether they believe that they have enough evidence to prosecute.
 
Indeed, it's kind of a weird sin-like thing to even think that way here in 2026.

I personally think it likely that both deliberate sabotage and collusion to engineer a lifting of BTC probably did occur, but that means nothing.  Even if it did, it doesn't seem to me like something which would get anyone into serious trouble...at least in a formal court of law.

 If there is evidence of deliberate sabotage and collusion to engineer a lifting of the BTC, then that would go towards the 3rd element, so yeah, it still might not be clear if the evidence is strong enough to prosecute.
 
Actually, foreknowledge of the hack would possibly yield greater monetary benefit in terms of various kinds of 'insider trading', or in terms of getting compensated (or just a pat on the head for doing God's work) by entities who benefited (e.g., coin custodians who won keys as the whole system shifted away from faith in self-custody), but nobody gets in trouble for that kind of stuff these days.

Sure, insider trading is another kind of a crime, and of course, it would have different elements.  I have not been hearing too much about any claims of insider trading of Coinkite and especially since insider trading rules seem to apply to public companies rather than private companies.  I am pretty sure that Coinkite is a private company.  

1) Self-Custody is a right.  Resist being labelled as: "non-custodial" or "un-hosted."  2) ESG, KYC & AML are attack-vectors on Bitcoin to be avoided or minimized.  3) How much alt (shit)coin diversification is necessary? if you are into Bitcoin, then 0%......if you cannot control your gambling, then perhaps limit your alt(shit)coin exposure to less than 10% of your bitcoin size...Put BTC here: bc1q49wt0ddnj07wzzp6z7affw9ven7fztyhevqu9k
TheDigitalMan
Jr. Member
*
Offline

Activity: 56
Merit: 37


View Profile
September 13, 2026, 12:12:23 PM
 #733

I would like to analyze is an actual seed phrase that was compromised.
You don't need an actual compromised seed phrase for that: Just recreate one seed phrase in the same way using the weak entropy, and you'll have everything you need.

Exactly.

The ColdCard seeds won't look wrong. They'll look like perfectly random seed phrases. The issue is, the possibilities come from a significantly smaller subset. It's still billions upon billions of possibilities... but it should be beyond quadrillions upon quadrillions upon quadrillions of possibilities.

I hear what you are saying but let me ask this.

If there was only 40 bits of entropy then I imagine 40 binary bits such as: 1111111111111111111111111111111111111111, now with all these bits turned on, i.e. set to 1, this number ends up being: 1,099,511,627,775 which is 1 trillion 99 billion etc.  So just over a trillion possibilities which is exactly what you stated earlier, "It's still billions upon billions of possibilities...".  But if I take those 40 binary 1's and add 216 0's in front of them so that I will have enough binary bits to make my 24-word seed phrase I would end up with: abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon avocado zoo zoo zoo zoo wink, for my seed phrase.  I suppose the 0's could be added to the end of the forty 1's.  Let's see what that would do? So the entropy: 1111111111111111111111111111111111111111000000000000000000000000000000000000000 0000000000000000000000000000000000000000000000000000000000000000000000000000000 0000000000000000000000000000000000000000000000000000000000000000000000000000000 0000000000000000000, has a value of: 115792089237210883131902427821989989825586314233321668944057034896658818662400 and would yield the following seed phrase: zoo zoo zoo wrap abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon aerobic

In both cases even when I put all the zero's at the end of the forty one's to make the number larger it still produces 19 iterations of "abandon". This would be a huge red flag I would think.  So I have to assume that while the number of different possibilities the coldcard wallet was generating was in a narrow range of numbers that represented a subset of numbers roughly 1 trillion in size. This subset of numbers was plunked down into the middle of the full ECDSA number range that we are drawing our seeds from? Therefore the seeds looked legitimate and the only thing that made them weak was the fact that every single seed the coldcard wallet generated from March 2021 through July 30 of this year was drawn from that small pool of roughly 1 trillion numbers.  Once that pool was identified it became easy to attack the wallets generated by the coldcard by simply going through all one trillion numbers and looking to see if any of them had bitcoin in them.  So in theory I assume if another hardware wallet had randomly selected a number from that same pool then that persons wallet was technically also put at risk? I'm of the opinion that the seeds themselves were not necessarily bad entropy but rather the fact that all the seeds the wallet generated were in a small window of numbers is what made them weak.  Am I wrong to think this?  Because if there is more I need to learn about entropy I am all ears!  I felt like I understood the seed phrase and the entropy that creates it pretty well.  If I have more to learn then I definately want to learn.  That is part of the reason I wanted to see a seed phrase that was compromised. I was curious to look at the actual binary entropy that made it up.  While this error on Coldcard's part is certainly agregious I am not entirely convinced that the entropy itself was weak. At least not in the sense that the 256 bits represented a weak series of bits. I think the real issue was that the wallet was generating seeds for the last 5 years that all fell within a narrow range of numbers. A range narrow enough that an attacker was able to search through the entire range without requiring any special computing power.

I would love to hear your opinion on my theory.  And if I am misunderstanding anything. Please educate me.  Because I want to fully understand the seed phrase. I feel like I already do. But I am definately open to further education if that is what I need.  Kresp.
Lucius
Legendary
*
Offline

Activity: 4088
Merit: 7793


A swap that needs a hand? zeto.cash@proton.me


View Profile WWW
September 13, 2026, 02:19:15 PM
 #734

~snip~
Nothing in this screams: "our customers got robbed!". It's almost as if they don't want people to know 1596 BTC was stolen from their shitty devices!


Who does that remind you of? The geniuses at Ledger were doing the same thing back in 2020 when that massive data breach occurred, and their famous CEO (Lord of the Rings) called the people who warned about it all sorts of unpleasant names.

It is obvious that a very large percentage of people who have or will have hardware wallets are very bad at understanding what they do and how they do it. Hundreds of thousands of Ledger users continue to use their devices, despite the fact that it is possible to extract their seed phrase remotely and share it with third parties—including any government agency that might ever request it. If that's not pure nonsense, I don't know what else could be.

JayJuanGee
Legendary
*
Offline

Activity: 4564
Merit: 15016


Self-Custody is a right. Say no to "non-custodial"


View Profile
September 13, 2026, 04:58:58 PM
Merited by LoyceV (4), fillippone (3), bitmover (2), vapourminer (1)
 #735

[edited out]
I would recommend at least two steps: using an hardware wallet that hasn’t been using subpar practice, this mean avoid ledger, at least, and using one that supports your own entropy to generate the seed, via dice rolling, for example.
This, before moving to a multivendor, multi sign setup.

I have seen a lot of folks jumping into the promotion of multi-signature, multi-vendor and/or various forms of collaborative custody, which I find to be potentially overly complicated.

And, yeah, perhaps many of us have lost a decent amount of confidence regarding the ways that seeds have been generated, so then there are some kinds of hardware wallets that allow us to add our own entropy.  I also have gained confidence in the use of passphrases, so I think that a passphrase that is at least 12 characters of numbers, letters, capital and symbols would likely provide enough difficulty to make it quite secure, and sure you could add several more characters if you want a bit more difficulty in your passphrase.

...A long and complex passphrase is still non-hackable with today's technology. If a Coldcard-generated seed was additionally protected with a complex passphrase, the BTC would probably not be among the +1500 coins that got stolen. Some 2 and 3-word passphrases got bruteforced. An 8-word passphrase wouldn't be. An 8-word passphrase with numbers, lowercase & uppercase letters, and special characters even less so.
These are two different things and in one case your bitcoin are at risk (like here with coldcard scam...) :
-passphrase or password (bip38) would not help you at all.

Of course a passphrase would have had helped, and it is almost impossible to break into a passphrase that has 12 characters or more that are combined with numbers, letters, upper case and characters.

A custom password used to encrypt and lock a single Bitcoin private key into a secure 58-character string
-extra-word or bip39 (that is not a password but literally part of the seed) yes it's an extra word and not the password it would be used.
Yes a very long string could help but at this point I don't see any reason to have those risks and rely on a third party for a seed generation.

If you choose a sufficiently complex passphrase of 12 characters or more, you have a lot of protections, so I don't see why you are proclaiming such efforts to be futile.

By the way, if I thought that my initial 12 seed words were vulnerable, then surely I would regenerate them and not stick with ONLY the passphrase as a protection, so surely it is better to have the 12-24 seedwords and the passphrase also rather than merely relying on one of them.

1) Self-Custody is a right.  Resist being labelled as: "non-custodial" or "un-hosted."  2) ESG, KYC & AML are attack-vectors on Bitcoin to be avoided or minimized.  3) How much alt (shit)coin diversification is necessary? if you are into Bitcoin, then 0%......if you cannot control your gambling, then perhaps limit your alt(shit)coin exposure to less than 10% of your bitcoin size...Put BTC here: bc1q49wt0ddnj07wzzp6z7affw9ven7fztyhevqu9k
tvbcof
Legendary
*
Offline

Activity: 5320
Merit: 1367


View Profile
September 13, 2026, 05:33:51 PM
Last edit: September 13, 2026, 08:44:35 PM by tvbcof
Merited by vapourminer (1), JayJuanGee (1)
 #736

...

...
Let me make it clear that I don't recommend that anyone other than highly technical people do anything with any of Coinkite's products.  I consider them unsafe.  Yes, it's 'playing with fire', but at the same time, so is playing with ANY hardware device at this point in time.  

Nope.

Just because Cold Card showed a very high level of vulnerability, arrogance and stupidness, that does not put all hardware wallets into the same category.

Arrogance actually can occur when one is way out in front.  I don't necessarily shy away from arrogance, but I do try hard to detect whether it is mis-placed.  It is quite unpleasant after all.  I never saw high degrees of stupidness from Coinkite and do not now.  They seem to have successfully pulled of a pretty ingenious long-con operation AND walked away.  Whatever that is, it's not 'stupidity'.

Allow me to point out that it isn't hard to deduce what kind of spew is likely to get most Bitcoiners juices flowing, nor to drone on about it for hours on end.  Everyone is going to be doing it so it is not a good test of who is trustworthy and who is not.  ~nvk was reasonably good at it and had been doing it for a while.  These things did add incrementally to the credibility of Coinkike wares for better or worse.  Worse in this case.  It is what it is, and everyone involved should always be understanding of these thing.  Me in particular.  I was, and I would have taken it like a man had I been nicked.  If I had been, I'm sure I would have put more resources into getting somewhat more pay-back.

Frequently I find relativistic arguments that put similar categories of items in the same group to be close to retarded.  It is like seeing some politicians as corrupt and evil and then also seeing that a variety of other politicians showing similar corrupt and evil attributes, and then proclaiming that all politicians are the same, when they are not.  Some are more corrupt and evil than others, and some are not corrupt and/or evil.

Similar arguments can be made in regards to hardware wallets.  Some have greater vulnerabilities than others, and some even have corrupt and/or evil players, such as the coinkite team has shown themselves to be (at least NVK and the CTO and maybe some others on the team who were in a position of knowing about the various RNG vulnerabilities and not doing anything about it).

All I am saying is that I cannot know with any degree of confidence about ANY effort.  As for operations, the euphemisms 'the devil you know' and 'out of the frying pan and into the fire' come to mind.

At the end of the day, these are off-line devices which highly limit the attack surface even if ~nvk and associated scumbags are further active.  Understanding how things work (like communications methods, flash updates, random number generation, etc) are satisfactory for ME to continue to use my CCQ (the 1/3 which didn't croak) while I thoroughly evaluate replacements (if any...maybe paper/pencil by-hand solutions, or roll-my-own ones, are eventually deemed the most safe option for me.)  It's also a little fun to troll people here I will admit...

The biggest threat I face is that there may be (past) collusion between Coinkite and the 'independant' wallet developers such that the details of the signed transaction are mis-represented in transaction details.

Indeed, playing with Bitcoin itself is now and always has been 'playing with fire.'

That is a bit much @tvbcof.  You must have difficulties viewing some of the nuances of the world.  Everything in the world is not black or white.

Funny enough, that is exactly what I think about 'you guys'.  That is to say, the reptile-brain '~nvk bad, do not ever touch' sort of mentality.  It is very devoid of nuance to be perfectly honest with you...but good advice just the same.  Again, I advise to stick with the the 'do not touch' way of thinking for most Bitcoin people.  Especially here in 2026.

-snip-: stuff about legal fallout.

We'll just have to wait and see.  I'm not expecting much, and if there is money/politics/religion behind Coinkite's operations I'm even less expecting to see anything happen.  Not even if, by chance, someone stumbled across highly compelling evidence against them.


sig spam anywhere and self-moderated threads on the pol&soc board are for losers.
fillippone
Legendary
*
Online Online

Activity: 3024
Merit: 21486


Duelbits.com - Rewarding, beyond limits.


View Profile WWW
September 13, 2026, 08:45:10 PM
Merited by JayJuanGee (1)
 #737

I have seen a lot of folks jumping into the promotion of multi-signature, multi-vendor and/or various forms of collaborative custody, which I find to be potentially overly complicated.

And, yeah, perhaps many of us have lost a decent amount of confidence regarding the ways that seeds have been generated, so then there are some kinds of hardware wallets that allow us to add our own entropy.  I also have gained confidence in the use of passphrases, so I think that a passphrase that is at least 12 characters of numbers, letters, capital and symbols would likely provide enough difficulty to make it quite secure, and sure you could add several more characters if you want a bit more difficulty in your passphrase.

In the end, a passphrase must be stored as part of the seed, adding some complexity.
For sure, it is way simpler than a multisig, with all the required seed conservation isssues.
I am not sure the larger self-custody community is ready for that. I have doubts about myself, too.

EL MOHA
Hero Member
*****
Offline

Activity: 1260
Merit: 513



View Profile
September 13, 2026, 11:11:34 PM
Merited by vapourminer (4), JayJuanGee (1)
 #738

I have seen a lot of folks jumping into the promotion of multi-signature, multi-vendor and/or various forms of collaborative custody, which I find to be potentially overly complicated.

And, yeah, perhaps many of us have lost a decent amount of confidence regarding the ways that seeds have been generated, so then there are some kinds of hardware wallets that allow us to add our own entropy.  I also have gained confidence in the use of passphrases, so I think that a passphrase that is at least 12 characters of numbers, letters, capital and symbols would likely provide enough difficulty to make it quite secure, and sure you could add several more characters if you want a bit more difficulty in your passphrase.

In the end, a passphrase must be stored as part of the seed, adding some complexity.
For sure, it is way simpler than a multisig, with all the required seed conservation isssues.
I am not sure the larger self-custody community is ready for that. I have doubts about myself, too.

Seriously I will say I get the fear of JayJuanGee in terms of multi signature wallet because in it there is two things that is happening, one is there are wallets that actually serves as one co-signer in some certain set up and this falls in the category of supporting a third party.

Then there is another set up where the owner has the ability to hold and back up the phrases of all the co-signers. If this is done in a single device that’s the three co-signer in 2-of-3 multi sig wallet for example uses the same device to generate their phrases and also sign transactions I will say that the set up is flawed because if the device is infected with any malware then all three co-signers are exposed then. For this set up the best would have been different device or hardware wallet for each co-signer and this then brings up two problems which is cost of buying three of the hardware wallets or even three different devices and then the redundancy of backing up all the three recovery phrases.

The owner would need to have to back up the three phrases in three different places? This is not including the fact that each seed phrase has to be stored in two or three different locations, that’s technically 6 to 9 different locations and that’s redundancy.

For me I think a single sig for an individual with a very strong passphrase will be more effective and easier to safeguard plus will reduce the excess cost on hardware wallets or devices.

Pmalek
Legendary
*
Offline

Activity: 3626
Merit: 9542



View Profile
September 14, 2026, 06:43:10 AM
 #739

I've seen a lot of people still using the "Q" as a signing device , they state that the Q is a great device as long as you properly generate your seed phrase and not rely on random number generators ....are they wrong ?
In theory, they aren't wrong. If you generated your seed phrase from dice rolls or coin flips the proper way and imported that into a Coldcard, you wouldn't have suffered the consequences of their weak entropy generation. If you coupled such a seed phrase with a long and complex passphrase, you would be even safer. But the real question is, why would you stay and keep using the products of a manufacturer that has failed in such a horrible way? Why would you keep using a product from a company that is silencing victims on social media, preventing them from commenting on their posts and banning them so they can't tell others about their experiences? Why would you believe anything that comes out of their mouths when it comes to securing your bitcoin when they have already shown that they can't do that?

...It is my understanding that the code was closed source...
It is not. It's source verifiable. The code is publicly available.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
TheDigitalMan
Jr. Member
*
Offline

Activity: 56
Merit: 37


View Profile
September 14, 2026, 08:50:55 AM
 #740

...It is my understanding that the code was closed source...
It is not. It's source verifiable. The code is publicly available.
[/quote]

Thanks for clarifying.

I would be interested in a copy of the firmware before they fixed it. Would that be available? Do you or anyone know what github account I would look for it on?

I want to generate some of these "weak" seed phrases.  Since I can't seem to get hold of any. I'm just interested in exactly what they look like. I understand I have been told they won't look any different from a normal seed phrase.  I get that.  So I'm trying to understand what range of numbers the wallet was generating the seed phrases from?  I'm interested because I've been working on a project for the last 7 years regarding seed phrases and how to keep them secure.  This incident definately has my attention and I am interested in better understanding exactly what made the seed phrases insecure.  I mean, I know it was because of low entropy. But clearly they weren't generating seed phrases like the ones in my previous post.  So I'm just interested in exactly what the wallet was generating.  Maybe I should offer to buy one if anyone still has a Coldcard wallet with the old firmware on it?

Cheers.

Kresp Rowland
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 [37] 38 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!