Bitcoin Forum
August 01, 2026, 06:18:08 PM *
News: COLDCARD users only: critical vulnerability risks funds stored on COLDCARD devices; immediate action required
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: How did the hackers even discover the vulnerability in the Coldcard wallet?  (Read 78 times)
standardnepo (OP)
Jr. Member
*
Offline

Activity: 43
Merit: 15


View Profile
Today at 10:57:33 AM
Merited by Welsh (1)
 #1

I am trying to understand how they think and how they approach something like this. Did someone notice a suspicious part of the firmware, realise that the randomness was weaker than it should have been, calculate all the possible seeds and then scan the blockchain to see whether any of those wallets contained funds?

Do hackers systematically examine the firmware and source code of different hardware-wallet brands such as Coldcard, Trezor and Ledger, looking for weaknesses in the way they generate seed phrases? Do they spend months testing different devices until they find one that produces seeds from a limited or predictable set of possibilities?

I understand that developers are human and that mistakes can happen. How does something this important make it into production without being detected?
Kruw
Sr. Member
****
Offline

Activity: 1190
Merit: 284


Use Bitcoin anonymously - wasabiwallet.io


View Profile WWW
Today at 10:59:28 AM
 #2

The bug was incredibly simple, it's shocking it was not discovered earlier. nvk is an incompetent blowhard who cares more about being a social media influencer than his hardware's security.

Protect your privacy - Coinjoin with Wasabi Wallet
Code:
https://coinjoin.kruw.io/
un_rank
Legendary
*
Offline

Activity: 1526
Merit: 1107



View Profile WWW
Today at 11:06:06 AM
 #3

Did someone notice a suspicious part of the firmware, realise that the randomness was weaker than it should have been, calculate all the possible seeds and then scan the blockchain to see whether any of those wallets contained funds?
Hackers are constantly trouble shooting security systems looking for vulnerability. The suspicion in thus case is that it was discovered years ago when those wallets were opened, the hacker got access to the seed phrase and sat on them for a while to allow the owners move funds into them before sweeping.

Do hackers systematically examine the firmware and source code of different hardware-wallet brands such as Coldcard, Trezor and Ledger, looking for weaknesses in the way they generate seed phrases? Do they spend months testing different devices until they find one that produces seeds from a limited or predictable set of possibilities?
Yes and yes.

I understand that developers are human and that mistakes can happen. How does something this important make it into production without being detected?
It's as you said, humans make errors. It also missed the eye of everyone as the codes are open source but no one spotted the vulnerability.

- Jay -

Odohu
Hero Member
*****
Offline

Activity: 1190
Merit: 776



View Profile WWW
Today at 11:23:04 AM
 #4

The bug was incredibly simple, it's shocking it was not discovered earlier. nvk is an incompetent blowhard who cares more about being a social media influencer than his hardware's security.
I'm not that technically savvy in such security aspect but I do know that before such sensitive product is released for use, they are tested and retested as a means of verification. It is my thinking that Coldcard wallet passed through those tests and the vulnerability was not detected. What if some of these vulnerabilities are connected to insider sabotage? Welll this may not be the case since the codes are open source so the only option is that it just happened.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT|
4,000+ GAMES
███████████████████
██████████▀▄▀▀▀████
████████▀▄▀██░░░███
██████▀▄███▄▀█▄▄▄██
███▀▀▀▀▀▀█▀▀▀▀▀▀███
██░░░░░░░░█░░░░░░██
██▄░░░░░░░█░░░░░▄██
███▄░░░░▄█▄▄▄▄▄████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
█████████
▀████████
░░▀██████
░░░░▀████
░░░░░░███
▄░░░░░███
▀█▄▄▄████
░░▀▀█████
▀▀▀▀▀▀▀▀▀
█████████
░░░▀▀████
██▄▄▀░███
█░░█▄░░██
░████▀▀██
█░░█▀░░██
██▀▀▄░███
░░░▄▄████
▀▀▀▀▀▀▀▀▀
||.
|
▄▄████▄▄
▀█▀
▄▀▀▄▀█▀
▄░░▄█░██░█▄░░▄
█░▄█░▀█▄▄█▀░█▄░█
▀▄░███▄▄▄▄███░▄▀
▀▀█░░░▄▄▄▄░░░█▀▀
░░██████░░█
█░░░░▀▀░░░░█
▀▄▀▄▀▄▀▄▀▄
▄░█████▀▀█████░▄
▄███████░██░███████▄
▀▀██████▄▄██████▀▀
▀▀████████▀▀
.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
░▀▄░▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄░▄▀
███▀▄▀█████████████████▀▄▀
█████▀▄░▄▄▄▄▄███░▄▄▄▄▄▄▀
███████▀▄▀██████░█▄▄▄▄▄▄▄▄
█████████▀▄▄░███▄▄▄▄▄▄░▄▀
███████████░███████▀▄▀
███████████░██▀▄▄▄▄▀
███████████░▀▄▀
████████████▄▀
███████████
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▀▄███░░░▀████░███▄▀██▄
███░████░░░░░▀██░████░███
███░████░█▄░░░░▀░████░███
███░████░███▄░░░░████░███
▀██▄▀███░█████▄░░███▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
OFFICIAL PARTNERSHIP
SOUTHAMPTON FC
FAZE CLAN
SSC NAPOLI
Doan9269
Hero Member
*****
Offline

Activity: 1680
Merit: 849



View Profile
Today at 01:37:57 PM
 #5

One thing with hackers is that they will never rest until the eventually landed at a particular prey, what they do is to continue with vulnerability search over every crypto entity that will give them access to hack easily, this is why once a vulnerability is not coming from the user end, scammers will never find it easy to hack any targets because they didn't have trouble user weak point to serve as an entry point for them, I'm sure after they have successfully identified this vulnerability with cold card, they would have similarly attempted on other hardware wallet without getting entry, except the also discover another vulnerability with any.

cryptomaniac_xxx
Hero Member
*****
Offline

Activity: 2310
Merit: 661



View Profile
Today at 01:42:48 PM
 #6

The bug was incredibly simple, it's shocking it was not discovered earlier. nvk is an incompetent blowhard who cares more about being a social media influencer than his hardware's security.
I'm not that technically savvy in such security aspect but I do know that before such sensitive product is released for use, they are tested and retested as a means of verification. It is my thinking that Coldcard wallet passed through those tests and the vulnerability was not detected. What if some of these vulnerabilities are connected to insider sabotage? Welll this may not be the case since the codes are open source so the only option is that it just happened.

This is also what I suspected, maybe the hackers did buy versions of ColdCard, dis-assemble them and then try to look for vulnerabilities. So it's not like the attack is done by someone by accident. They might have studied and then de-compile the firmware.

And then look for the pattern, and as what it was shown, it was not random, that's why they were able to attack it will. I don't know what will happen to ColdCard because it's obvious that they didn't do their homework and it run for years until the hackers where able to discover it.

Or maybe it could be the help of AI agent too.

 
 RAZED  
| 
 100% 
WELCOME
BONUS
█████████████████████
█████████████████████████
████████████▀░░░░▀███████
██████████▀░░▄▀▀▄░░▀█████
██████████▄▄██▄▄██▄░▀████
█████▀░░░░░░░▀██░░█░░████
████░░████▀▀█░░██▀░░▄████
████░░████▄▄█░░█░░▄██████
████░░█▀▀████░░██████████
████░░█▄▄███▀░░██████████
█████▄░░░░░░░▄███████████
█████████████████████████
█████████████████████
█████████████████████
█████████████████████████
██████████▀▀░░░░░▀▀██████
████████▀░░▄▄█░░▀▄░░█████
██████▀░░▄█████▄░░▀░░████
█████░░▄████▄▀░░█▄▄░░████
████░░▄███▄▀░░▄▀██▀░░████
████░░▀▀██░░▄▀███▀░░█████
████░░▄░░▀█████▀░░▄██████
█████░░▀▄░░█▀▀░░▄████████
██████▄▄░░░░░▄▄██████████
█████████████████████████
█████████████████████
| 
 NO 
KYC
| 
  RAZE THE LIMITS    PLAY NOW     
Ashawowo(OS)
Full Member
***
Offline

Activity: 140
Merit: 109



View Profile
Today at 02:26:39 PM
 #7

I'm not that technically savvy in such security aspect but I do know that before such sensitive product is released for use, they are tested and retested as a means of verification. It is my thinking that Coldcard wallet passed through those tests and the vulnerability was not detected. What if some of these vulnerabilities are connected to insider sabotage? Welll this may not be the case since the codes are open source so the only option is that it just happened.
This is also what I suspected, maybe the hackers did buy versions of ColdCard, dis-assemble them and then try to look for vulnerabilities. So it's not like the attack is done by someone by accident. They might have studied and then de-compile the firmware.
Why would they go through that stress just to look for vulnerabilities while the firmware code is Open-source on github?

I believe the major loophole came from their firmware upgrade from GPL to MIT+CC which it's migration started since 2020. I believe the hacker was an insider who knew about this loophole all along and waited for the right timing to pull off this big scam.

OP, just visit this thread to know more, there are several replies there that can give you the answer you desire.

█████████████████     BitList     █████████████████
████     |           Mixer           |        Exchanges        |          Casino          |     ████
|   Bitcointalk Archive   |   Data Visualization & Search   |  Currency Converter  |
hd49728
Legendary
*
Offline

Activity: 2898
Merit: 1360



View Profile
Today at 02:27:36 PM
 #8

The bug was incredibly simple, it's shocking it was not discovered earlier.
This was said but nvk and his team perhaps ignored this warning two years ago and anytime till this exploitation days ago.
https://www.youtube.com/watch?v=oj_W3xOlt6U

Perhaps hackers used AI to scan these things, found that video and took action for their jobs.

Quote
nvk is an incompetent blowhard who cares more about being a social media influencer than his hardware's security.
The nvk account was last actively in May this year. Maybe he will be back in the forum and not sure what he will said here after his hardware wallet's terrible security issues.


Kruw
Sr. Member
****
Offline

Activity: 1190
Merit: 284


Use Bitcoin anonymously - wasabiwallet.io


View Profile WWW
Today at 03:24:14 PM
 #9

The nvk account was last actively in May this year. Maybe he will be back in the forum and not sure what he will said here after his hardware wallet's terrible security issues.

Thanks, just left him a negative trust rating to warn others.

Protect your privacy - Coinjoin with Wasabi Wallet
Code:
https://coinjoin.kruw.io/
hd49728
Legendary
*
Offline

Activity: 2898
Merit: 1360



View Profile
Today at 04:34:56 PM
 #10

I believe the major loophole came from their firmware upgrade from GPL to MIT+CC which it's migration started since 2020. I believe the hacker was an insider who knew about this loophole all along and waited for the right timing to pull off this big scam.
Insiders, no but there is an outsider talked and warned about that two years ago.

This video.
https://www.youtube.com/watch?v=oj_W3xOlt6U
Some people visited that video recent days and left some comments too.

Thanks, just left him a negative trust rating to warn others.
It can be a neutral trust feedback, while a red one is not actually right. He does not scam anyone, if he is not the attacker. If he is proven as the attacker, things will change and he will be very deserved with red trust feedbacks.

Luke-Jr aka Luke Dashjr did not get negative trust feedback because of his Bitcoin Knot wallet.

Mrbluntzy
Sr. Member
****
Offline

Activity: 910
Merit: 261



View Profile WWW
Today at 04:58:54 PM
 #11

Exchanges has been hacked before, casinos has been hacked before and other companies that has been hacked too just like this recent one that you are talking about, and how the hackers do all of that is by constant research, since they have made up their mind to steal from people, in other to succeed, they will do so much research, code auditing, reverse engineering and many mother methods they have on what ever or whom ever their target is. So, the hackers of this coldcard must have done some reverse engineering and code auditing and many research on the wallet which they must have been targeting the wallet for a long time and were just waiting for when to strike.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!